Kanji
・Cloud Engineer / Freelance ・Geboren 1993 ・Aus Ehime / Wohnhaft in Shibuya, Tokio ・5 Jahre AWS-Erfahrung Profildetails
Inhaltsverzeichnis
Amazon GuardDuty (hereafter referred to as GD) is a managed threat detection service that monitors activity in your AWS account and detects unauthorized actions and suspicious behavior.
GD collects and analyzes AWS CloudTrail logs, Amazon VPC Flow Logs, and DNS logs to identify malicious activity.
A common misconception is that you must enable CloudTrail and VPC Flow Logs to use GD, but this is not required.
GD offers the following seven optional threat detection features in addition to its basic data sources:
GuardDuty EKS Protection
GuardDuty Lambda Protection
GuardDuty Malware Protection for EC2
GuardDuty Malware Protection for S3
GuardDuty RDS Protection
GuardDuty S3 Protection
GuardDuty Runtime Monitoring
GD is classified as an IDS/IPS (Intrusion Detection System/Intrusion Prevention System).
If you already use IDS/IPS products in your environment, consider how to integrate them with GD.
IDS only notifies you of abnormal traffic, while IPS can also block it.
IPS enables faster responses than IDS, but can have a greater business impact.
Incorrect IPS settings can cause false positives, potentially leading to system outages.
GD uses machine learning to detect brute force attacks and suspicious API calls.
The table below summarizes the types of attacks and communications detected or blocked by GD and Network Firewall managed rules, helping you understand their capabilities and differences.
References:
GuardDuty finding types - Amazon GuardDuty
Using AWS managed rule groups in AWS Network Firewall - AWS Network Firewall
GuardDuty S3 Protection - Amazon GuardDuty
GuardDuty RDS Protection - Amazon GuardDuty
GuardDuty Malware Protection for EC2 - Amazon GuardDuty
GuardDuty Malware Protection for S3 - Amazon GuardDuty
GuardDuty EKS Protection - Amazon GuardDuty
GuardDuty Lambda Protection - Amazon GuardDuty
GuardDuty Runtime Monitoring - Amazon GuardDuty
Intelligent Threat Detection – Amazon GuardDuty Pricing – AWS
When considering which threat detection features to enable, make sure that the threats detected by GD are not already addressed by other designs.
The following is a list of S3 Protection finding types and their corresponding countermeasures or detection methods.
GuardDuty S3 Protection finding types - Amazon GuardDuty
In most cases, you can address or detect these findings using other AWS services.