æ¬è¨äºã¯
AWSã¢ã¯ã¼ãåè³è
ç¥ã
20æ¥ç®ã®è¨äºã§ãã
â¨ð
19æ¥ç®
â¶â¶ æ¬è¨äº â¶â¶
21æ¥ç®
ðâ¨
ããã«ã¡ã¯ã西å ã§ãã
ãã®åº¦ã2025 Japan AWS Top Engineersããã³2025 Japan All AWS Certifications Engineersã«é¸åºãã¦ããã ãã¾ããã 社å ã«ã¯å¤ãã®çè ãããä¸ãã¾ã ã¾ã èªåã¯æªçã ã¨æãã¦ããã¾ãããåã«æ¥ãã¬ããç²¾ä¸æ¯é å¼µãããã¨æãã¾ãã
ç§ã¯ã客æ§ä¼æ¥å ã®CCoEã®æ¹ã åãã«AWSãã«ãã¢ã«ã¦ã³ãçµ±å¶ã®ãµãã¼ããè¡ã£ã¦ãã¾ãã ä¸ã§ããã»ãã¥ãªãã£ç³»ãµã¼ãã¹ã®æå¹åã¯ã¨ã¦ãéè¦ãªä»»åã®ä¸ã¤ã§ãã
åºæ¬çã«ã»ãã¥ãªãã£ç³»ãµã¼ãã¹ã¯å ¨ã¦æå¹åãã¦ãåé¡ã®çºçãé²ãã ããåé¡ãçºçããå ´åã«ã¯è¿ éã«å¯¾å¿ãããã¨ãéè¦ã¨ããã¦ãã¾ãã ããããä½ãèããæå¹åãè¡ãã¨æ¢åã®ã¯ã¼ã¯ãã¼ãã«å½±é¿ãä¸ãã¦ãã¾ãå¯è½æ§ãããã¾ãã å¤ãã®AWSã¢ã«ã¦ã³ãã«å¯¾ãã¦æå¹åãè¡ãå ´åããã®å½±é¿ã¯å¤å¤§ãªãã®ã¨ãªã£ã¦ãã¾ãã¾ãã
ä»åã¯ãã»ãã¥ãªãã£ç³»ãµã¼ãã¹ãæå¹åããéã«ç§ãæ°ãã¤ãã¦ãããã¤ã³ãã«ã¤ãã¦ãAmazon GuardDutyãä¾ã«æãã¦ã話ããããã¨æãã¾ãã
- CCoEå°å ¥ã«ããã課é¡
- æå¹åã«åããé²ãæ¹
- ã©ã¡ãã®æ¹éã«å¾ãã¹ãã
- ã¾ã¨ã
CCoEå°å ¥ã«ããã課é¡
ã¾ãåæã¨ãã¦ãCCoEé¨éãã客æ§ã®å ´åãã¡ã³ãã¼ã¢ã«ã¦ã³ããæ±ãé¨éã¨ç´æ¥ããåããè¡ããªããã¨ããããã¨æãã¾ãã å½ç¶ã®ãã¨ã§ãããCCoEé¨éã¨ã¡ã³ãã¼ã¢ã«ã¦ã³ãå ã§éçºãè¡ãé¨éã¯åããã¦ãããé£çµ¡ãåãéã CCoEé¨éãä»ãå¿ è¦ãããããã§ãã
ããããã¼ã«ãã£ã³ã°ã¹ç³»ã®ä¼ç¤¾æ§ããã°ã«ã¼ãä¼ç¤¾ãè¤æ°æ±ãã伿¥æ§ã®å ´åã管çã¢ã«ã¦ã³ãã¯è¦ªä¼ç¤¾ã®CCoEé¨éã管çããã¡ã³ãã¼ã¢ã«ã¦ã³ãã¯ã°ã«ã¼ãä¼ç¤¾ãå©ç¨ãã¦ããã¨ããã±ã¼ã¹ãããã§ãããã ãã®ãããªå ´åã¯ãããä¸å±¤ã¡ã³ãã¼ã¢ã«ã¦ã³ãã®ã¦ã¼ã¶ã¼ã¨é£çµ¡ãåããã¨ãé£ãããªãã¾ãã

ãã®ããã«ãCCoEé¨éã®æ¹ã¨ããåããã¦ç®¡çã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ãããã¨ã¯ã§ãã¦ããã¡ã³ãã¼ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹æ¨©ã¯ç§ãã¡ã«ã¯ç¡ãã¨ãããã¨ãå¤ã ããã¾ãã ãã®å ´åãç§ãã¡ãã¡ã³ãã¼ã¢ã«ã¦ã³ãå ã§ã©ã®ãããªã¢ã¼ããã¯ãã£ãæ§ç¯ããä½ã®ããã®ã¯ã¼ã¯ãã¼ããéç¨ãã¦ããããææ¡ãããã¨ã¯ã§ãã¾ããã
