ãã®ã³ã³ãã³ãã¯ãããã§ããã?
CRED achieves a high level of network inspection with VPC traffic mirroring
2021 幎 9 æ 8 æ¥: HAQM Elasticsearch Service 㯠HAQM OpenSearch Service ã«åç§°ã倿ŽãããŸããã詳现ãã芧ãã ããã
CREDãSecurity LeadãHimanshu Das æ°ã«ããã²ã¹ãæçš¿
CRED ã¯ãäŒå¡éå®ã®ã¯ã¬ãžããã«ãŒãç¹å žãéå®ç¹å žãäžæµãã©ã³ãã®äœéšãéããŠã人ã ã人çãã¢ããã°ã¬ãŒãã§ããããã«ããããšãç®æããŠããŸããä¿¡çšåã®ããå人ãå çåºãæ©é¢ãéãŸãä¿¡é Œã®é«ãã³ãã¥ããã£ã§ãã CRED ã¯ãæ°çŸäžãã®ã¯ã¬ãžããã«ãŒãå©çšè ã«ãµãŒãã¹ãæäŸãã人ã ã®ããã«ãã¯ã¬ãžããã«ãŒãäœéšãåæ§ç¯ããŠããŸããã
倧éã®æ©å¯ååŒãããŒã¿ãæ±ã CRED ã¯ãåžžã«ã»ãã¥ãªãã£ã«éç¹ã眮ããŠããŸãããäŒæ¥ã«ã¯ 2 ã€ã®ã¿ã€ãããããŸãã1 ã€ã¯ã»ãã¥ãªãã£ãåŸåããšèŠãªãããäŒæ¥ã§ããã 1 ã€ã¯ã»ãã¥ãªãã£ãæãéèŠã§ããäŒæ¥ã§ããäžéäŒæ¥ã«ã€ããŠã¯ã©ãã§ãã? CRED ã§ã¯ãäžèšã®ã«ãŒã«ã®äžéè ã¯ããªããšå¿ããä¿¡ããŠããŸããã ãããããåœç€Ÿã¯åŸè ã®é£å¶ã«å±ããŠãããšãããŸããCRED ã¯ã»ãã¥ãªãã£ç¬¬äžã®äŒæ¥ã§ãããåžžã«ã»ãã¥ãªãã£ãæåªå äºé ãšã¿ãªããŠããŸãã
ãAWS ã䜿çšããããšã§ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®å®å®æ§ãšé«å¯çšæ§ãåžžã«ä¿ã€ããšãã§ããã ãã§ãªããåã¬ã€ã€ãŒã§ã»ãã¥ãªãã£ã確ä¿ããããšãã§ããããã«ãªããŸããã~ CREDãSecurity EngineeringãAvinash Jain æ°
AWS VPC ãã©ãã£ãã¯ãã©ãŒãªã³ã°: NIDS ã䜿çšããŠãããªã㯠VPC ãµããããã®ãããã¯ãŒã¯äŸµå ¥ãã¢ãã¿ãªã³ã°ãã
COVID ã¯ãã¹ãŠã®äººã襲ããããããã«åœ±é¿ãäžããŸãã.çµç¹ã«ãããŠã¯ãåŸæ¥å¡ã¯åšå® å€å (WFH) ãæ±ããããçŸåšã§ã¯å€ãã®æ¥çããªã¢ãŒãã¯ãŒã¯ãè¡ã£ãŠãããããäŒæ¥ãããã¯ãŒã¯ãžã®ãŠãŒã¶ãŒæ¥ç¶ã®ãã¿ãŒã³ãæ ¹åºããèŠãããŠããŸããçŸåšã§ã¯ãã»ãšãã©ã®ãŠãŒã¶ãŒãããŒã«ã«ã«æ¥ç¶ããã®ã§ã¯ãªãããªã¢ãŒãã§æ¥ç¶ããŠããŸãããŸããåŸæ¥å¡ãéèŠãªããžãã¹æ©èœã«ã¢ã¯ã»ã¹ã§ããããã«ããã«ã¯ãVPN æ¥ç¶ãå¿ é ã§ãã
