Kanji
・Cloud Engineer / Freelance ・Geboren 1993 ・Aus Ehime / Wohnhaft in Shibuya, Tokio ・5 Jahre AWS-Erfahrung Profildetails
Inhaltsverzeichnis
– Die CloudFormation-Vorlagen in diesem Artikel folgen den Codierungsrichtlinien für CloudFormation-Vorlagen/SAM-Vorlagen . - CloudFormation Guard wird zur Auswertung von Regelsätzen verwendet, die die Einhaltung des „Center for Internet Security (CIS) Amazon Web Services Foundation v1.4 Level 1“ prüfen. - Da das VSCode-Plugin nicht zur Auswertung verwendet werden kann, verwenden Sie stattdessen den folgenden Befehl:
cfn-guard validate \ --rules ~/cis-aws-benchmark-level-1.guard \ --data ./template.yml
– Die folgende CloudFormation-Vorlage richtet eine grundlegende Athena-Arbeitsgruppe ein. – Das Ziel für Serverzugriffsprotokolle ist der Bucket, der für die Überwachungsprotokollspeicherung in Amazon S3 Sample Code Collection definiert ist. – Wie in Amazon S3 Server Access Logging Now Supports Date-Based Partitioning beschrieben, können Serverzugriffsprotokolle jetzt nach Datum partitioniert werden.Daher ist der Pfad so konfiguriert, dass er nach der Ereigniszeit von S3-Ereignissen aufgeteilt wird. – Der Protokollaufbewahrungszeitraum ist auf 45 Tage festgelegt und entspricht dem Aufbewahrungszeitraum des Abfrageverlaufs. - Anzeigen aktueller Abfragen in der Athena-Konsole – Amazon Athena - Während das AWS-Benutzerhandbuch keine spezifischen Informationen zu S3-Bucket-Richtlinien bereitstellt, ermöglicht das Zulassen der Aktionen „s3:PutObject“ und „s3:GetBucketLocation“ Athena den Zugriff auf den Bucket.
AWSTemplateFormatVersion: 2010-09-09 Resources: AthenaBucket01: Type: AWS::S3::Bucket Properties: BucketName: !Sub sample-athena-bucket-${AWS::AccountId}-${AWS::Region} BucketEncryption: ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: SSEAlgorithm: AES256 LifecycleConfiguration: Rules: - Status: Enabled ExpirationInDays: 45 Prefix: athena-query-resultsd/ - Status: Enabled AbortIncompleteMultipartUpload: DaysAfterInitiation: 7 NoncurrentVersionExpirationInDays: 7 PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true LoggingConfiguration: DestinationBucketName: !Sub sample-server-access-log-bucket-${AWS::AccountId}-${AWS::Region} TargetObjectKeyFormat: PartitionedPrefix: PartitionDateSource: EventTime VersioningConfiguration: Status: Enabled AthenaBucketPolicy01: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref AthenaBucket01 PolicyDocument: Version: 2012-10-17 Statement: - Sid: AllowAthenaGetBucketLocation Effect: Allow Principal: Service: - !Sub athena.${AWS::Region}.amazonaws.com Action: - s3:GetBucketLocation - s3:PutObject Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* # 参考: https://docs.aws.amazon.com/ja_jp/securityhub/latest/userguide/s3-controls.html#s3-5 - Sid: AllowSSLRequestsOnly Effect: Deny Principal: '*' Action: s3:* Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* Condition: Bool: aws:SecureTransport: false AthenaWorkgroup01: Type: AWS::Athena::WorkGroup Properties: Name: sample-athena-workgroup State: ENABLED WorkGroupConfiguration: EngineVersion: SelectedEngineVersion: AUTO ResultConfiguration: OutputLocation: !Sub s3://${AthenaBucket01}/athena-query-results/ EncryptionConfiguration: EncryptionOption: SSE_S3
– Die folgende CloudFormation-Vorlage konfiguriert eine Glue-Datenbank zum Analysieren von Protokollen, die im Audit-Log-Bucket und Serverzugriffs-Log-Bucket gesammelt wurden, beschrieben in 【IaC】Amazon S3 Sample Code Collection . - Zu den unterstützten AWS-Diensten gehören AWS Config, AWS CloudTrail, Amazon GuardDuty, Amazon VPC Flow Logs und S3 Server Access Logs.
– Für alle Tabellen werden drei Partitionsschlüssel mithilfe der Partitionsprojektion festgelegt: „Konto“, „Region“ und „Zeitstempel“. - „Konto“ ist eine 12-stellige Ganzzahl, „Region“ ist ein Zeichenfolgentyp für AWS-Regionsnamen und „Zeitstempel“ ist ein Datumstyp mit einem Bereich von vor sieben Jahren bis heute. - Darüber hinaus ist „Region“ ein Aufzählungstyp, der AWS-Regionsnamen auflistet. – Für die Serverzugriffsprotokolltabelle wird ein zusätzlicher Partitionsschlüssel „source_bucket_name“ hinzugefügt. – Dies wird als Partitionsschlüssel für den S3-Bucket-Namen festgelegt, der Serverzugriffsprotokolle aufzeichnet.
