Kanji
・클라우드 엔지니어 / 프리랜서 ・1993년생 ・에히메현 출신 / 도쿄도 시부야구 거주 ・AWS 경력 5년 프로필 상세
목차
cfn-guard validate \ --rules ~/cis-aws-benchmark-level-1.guard \ --data ./template.yml
s3:PutObject
s3:GetBucketLocation
AWSTemplateFormatVersion: 2010-09-09 Resources: AthenaBucket01: Type: AWS::S3::Bucket Properties: BucketName: !Sub sample-athena-bucket-${AWS::AccountId}-${AWS::Region} BucketEncryption: ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: SSEAlgorithm: AES256 LifecycleConfiguration: Rules: - Status: Enabled ExpirationInDays: 45 Prefix: athena-query-resultsd/ - Status: Enabled AbortIncompleteMultipartUpload: DaysAfterInitiation: 7 NoncurrentVersionExpirationInDays: 7 PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true LoggingConfiguration: DestinationBucketName: !Sub sample-server-access-log-bucket-${AWS::AccountId}-${AWS::Region} TargetObjectKeyFormat: PartitionedPrefix: PartitionDateSource: EventTime VersioningConfiguration: Status: Enabled AthenaBucketPolicy01: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref AthenaBucket01 PolicyDocument: Version: 2012-10-17 Statement: - Sid: AllowAthenaGetBucketLocation Effect: Allow Principal: Service: - !Sub athena.${AWS::Region}.amazonaws.com Action: - s3:GetBucketLocation - s3:PutObject Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* # 参考: https://docs.aws.amazon.com/ja_jp/securityhub/latest/userguide/s3-controls.html#s3-5 - Sid: AllowSSLRequestsOnly Effect: Deny Principal: '*' Action: s3:* Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* Condition: Bool: aws:SecureTransport: false AthenaWorkgroup01: Type: AWS::Athena::WorkGroup Properties: Name: sample-athena-workgroup State: ENABLED WorkGroupConfiguration: EngineVersion: SelectedEngineVersion: AUTO ResultConfiguration: OutputLocation: !Sub s3://${AthenaBucket01}/athena-query-results/ EncryptionConfiguration: EncryptionOption: SSE_S3
다음 CloudFormation 템플릿은 【IaC】Amazon S3 샘플 코드 모음 에 설명된 감사 로그 버킷과 서버 액세스 로그 버킷에 축적된 로그를 분석하기 위한 Glue 데이터베이스를 구성합니다.
지원되는 AWS 서비스에는 AWS Config, AWS CloudTrail, Amazon GuardDuty, Amazon VPC 흐름 로그 및 S3 서버 액세스 로그가 포함됩니다.
5개의 테이블로 구성된 단일 데이터베이스가 생성됩니다.
CloudTrail 테이블
구성 테이블
GuardDuty 테이블
VPC 흐름 로그 테이블
서버 접속 로그 테이블
모든 테이블에 대해 파티션 프로젝션을 사용하여 ‘account’, ‘region’, ’timestamp’라는 3개의 파티션 키가 설정됩니다.
account 는 12자리 정수, region 은 AWS 리전 이름에 대한 문자열 유형, timestamp 는 7년 전부터 현재까지의 범위를 갖는 날짜 유형입니다.
account
region
timestamp
또한 region 은 AWS 지역 이름을 나열하는 열거형입니다.
서버 액세스 로그 테이블의 경우 추가 파티션 키 ’source_bucket_name’이 추가됩니다.
서버 접속 로그를 기록하는 S3 버킷 이름에 대한 파티션 키로 설정됩니다.