VPN ã€ã³ã¹ã¿ã³ã¹ã¯ãäžçäžã®åŸæ¥å¡ãæ¥ç¶ããŠå éšã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããã«éæŠè£ å°åž¯ (DMZ) ã«ä¿ç®¡ãããŠãããããWFH æ¥ç¶ãäºæããæ®ºå°ããVPN ãããã¯ãŒã¯ãããããçš®é¡ã®ã¬ã€ã€ãŒ 7/ã¬ã€ã€ãŒ 3 æ»æã«å¯ŸããŠããè匱ã«ãªããŸãã
ãã®ããã°èšäºã§ã¯ãAWS VPC Traffic Mirroring ãšãããã¯ãŒã¯äŸµå ¥æ€ç¥ã·ã¹ãã ã䜿çšããŠããããã¯ãŒã¯äŸµå ¥ã瀺ãç°åžžãªãã©ãã£ãã¯ãã¿ãŒã³ãã³ã³ãã³ãã«åžžã«æ³šæãæããªããããããªã㯠VPC ã«ä¿ç®¡ãããŠãããããªã㯠VPN ã€ã³ã¹ã¿ã³ã¹ã®ã»ãã¥ãªãã£ãšã¢ãã¿ãªã³ã°ã匷åããæ¹æ³ã«ã€ããŠèª¬æããŸãã
VPC ãã©ãã£ãã¯ãã©ãŒãªã³ã°ã¯ãã€ã³ã¹ã¿ã³ã¹èªäœã«äœãã€ã³ã¹ããŒã«ããªããŠããVPC å ã® HAQM EC2 ã€ã³ã¹ã¿ã³ã¹ã®ã€ã³ããŠã³ãããã³ã¢ãŠãããŠã³ããã©ãã£ãã¯ãè€è£œããŸãããã®éè€ãããã©ãã£ãã¯ããããã¯ãŒã¯äŸµå ¥æ€ç¥ã·ã¹ãã (NIDS) ã«éä¿¡ããŠåæãšã¢ãã¿ãªã³ã°ãè¡ããšãããã®ã§ãããããã¯ãŒã¯äŸµå ¥ãã¢ãã¿ãªã³ã°ããã¢ãŒããã¯ãã£å³ã¯æ¬¡ã®ããã«ãªããŸãã

VPN ãµãŒããŒã«éä¿¡ããããã©ãã£ãã¯ã¯ãã¹ãŠããã©ãŒãªã³ã°ããããã©ãã£ãã¯ã®éä¿¡å ãšãªããã©ãŒã¿ãŒã²ãã (Network Load Balancer) ã«éä¿¡ãããŸããVPC ãã©ãã£ãã¯ãã©ãŒãªã³ã°ã«ã¯ããã£ãã㣠(æ¿èª) ãŸãã¯ã¹ããã (æåŠ) ãããã€ã³ããŠã³ããŸãã¯ã¢ãŠãããŠã³ãã® (ãœãŒã¹ãåºæºãšããŠ) ãã©ãã£ãã¯ãæå®ãããã©ãŒãã£ã«ã¿ãŒã®åªããæ©èœããããŸãããã©ãŒã¿ãŒã²ãããããäŸµå ¥æ€ç¥ (IDS)ãäŸµå ¥é²æ¢ (IPS)ããããã¯ãŒã¯ã»ãã¥ãªãã£ã¢ãã¿ãªã³ã°ãªã©ã®æ©èœãæäŸãããªãŒãã³ãœãŒã¹ã®ãããã¯ãŒã¯è åšæ€åºãšã³ãžã³ã§ãã Suricata ã䜿çšããŠãè€è£œããããã©ãã£ãã¯ã NIDS ã·ã¹ãã ã«éä¿¡ããŸããSuricata ãéžã¶ã®ã¯ã詳现ãªãã±ããæ€æ»ãšãã¿ãŒã³ãããã³ã°ãéåžžã«ããŸãæ©èœããè åšãæ»æã®æ€åºã«éåžžã«åœ¹ç«ã€ããã§ãããŸãããã«ãã¹ã¬ããæ©èœãåããŠãããããåãããŒããŠã§ã¢äžã§ããã©ãã£ãã¯éã®å€ãé«éãããã¯ãŒã¯ã§ããå€ãã®ã«ãŒã«ãåŠçã§ãããšããçè«äžã®èœåãåŸãããŸãã