ã¾ããã¢ã«ã¦ã³ãã®æ°ãå¤ãã¨ããªããããã¹ã¦ã®ã¯ã¼ã¯ãã¼ããææ¡ãããã¨ã¯å°é£ã«ãªãã¾ãã ä»åã®è¨äºã§ã¯ããã®ãããªåæã«ç«ã£ã¦è©±ãé²ãããã¨æãã¾ãã
æå¹åã«åããé²ãæ¹
å ã»ã©ãã¡ã³ãã¼ã¢ã«ã¦ã³ãå ã®ã¯ã¼ã¯ãã¼ããææ¡ãããã¨ã¯é£ããã¨è¿°ã¹ã¾ããã ããããçµ±å¶ãå©ããã¦åä¸ã«ã»ãã¥ãªãã£ãæ ä¿ããããã«ã¯ãå種ã»ãã¥ãªãã£ãµã¼ãã¹ãå°å ¥ããå¿ è¦ãããã¾ãã ã§ã¯ããã®ãããªä¸ã§ã»ãã¥ãªãã£ç³»ãµã¼ãã¹ãå°å ¥ããéã«ã¯ãã©ã®ããã«é²ããã®ãè¯ãã§ããããã
ã¾ã念é ã«ç½®ãã¹ããªã®ã¯ãæ¢åã¯ã¼ã¯ãã¼ããæ¢ããªããã¨ããè¦ç¹ã§ãã ã»ãã¥ãªãã£åä¸ã®ããã«å®æ½ããæ½çã«ãã£ã¦ã¯ã¼ã¯ãã¼ãã忢ãããã¨ã¯ãæ¥åã«å½±é¿ãåºãã ãã§ãªããCCoEé¨éã¨ã¡ã³ãã¼ã¢ã«ã¦ã³ãå´é¨éã®é¢ä¿æ§ã®æªåãæãå¯è½æ§ãããã¾ãã
ãã®ããã«ããã¾ãã¯å°å ¥ããã»ãã¥ãªãã£ãµã¼ãã¹ãã©ã®AWSãµã¼ãã¹ã«å¯¾ãã¦ã¹ãã£ã³ãç£è¦ãè¡ãã®ããã¾ããããã«ãã£ã¦ã©ã®ãããªå½±é¿ãããã®ããææ¡ãããã¨ãéè¦ã§ãã ãã®ããã§ããµã¼ãã¹ã«å½±é¿ããããã®ãçµãåºãã対å¿ãæ¤è¨ãã¦ããå¿ è¦ãããã¾ãã

ã¾ããçºçããè²»ç¨ã®ç®åºãäºç®ã¨ã®ç §ããåãããå ·ä½çãªæå¹åæ¹æ³ï¼ã³ã³ã½ã¼ã«ç»é¢ã»CLIã»IaCãªã©ï¼ã®æ¤è¨ãéè¦ãªè¦ç¹ã§ãã æ¬è¨äºã§ã¯ãæ¢åã¯ã¼ã¯ãã¼ããæ¢ããªããã¨ããç¹ã«ãã©ã¼ã«ã¹ãã¦ãããããè²»ç¨èª¿æ´ã«ã¤ãã¦ã¯å²æãã¾ãã
ããã¥ã¡ã³ãã®èªã¿è¾¼ã¿
å½ç¶ã®ãã¨ã§ã¯ããã¾ãããæå¹åãè¡ããµã¼ãã¹ã«ã¤ãã¦ãã©ã®ãããªæ©è½ãæå¹åã§ããã®ãããåæ©è½ã¯ä½ã®ãµã¼ãã¹ã«å¯¾ãã¦ç£è¦ãã¹ãã£ã³ãè¡ãã®ããããã®ç£è¦ãã¹ãã£ã³ã«ãã£ã¦ã©ã®ãããªå½±é¿ãããã®ããããããã¥ã¡ã³ããèªã¿è¾¼ãã§ææ¡ãããã¨ãéè¦ã§ãã
ããã§ãAmazon GuardDutyãä¾ã«æãã¦èª¬æãããã¨æãã¾ãã Amazon GuardDutyã¨ã¯ããã¼ã¸ãåã®è 卿¤åºãµã¼ãã¹ã§ãAWS ã¢ã«ã¦ã³ãã¨ã¯ã¼ã¯ãã¼ããç¶ç¶çã«ã¢ãã¿ãªã³ã°ãã¦æªæã®ããã¢ã¯ãã£ããã£ãæ¤åºãã¾ãã ã¾ã㯠GuardDuty ã®å ¬å¼ããã¥ã¡ã³ããè¦ã¦ã¿ã¾ãããã