„yaml AWSTemplateFormatVersion: 2010-09-09 Ressourcen: GlueDatabase01: Typ: AWS::Glue::Database Eigenschaften: Datenbankeingabe: Name: sample_glue_database Katalog-ID: !Ref AWS::AccountId
CloudTrailTable01: Typ: AWS::Glue::Table Eigenschaften: Datenbankname: !Ref GlueDatabase01 Katalog-ID: !Ref AWS::AccountId Tabelleneingabe: Tabellentyp: EXTERNAL_TABLE Name: cloud_trail Partitionsschlüssel: - Name: Konto Typ: Zeichenfolge - Name: Region Typ: Zeichenfolge - Name: Zeitstempel Typ: Zeichenfolge Parameter: project.enabled: wahr project.account.type: Ganzzahl Projektion.Konto.Ziffer: 12 project.account.range: 000000000000,999999999999 Projektion.Zeitstempel.Typ: Datum project.timestamp.range: NOW-7YEARS,NOW Projektions-Zeitstempelformat: jjjj/MM/tt Projektion.Zeitstempel.Intervall: 1 project.timestamp.interval.unit: TAGE project.region.type: enum project.region.values:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 EXTERNES: WAHR storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C l o u d T r a i l / {!region}/ ! t i m e s t a m p S t o r a g e D e s c r i p t o r : S p e i c h e r o r t : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ Eingabeformat: com.amazon.emr.cloudtrail.CloudTrailInputFormat Ausgabeformat: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat Komprimiert: falsch SerdeInfo: Serialisierungsbibliothek: com.amazon.emr.hive.serde.CloudTrailSerde StoredAsSubDirectories: false Spalten: - Name: Eventversion Typ: Zeichenfolge - Name: Benutzeridentität Typ:struct<type:string,principalId:string,arn:string,accountId:string,invokedBy:string,accessKeyId:string,userName:string,sessionContext:struct<attributes:struct<mfaAuthenticated:string,creationDate:string>,sessionIssuer:struct<type:string,principalId:string,arn:string,accountId:string,userName:string>>> - Name: Ereigniszeit Typ: Zeichenfolge - Name: Ereignisquelle Typ: Zeichenfolge - Name: Ereignisname Typ: Zeichenfolge - Name: awsregion Typ: Zeichenfolge - Name: Quell-IP-Adresse Typ: Zeichenfolge - Name: Benutzeragent Typ: Zeichenfolge - Name: Fehlercode Typ: Zeichenfolge - Name: Fehlermeldung Typ: Zeichenfolge - Name: Anforderungsparameter Typ: Zeichenfolge - Name: Antwortelemente Typ: Zeichenfolge - Name: zusätzliche Ereignisdaten Typ: Zeichenfolge - Name: Anfrage-ID Typ: Zeichenfolge - Name: Ereignis-ID Typ: Zeichenfolge - Name: Ressourcen Typ: array<struct<arn:string,accountId:string,type:string>> - Name: Ereignistyp Typ: Zeichenfolge - Name: Apiversion Typ: Zeichenfolge - Name: schreibgeschützt Typ: Zeichenfolge - Name: Empfängerkonto-ID Typ: Zeichenfolge - Name: serviceeventdetails Typ: Zeichenfolge - Name: sharedeventid Typ: Zeichenfolge - Name: vpcendpointid Typ: Zeichenfolge
ConfigTable01: Typ: AWS::Glue::Table Eigenschaften: Katalog-ID: !Ref AWS::AccountId Datenbankname: !Ref GlueDatabase01 Tabelleneingabe: Name: Konfig Partitionsschlüssel: - Name: Konto Typ: Zeichenfolge - Name: Region Typ: Zeichenfolge - Name: Zeitstempel Typ: Zeichenfolge Parameter: project.enabled: wahr project.account.type: Ganzzahl Projektion.Konto.Ziffer: 12 project.account.range: 000000000000,999999999999 Projektion.Zeitstempel.Typ: Datum project.timestamp.range: NOW-7YEARS,NOW Projektions-Zeitstempelformat: jjjj/MM/tt Projektion.Zeitstempel.Intervall: 1 project.timestamp.interval.unit: TAGE project.region.type: enum project.region.values:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C o n f i g / {!region}/ ! t i m e s t a m p T a b e l l e n t y p : E X T E R N A L T A B L E S t o r a g e D e s c r i p t o r : S p e i c h e r o r t : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ Eingabeformat: com.amazon.emr.cloudtrail.CloudTrailInputFormat Ausgabeformat: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat SerdeInfo: Serialisierungsbibliothek: org.apache.hive.hcatalog.data.JsonSerDe Spalten: - Name: Dateiversion Typ: Zeichenfolge - Name: configSnapshotId Typ: Zeichenfolge - Name: Konfigurationselemente Typ: array<struct<configurationItemVersion:string,configurationItemCaptureTime:string,configurationStateId:bigint,awsAccountId:string,configurationItemStatus:string,resourceType:string,resourceId:string,resourceName:string,ARN:string,awsRegion:string,availabilityZone:string,configurationStateMd5Hash:string,resourceCreationTime:string>>