èé害æ§ãšå¯çšæ§ãé«ããããã«ãç§ãã¡ã¯ Suricata èšå®ã䜿çšã㊠EC2 ã€ã³ã¹ã¿ã³ã¹ã«éè€ãã©ãã£ãã¯ãéä¿¡ããŸãããã®ç®çã§ HAQM EC2 T3 ã€ã³ã¹ã¿ã³ã¹ã䜿çšããŠããŸããããã¯ãåžžã«å€§éã®ãã©ãã£ãã¯ãçºçããããšãããã£ãŠãããããã©ãŒãã³ã¹ãšå¹çãç§ãã¡ãéæãããå¥ã® 2 ã€ã®åºæºã ã£ããããæå³çã«éžæããæ¹æ³ã§ãããT3 ã€ã³ã¹ã¿ã³ã¹ã¯ããã€ã§ãå¿ èŠãªã ã CPU ãããŒã¹ã䜿çšããããšãã§ããåºæ¬ã¬ãã«ã® CPU ããã©ãŒãã³ã¹ãæäŸããŠãããŸããã
ã¢ãã¿ãªã³ã°ãšãã®ã³ã°
Suricata ã€ã³ã¹ã¿ã³ã¹ã«ã¯ Filebeat ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ãããŠããŸããããã¯ãã°ããŒã¿ã転éããŠäžå 管çããããã®è»œéã·ãããŒã§ããSuricata ã¯ãã©ãã£ãã¯ãç¶ç¶çã«ã¢ãã¿ãªã³ã°ããSuricata ã«ãŒã« (/etc/suricata/Rules) ãã¢ã©ãŒããããªã¬ãŒããŸãããã®åŸãFilebeat ã¯ã¢ã©ãŒããã°ã ELK ã¹ã¿ãã¯ã«éä¿¡ããããã§ Logstash 㯠JSON ããŒã¿ãåŠçããŸããã»ã«ããã¹ãåã® HAQM OpenSearch Service (HAQM Elasticsearch Service ã®åŸç¶ãµãŒãã¹) ã® Suricata ã¢ãžã¥ãŒã«ã䜿çšããŠããŸãããã®ãµãŒãã¹ã¯ã以äžã®ã¿ã¹ã¯ã代è¡ããŠå®è¡ããŠãããŸãã
â åã蟌ã¿ããŒãã䜿çšããŠãã°è¡ãè§£æããã³åŠçããããŒã¿ã Kibana ã§ã®å¯èŠåã«é©ããæ§é ã«ããŸã
â ãã°ããŒã¿ãå¯èŠåããããã®ããã·ã¥ããŒãããããã€ããŸã
Kibanaâs Coordinate Map ããžã¥ã¢ã©ã€ãŒãŒã·ã§ã³ã䜿çšããŠãã·ã¹ãã ã«æµå ¥ãããã©ãã£ãã¯ã®å°ççååžãã¢ãã¿ãªã³ã°ã§ããŸããevent_type ãã£ãŒã«ãã«ã¯ Suricata ã®ãã°ã¿ã€ãã衚瀺ãããŸããåã°ã©ããå¯èŠåããããšã§ãã·ã¹ãã ã«èšé²ãããŠããäžäœã®ãã°ã¿ã€ãã®å èš³ã確èªã§ããŸãã
å³ãããããããã«ãã¢ã©ãŒãã¯é倧床ã«åºã¥ããŠãé«ãããäžãããäœãã«åé¡ãããŠããŸããã€ãã³ãã®åé¡ã¯æ¬¡ã® 2 ã€ã®å Žæã§è¡ãããŸãã
1. VPC ã® 1 ã€ã¯ããã©ãŒãã£ã«ã¿ãŒãã§ãã
2. 次ã«ãSuricata ã«ãŒã«ã䜿çšããŠãããã³ã«ãç¹å®ããã€ãã³ãã®ç°åžžãåé¡ããŸãã