ã²ã¨ãã¡ã«GuardDutyã¨ãã£ã¦ããè¤æ°ã®æ©è½ãåå¨ãããã¨ãåããã¾ãã Runtime Monitoringã¯ããã«ãã®ä¸ã§æå¹å対象ãµã¼ãã¹å¥ã«é ç®ãåå¨ãã¦ãã¾ãã
- S3 Protection
- EKS Protection
- Malware Protection for EC2
- Malware Protection for S3
- RDS Protection
- Lambda Protection
- Runtime Monitoring
- Amazon EKS
- Amazon ECS
- Amazon EC2
ã§ã¯ãåæ©è½ã«ã¤ãã¦ä½ãè¡ãã®ããããªã大éæã§ã¯ããã¾ãã以ä¸ã®è¡¨ã«ã¾ã¨ãã¾ãã
| # | æ©è½å | ä½ãè¡ãã®ã | ãæ¢åã¯ã¼ã¯ãã¼ã稼åã¸ã®å½±é¿ã |
|---|---|---|---|
| 1 | S3 Protection | CloudTrailã®ç£è¦ | ãã°ç£è¦ã®ããé大ãªå½±é¿ãªã |
| 2 | EKS Protection | CloudWatchã«é ããEKSã®ãã°ç£è¦ | ãã°ç£è¦ã®ããé大ãªå½±é¿ãªã |
| 3 | Malware Protection for EC2 | EBSã¹ãããã·ã§ããã®ã¹ãã£ã³ | ã¹ãããã·ã§ããã¸ã®ã¹ãã£ã³ã®ããé大ãªå½±é¿ãªã |
| 4 | Malware Protection for S3 | ã¢ãããã¼ãããããªãã¸ã§ã¯ãã®ã¹ãã£ã³ | ãªãã¸ã§ã¯ãã¸ã®ã¹ãã£ã³ã§ããã¯ã¼ã¯ãã¼ãã¸ã®å½±é¿ãªã |
| 5 | RDS Protection | 䏿£ãªãã°ã¤ã³ã¢ã¯ãã£ããã£ã®æ¤ç¥ | ããã©ã¼ãã³ã¹å½±é¿ãªãï¼â»ããã¥ã¡ã³ãã«ãæè¨ããã¦ããï¼ |
| 6 | Lambda Protection | Lambdaã®å種ãã°ã®ç£è¦ | ãã°ç£è¦ã®ããé大ãªå½±é¿ãªã |
| 7 | Runtime Monitoring ï¼Amazon EKSï¼ | æ°ããªpodã使ãã¦ç£è¦ãè¡ã | ç£è¦ç¨podãCPUãã¡ã¢ãªãæ¶è²»ããããå½±é¿ãåã¼ãå¯è½æ§ãã |
| 8 | Runtime Monitoring ï¼Amazon ECSï¼ | ãµã¤ãã«ã¼ã³ã³ããã使ãã¦ç£è¦ãè¡ã | ã¨ã¼ã¸ã§ã³ããCPUãã¡ã¢ãªãæ¶è²»ããããå½±é¿ãåã¼ãå¯è½æ§ãããã¾ãã³ã³ããã®åèµ·åãå¿ è¦ |
| 9 | Runtime Monitoring ï¼Amazon EC2ï¼ | ã¨ã¼ã¸ã§ã³ããã¤ã³ã¹ãã¼ã«ãã¦ç£è¦ãè¡ã | ã¨ã¼ã¸ã§ã³ããCPUãã¡ã¢ãªãæ¶è²»ããããå½±é¿ãåã¼ãå¯è½æ§ãã |