GuardDutyTable01: Typ: AWS::Glue::Table Eigenschaften: Datenbankname: !Ref GlueDatabase01 Katalog-ID: !Ref AWS::AccountId Tabelleneingabe: Tabellentyp: EXTERNAL_TABLE Name: Guard_Duty Partitionsschlüssel: - Name: Konto Typ: Zeichenfolge - Name: Region Typ: Zeichenfolge - Name: Zeitstempel Typ: Zeichenfolge Parameter: project.enabled: wahr project.account.type: Ganzzahl Projektion.Konto.Ziffer: 12 project.account.range: 000000000000,999999999999 Projektion.Zeitstempel.Typ: Datum project.timestamp.range: NOW-1YEARS,NOW Projektions-Zeitstempelformat: jjjj/MM/tt Projektion.Zeitstempel.Intervall: 1 project.timestamp.interval.unit: TAGE project.region.type: enum project.region.values:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 EXTERNES: WAHR storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / G u a r d D u t y / {!region}/ ! t i m e s t a m p S t o r a g e D e s c r i p t o r : S p e i c h e r o r t : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ Eingabeformat: org.apache.hadoop.mapred.TextInputFormat Ausgabeformat: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat Komprimiert: falsch SerdeInfo: Serialisierungsbibliothek: org.openx.data.jsonserde.JsonSerDe StoredAsSubDirectories: false Spalten: - Name: Schemaversion Typ: Zeichenfolge - Name: Konto-ID Typ: Zeichenfolge - Name: Region Typ: Zeichenfolge - Name: Partition Typ: Zeichenfolge - Name: ID Typ: Zeichenfolge - Name: Arn Typ: Zeichenfolge - Name: Typ Typ: Zeichenfolge - Name: Ressource Typ: struct<resourcetype:string,accesskeydetails:struct<accesskeyid:string,principalid:string,usertype:string,username:string>> - Name: Dienst Typ:struct<servicename:string,detectorid:string,action:struct<actiontype:string,awsapicallaction:struct<api:string,servicename:string,callertype:string,remoteipdetails:struct<ipaddressv4:string,organization:struct<asn:string,asnorg:string,isp:string,org:string>,country:struct ,city:struct ,geolocation:struct<lat:float,lon:float>>,affectedresources:string>>,resourcerole:string,additionalinfo:struct<recentapicalls:array<struct<api:string,count:int>>>,evidence:string,eventfirstseen:string,eventlastseen:string,archived:boolean,count:int> - Name: Schweregrad Typ: int - Name: erstellt am Typ: Zeichenfolge - Name: aktualisiert am Typ: Zeichenfolge - Name: Titel Typ: Zeichenfolge - Name: Beschreibung Typ: Zeichenfolge
VPCFlowLogsTable01: Typ: AWS::Glue::Table Eigenschaften: Datenbankname: !Ref GlueDatabase01 Katalog-ID: !Ref AWS::AccountId Tabelleneingabe: Tabellentyp: EXTERNAL_TABLE Name: vpc_flow_logs Partitionsschlüssel: - Name: Konto Typ: Zeichenfolge - Name: Region Typ: Zeichenfolge - Name: Zeitstempel Typ: Zeichenfolge Parameter: project.enabled: wahr project.account.type: Ganzzahl Projektion.Konto.Ziffer: 12 project.account.range: 000000000000,999999999999 Projektion.Zeitstempel.Typ: Datum project.timestamp.range: NOW-7YEARS,NOW Projektions-Zeitstempelformat: jjjj/MM/tt Projektion.Zeitstempel.Intervall: 1 project.timestamp.interval.unit: TAGE project.region.type: enum project.region.values:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 EXTERNES: WAHR storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / v p c f l o w l o g s / {!region}/ ! t i m e s t a m p S t o r a g e D e s c r i p t o r : S p e i c h e r o r t : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ Eingabeformat: org.apache.hadoop.mapred.TextInputFormat Ausgabeformat: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat SerdeInfo: Serialisierungsbibliothek: org.apache.hadoop.hive.serde2.lazy.LazySimpleSerDe Parameter: field.delim: ’ ’ Skip.header.line.count: 1 Parameter: Klassifizierung: Textdatei Skip.header.line.count: 1 Spalten: - Name: Version Typ: int - Name: Konto-ID Typ: Zeichenfolge - Name: Schnittstellen-ID Typ: Zeichenfolge - Name: srcaddr Typ: Zeichenfolge - Name: dstaddr Typ: Zeichenfolge - Name: Quelle Typ: int - Name: dstport Typ: int - Name: Protokoll Typ: bigint - Name: Pakete Typ: bigint - Name: Bytes Typ: bigint - Name: Start Typ: bigint - Name: Ende Typ: bigint - Name: Aktion Typ: Zeichenfolge - Name: vpc_id Typ: Zeichenfolge - Name: subnet_id Typ: Zeichenfolge - Name: Instanz-ID Typ: Zeichenfolge - Name: tcp_flags Typ: int - Name: Typ Typ: Zeichenfolge - Name: pkt_srcaddr Typ: Zeichenfolge - Name: pkt_dstaddr Typ: Zeichenfolge - Name: az_id Typ: Zeichenfolge - Name: Sublocation_Type Typ: Zeichenfolge - Name: sublocation_id Typ: Zeichenfolge - Name: pkt_src_aws_service Typ: Zeichenfolge - Name: pkt_dst_aws_service Typ: Zeichenfolge - Name: flow_direction Typ: Zeichenfolge - Name: Verkehrspfad Typ: int
ServerAccessLogTable01: Typ: AWS::Glue::Table Eigenschaften: Datenbankname: !Ref GlueDatabase01 Katalog-ID: !Ref AWS::AccountId Tabelleneingabe: Name: server_access_log Tabellentyp: EXTERNAL_TABLE Partitionsschlüssel: - Name: Konto Typ: Zeichenfolge - Name: Region Typ: Zeichenfolge - Name: Zeitstempel Typ: Zeichenfolge - Name: source_bucket_name Typ: Zeichenfolge Parameter: project.enabled: wahr project.account.type: Ganzzahl Projektion.Konto.Ziffer: 12 project.account.range: 000000000000,999999999999 Projektions-Zeitstempelformat: jjjj/MM/tt Projektion.Zeitstempel.Intervall: 1 project.timestamp.interval.unit: TAGE project.timestamp.range: NOW-7YEARS,NOW Projektion.Zeitstempel.Typ: Datum project.region.type: enum project.region.values:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 project.source_bucket_name.type: injiziert storage.location.template: !Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ ! a c c o u n t / {!region}/ ! s o u r c e b u c k e t n a m e / {!timestamp} StorageDescriptor: Speicherort: !Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ Eingabeformat: org.apache.hadoop.mapred.TextInputFormat Ausgabeformat: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat SerdeInfo: Serialisierungsbibliothek: org.apache.hadoop.hive.serde2.RegexSerDe Parameter: input.regex: ’([^ ] ) ([^ ] ) [(. ?)] ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ("[^\"] "|-) (-|[0-9] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] )([^ ] ) ([^ ] ) ("[^\"] "|-) ([^ ] )(?: ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ))?.*$’ Spalten: - Name: Eimerbesitzer Typ: Zeichenfolge - Name: Bucket_Name Typ: Zeichenfolge - Name: Anfragedatum/Uhrzeit Typ: Zeichenfolge - Name: remoteip Typ: Zeichenfolge - Name: Antragsteller Typ: Zeichenfolge - Name: Anfrage-ID Typ: Zeichenfolge - Name: Operation Typ: Zeichenfolge - Name: Schlüssel Typ: Zeichenfolge - Name: request_uri Typ: Zeichenfolge - Name: httpstatus Typ: Zeichenfolge - Name: Fehlercode Typ: Zeichenfolge - Name: bytessent Typ: bigint - Name: Objektgröße Typ: bigint - Name: Gesamtzeit Typ: Zeichenfolge - Name: Bearbeitungszeit Typ: Zeichenfolge - Name: Referrer Typ: Zeichenfolge - Name: Benutzeragent Typ: Zeichenfolge - Name: Versions-ID Typ: Zeichenfolge - Name: hostid Typ: Zeichenfolge - Name: sigv Typ: Zeichenfolge - Name: Ciphersuite Typ: Zeichenfolge - Name: Authentifizierungstyp Typ: Zeichenfolge - Name: Endpunkt Typ: Zeichenfolge - Name: tlsversion Typ: Zeichenfolge - Name: accesspointarn Typ: Zeichenfolge - Name: erforderlich Typ: Zeichenfolge