çŸæç¹ã«ãããŠã¯ãSuricata ããæäŸãããŠããããã©ã«ãã®ã«ãŒã«ã»ããã䜿çšãããŸããããã«ã¯ãæªæã®ãã IP ã¬ãã¥ããŒã·ã§ã³ãã§ãã¯ãçããããŠãŒã¶ãŒãšãŒãžã§ã³ãã眲åããŒã¹ã®äŸµå ¥ãããªã·ãŒéåããã©ãã£ãã¯ç°åžžãªã©ãå«ãŸããŸããåã°ã©ãã®ããžã¥ã¢ã©ã€ãŒãŒã·ã§ã³ã®äŸã® 1 ã€ã«ãSuricata ããããã¯ãŒã¯äžã§äœããã® Tor ã¢ã¯ãã£ããã£ããã®ä»ã®ãããã¯ãŒã¯ç°åžžãçºèŠããç®æã瀺ãããŠããŸãã修埩ããã»ã¹ã¯ãäžå çãªãã®ã³ã°ãã¢ã©ãŒããæææ±ºå®ã®ãã¬ãŒã ã¯ãŒã¯ãéããŠè¡ãããŸããããã·ã¥ããŒãå šäœãèŠããããã«ã以äžã®ãã©ã¡ãŒã¿ãèšå®ãããŠããŸãã
o ã¢ã©ãŒãæ°
o ã¢ã©ãŒãäžäœ 10 ä»¶ã®çœ²å
o ã¢ã©ãŒãäžäœ 20 ä»¶ã®éä¿¡å IP
o ã¢ã©ãŒãäžäœ 20 ä»¶ã®éä¿¡å IP
o ã¢ã©ãŒãã®éèŠåºŠ
o ã¢ã©ãŒãã¿ã€ã ã©ã€ã³
o DNS ã€ãã³ãçµæå€å

æçµçµæ
VPC ãã©ãã£ãã¯ãã©ãŒãªã³ã°ã«ãããAWS VPC å ã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãç°¡åã«ã¢ãã¿ãªã³ã°ã§ããŸãããããã¯ãŒã¯ãã©ãã£ãã¯ã广çã«ã¢ãã¿ãªã³ã°ãããã©ãã£ãã¯ãã¿ãŒã³ãåæããæªæã®ãããã©ãã£ãã¯ãç©æ¥µçã«æ€åºã§ããããã«ãªããŸãããæ¬¡ã®ãããªå©ç¹ããããŸãã
- ãããã¯ãŒã¯ãšã»ãã¥ãªãã£ã®ç°åžžæ€åº - VPC å ã®ä»»æã®ã¯ãŒã¯ããŒããã察象ã®ãã©ãã£ãã¯ãæœåºããéžæããæ€åºããŒã«ã«ã«ãŒãã£ã³ã°ããããšã§ãåŸæ¥ã®ãã°ããŒã¹ã®ããŒã«ã§ã¯äžå¯èœãªã»ã©è¿ éã«æ»æãæ€åºããŠå¯Ÿå¿ããããšãã§ããŸãã
- éçšäžã®ã€ã³ãµã€ããåŸã - VPC ãã©ãã£ãã¯ãã©ãŒãªã³ã°ã䜿çšããŠãããã¯ãŒã¯ã®å¯èŠæ§ãšå¶åŸ¡ãå®çŸããããå€ãã®æ å ±ã«åºã¥ããŠã»ãã¥ãªãã£äžã®æ±ºå®ãäžããããã«ããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ãšã»ãã¥ãªãã£å¶åŸ¡ã®å®è£ - ã¢ãã¿ãªã³ã°ããã®ã³ã°ãªã©ã矩åä»ããèŠå¶ãã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãæºãããŸãã
Suricata ã¯ããããã¯ãŒã¯ã«æªæã®ããã¢ã¯ãã£ããã£ããªããã¢ãã¿ãªã³ã°ããããã®åªãããªãŒãã³ãœãŒã¹ãªãã·ã§ã³ã§ããä»åŸããã«ãŒã«ãããã·ã¥ããŒãã远å ã㊠Suricata ãšã®é£æºã匷åããŠããäºå®ã§ãã

AWS Editorial Team
AWS ã¹ã¿ãŒãã¢ããã® Content Marketing Team ã¯ãæè²ããšã³ã¿ãŒãã€ã³ã¡ã³ããã€ã³ã¹ãã¬ãŒã·ã§ã³ãæäŸããåªããã³ã³ãã³ããããããããã«ãããããèŠæš¡ããã³ããããã»ã¯ã¿ãŒã®ã¹ã¿ãŒãã¢ãããšé£æºããŠããŸãã
ãã®ã³ã³ãã³ãã¯ãããã§ããã?