å½±é¿ã®ããæ©è½ãã©ãæå¹åããã
å è¿°ã®è¡¨ã®ãæ¢åã¯ã¼ã¯ãã¼ãã¸ã®å½±é¿ãåãè¦ã¦ã¿ã¾ãããã #1ï½6ã«ã¤ãã¦ã¯ã¯ã¼ã¯ãã¼ãã«å¯¾ãã¦é大ãªå½±é¿ã¯ããã¾ããã ãã®ãããæå¹åãè¡ãæ¹éã§åé¡ããã¾ããã
åé¡ã¯#7以éã®RuntimeMonitoringã§ãã #7~8ã¯å ¨ã¦ã¤ã³ã¹ã¿ã³ã¹ã®CPUãã¡ã¢ãªãæ¶è²»ãããããã¯ã¼ã¯ãã¼ãã«å½±é¿ãåã¼ãå¯è½æ§ãããã¾ãã å ·ä½çã«ã©ã®ãããæ¶è²»ããããããã¥ã¡ã³ãã«è¨è¼ããã¦ãã¾ãã
ãã®ãããªã¯ã¼ã¯ãã¼ãã¸ã®å½±é¿ãåã¼ãæ©è½ã«ã¤ãã¦ã¯ãã©ã®ããã«æå¹åãããæ¹éãæ¤è¨ããå¿ è¦ãããã¾ãã ãã®æã«ãã¤ã³ãã¨ãªãã®ã¯ãããããã¦ã³ãã¨ãå奿é©åãã®2ç¹ã¨èãã¾ãã
ããããã¦ã³
ããããã¦ã³ã¯ãCCoEãå ¨ã¢ã«ã¦ã³ãã¸ã®å°å ¥ãæ¨ãé²ããã¨ããããæ¹ã§ãã å½±é¿ã®å°ãªãã¢ã«ã¦ã³ãããé æ¬¡æå¹åãã¦æ§åãè¦ã¤ã¤ãæçµçã«ãã¹ã¦ã®ã¢ã«ã¦ã³ããæå¹åãããã¨ãç®æãã¾ãã
ãã®èãæ¹ã®ã¡ãªããã¯ãåä¸ã«çµ±å¶ãå©ããããã¨ãã§ããã¨ããç¹ã§ãã æçµçã«ã¯ãã¹ã¦ã®ã¢ã«ã¦ã³ãã«å¯¾ãã¦ã»ãã¥ãªãã£ãµã¼ãã¹ãå°å ¥ã§ãããã¹ããã©ã¯ãã£ã¹ã«æãè¿ãå½¢ã§ãããã
䏿¹ã§ãCCoEããã¹ã¦ã®ã¯ã¼ã¯ãã¼ãã®è©³ç´°ãææ¡ã§ãã¦ããªãå ´åãæå¹åã«ããå½±é¿åº¦åãã¯è¨ãç¥ãã¾ããã ã¾ããã¤ã³ã·ãã³ããåé¿ããã«ã¯ã¡ã³ãã¼ã¢ã«ã¦ã³ãã¨æå¹åã®ã¿ã¤ãã³ã°ã調æ´ããå¿ è¦ããããCCoEå´ã®è² æ å¢å ãäºæ³ããã¾ãã

å奿é©å
ãã䏿¹ã®èãæ¹ã¯å奿é©åã§ãï¼â»ããããã¦ã³ã®å¯¾ç¾©èªã¯ããã ã¢ããã§ãããå°ãè¨èã®ä¸»æ¨ãç°ãªããããå奿é©åãã¨ãã¾ããï¼ã ãã®èãæ¹ã§ã¯ãæå¹åã®å¤æãã¡ã³ãã¼ã¢ã«ã¦ã³ãå´ã«å§ãã¾ãã
æ¢åã¯ã¼ã¯ãã¼ãã®éè¦åº¦ããæå¹åãã¦ãåé¡ãªãã¿ã¤ãã³ã°ã¯ã¡ã³ãã¼ã¢ã«ã¦ã³ãå´ãä¸çªçè§£ãã¦ãã¾ãã ãã®ããããµã¼ãã¹ã®æ¦è¦ãæå¹åã«ããå½±é¿ãããã¥ã¢ã«ã¨ãã¦ã¾ã¨ãã¦ã¡ã³ãã¼ã¢ã«ã¦ã³ãå´ã«å ±æããæé©ãªã¿ã¤ãã³ã°ã§æå¹åã宿½ãã¦ãããã¾ãã
ãã®èãæ¹ã®ã¡ãªããã¯ãæ¢åã¯ã¼ã¯ãã¼ãã§åé¡ãèµ·ãããªã¹ã¯ãæãæãããã¨ãã§ããã¨ããç¹ã§ããã¯ã¼ã¯ãã¼ããæãææ¡ãã¦ããã¡ã³ãã¼ã¢ã«ã¦ã³ãå´ã«æå¹åãå§ãããã¨ã§ãæé©ãªã¿ã¤ãã³ã°ã§ã®æå¹åããæ¸å¿µã®ããã¯ã¼ã¯ãã¼ãã¸ã®æå¹åãè¡ããªãã¨ãã£ã夿ããããã¨ãåºæ¥ã¾ãã
䏿¹ã§ããã®ææ³åã£ãå ´åæå¹åã®ã¿ã¤ãã³ã°ã¯ãã©ãã©ã§ãå ´åã«ãã£ã¦ã¯æå¹åãè¡ãããæ¾ç½®ããããã¨ãããã§ãããã

ã©ã¡ãã®æ¹éã«å¾ãã¹ãã
å ã»ã©ã®2ã¤ã®æ¹éã表ã«ã¾ã¨ãã¾ããã
| ææ³ | ã¡ãªãã | ãã¡ãªãã |
|---|---|---|
| ããããã¦ã³ | ã»å
¨ã¢ã«ã¦ã³ãã«åä¸ãªçµ±å¶ãå©ããããã ã»æçµçã«å ¨ã¢ã«ã¦ã³ãã¸å°å ¥ã§ãã ã»ãã¹ããã©ã¯ãã£ã¹ã«è¿ã |
ã»CCoEãå
¨ã¯ã¼ã¯ãã¼ãã®è©³ç´°ãææ¡ã§ãã¦ããªãå ´åãå½±é¿ãèªããªã ã»æå¹åã¿ã¤ãã³ã°èª¿æ´ãªã©CCoEå´ã®è² æ å¢å |
| å奿é©å | ã»æ¢åã¯ã¼ã¯ãã¼ãã¸ã®å½±é¿ãªã¹ã¯ãæå°åã§ãã ã»æé©ãªã¿ã¤ãã³ã°ã§æå¹åå¯è½ ã»æ¸å¿µã®ããã¯ã¼ã¯ãã¼ãã¯é¤å¤ã§ãã |
ã»æå¹åã®ã¿ã¤ãã³ã°ããã©ãã©ã«ãªã ã»å ´åã«ãã£ã¦ã¯æå¹åãããæ¾ç½®ããããã¨ããã |
ã©ã¡ãã®æ¹éã«ãããã¯ãCCoE ã®ã»ãã¥ãªãã£æ½çã®æ¹éã«ããã¾ãã ãå¼·ãæå¿ãæã£ã¦å¿ ãå ¨ã¢ã«ã¦ã³ãã¸ã»ãã¥ãªãã£ãµã¼ãã¹ãå°å ¥ãããã¨ããã®ã§ããã°ãããããã¦ã³çãªé²ãæ¹ãè¯ãã§ãããã ããã§ã¯ãªããããã¾ã§æ¢åã¯ã¼ã¯ãã¼ãã¸å½±é¿ãä¸ããªããã¨ã第ä¸ãã¨ããèããéè¦ããã®ã§ããã°ãå奿é©åãè¯ãã§ãããã
ã©ã¡ããæ£è§£ã¨ãããã¨ã¯ãªããã¯ã¼ã¯ãã¼ãã®ç¶æ³ãè¦ãªããå¯è½ãªéãå ¨ã¢ã«ã¦ã³ãã¸ã®å°å ¥ã¯ç®æãã¦ãããã¨ãéè¦ã§ãã
ã¾ã¨ã
ã»ãã¥ãªãã£ãµã¼ãã¹ã®æå¹åæ¹éã«ã¤ãã¦æ¸ãã¾ããã GuardDutyãä¾ã«æãã¾ããããä»ã®ã»ãã¥ãªãã£ãµã¼ãã¹ã«ãå½ã¦ã¯ã¾ãèãæ¹ã ã¨æãã¾ãã
ãã¹ããã©ã¯ãã£ã¹ã¯AWSã«ãã£ã¦æç¤ºããã¦ãã¾ããããããå¿ ãããä»ã®ç°å¢ã«å½ã¦ã¯ããããã¨ã¯éãã¾ããã ã¾ããGuardDutyã®RuntimeMonitoringã¯ç®¡çã¢ã«ã¦ã³ããããã¡ã³ãã¼ã¢ã«ã¦ã³ããããæå¹åãè¡ãã¾ãããå ¨ã¦ã®ã»ãã¥ãªãã£ãµã¼ãã¹ãããã¨ã¯éãã¾ããã å½±é¿ç¯å²ãæå¹åæ¹æ³ãç¶²ç¾ çã«æ¼ãããããã§ãã¬ã¼ããªããèããå ·ä½çãªæ¹éãåºãã¦ãããã¨ãã¨ã³ã¸ãã¢ã®è ã®è¦ãã©ããã ã¨æãã¾ãã