``yaml AWSTemplate형식버전: 2010-09-09 자원: GlueDatabase01: 유형: AWS::Glue::데이터베이스 속성: 데이터베이스입력: 이름: Sample_glue_database CatalogId: !Ref AWS::AccountId
CloudTrailTable01: 유형: AWS::Glue::테이블 속성: 데이터베이스 이름: !Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 테이블 입력: 테이블 유형: EXTERNAL_TABLE 이름: cloud_trail 파티션키: - 이름 : 계정 유형: 문자열 - 이름 : 지역 유형: 문자열 - 이름: 타임스탬프 유형: 문자열 매개변수: 투영.활성화: 사실 투영.계정.유형: 정수 투영.계정.숫자: 12 투영.계정.범위: 000000000000,999999999999 투영.타임스탬프.유형: 날짜 투영.타임스탬프.범위: 지금~7년,지금 투영.타임스탬프.형식: yyyy/MM/dd 투영.타임스탬프.간격: 1 투영.타임스탬프.간격.단위: DAYS 투영.지역.유형: 열거형 투영.지역.값:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 외부: 사실 Storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C l o u d T r a i l / {!region}/ ! t i m e s t a m p 저 장 소 설 명 자 : 위 치 : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 입력 형식: com.amazon.emr.cloudtrail.CloudTrailInputFormat 출력 형식: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 압축: 거짓 Serde정보: 직렬화 라이브러리: com.amazon.emr.hive.serde.CloudTrailSerde StoredAsSubDirectories: 거짓 열: - 이름 : 이벤트버전 유형: 문자열 - 이름 : 사용자 ID 유형:struct<type:string,principalId:string,arn:string,accountId:string,invokedBy:string,accessKeyId:string,userName:string,sessionContext:struct<attributes:struct<mfaAuthenticated:string,creationDate:string>,sessionIssuer:struct<type:string,principalId:string,arn:string,accountId:string,userName:string>>> - 이름 : 이벤트타임 유형: 문자열 - 이름 : 이벤트소스 유형: 문자열 - 이름 : 이벤트명 유형: 문자열 - 이름: awsregion 유형: 문자열 - 이름 : sourceipaddress 유형: 문자열 - 이름 : 사용자 에이전트 유형: 문자열 - 이름 : 오류코드 유형: 문자열 - 이름: 오류 메시지 유형: 문자열 - 이름: 요청 매개변수 유형: 문자열 - 이름: responseelements 유형: 문자열 - 이름 : 추가이벤트데이터 유형: 문자열 - 이름 : 요청ID 유형: 문자열 - 이름 : eventid 유형: 문자열 - 이름 : 자원 유형: array<struct<arn:string,accountId:string,type:string>> - 이름 : 이벤트타입 유형: 문자열 - 이름 : apiversion 유형: 문자열 - 이름: 읽기전용 유형: 문자열 - 이름 : 수신자계정ID 유형: 문자열 - 이름 : serviceeventdetails 유형: 문자열 - 이름: 공유이벤트ID 유형: 문자열 - 이름: vpcendpointid 유형: 문자열
구성 테이블01: 유형: AWS::Glue::테이블 속성: CatalogId: !Ref AWS::AccountId 데이터베이스 이름: !Ref GlueDatabase01 테이블 입력: 이름: 구성 파티션키: - 이름 : 계정 유형: 문자열 - 이름 : 지역 유형: 문자열 - 이름: 타임스탬프 유형: 문자열 매개변수: 투영.활성화: 사실 투영.계정.유형: 정수 투영.계정.숫자: 12 투영.계정.범위: 000000000000,999999999999 투영.타임스탬프.유형: 날짜 투영.타임스탬프.범위: 지금~7년,지금 투영.타임스탬프.형식: yyyy/MM/dd 투영.타임스탬프.간격: 1 투영.타임스탬프.간격.단위: DAYS 투영.지역.유형: 열거형 투영.지역.값:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 Storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C o n f i g / {!region}/ ! t i m e s t a m p 테 이 블 유 형 : E X T E R N A L T A B L E 저 장 소 설 명 자 : 위 치 : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 입력 형식: com.amazon.emr.cloudtrail.CloudTrailInputFormat 출력 형식: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat Serde정보: 직렬화 라이브러리: org.apache.hive.hcatalog.data.JsonSerDe 열: - 이름 : 파일버전 유형: 문자열 - 이름: configSnapshotId 유형: 문자열 - 이름 : 구성항목 유형: array<struct<configurationItemVersion:string,configurationItemCaptureTime:string,configurationStateId:bigint,awsAccountId:string,configurationItemStatus:string,resourceType:string,resourceId:string,resourceName:string,ARN:string,awsRegion:string,availabilityZone:string,configurationStateMd5Hash:string,resourceCreationTime:string>>
GuardDutyTable01: 유형: AWS::Glue::테이블 속성: 데이터베이스 이름: !Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 테이블 입력: 테이블 유형: EXTERNAL_TABLE 이름:guard_duty 파티션키: - 이름 : 계정 유형: 문자열 - 이름 : 지역 유형: 문자열 - 이름: 타임스탬프 유형: 문자열 매개변수: 투영.활성화: 사실 투영.계정.유형: 정수 투영.계정.숫자: 12 투영.계정.범위: 000000000000,999999999999 투영.타임스탬프.유형: 날짜 투영.타임스탬프.범위: 지금~1년,지금 투영.타임스탬프.형식: yyyy/MM/dd 투영.타임스탬프.간격: 1 투영.타임스탬프.간격.단위: DAYS 투영.지역.유형: 열거형 투영.지역.값:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 외부: 사실 Storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / G u a r d D u t y / {!region}/ ! t i m e s t a m p 저 장 소 설 명 자 : 위 치 : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 입력 형식: org.apache.hadoop.mapred.TextInputFormat 출력 형식: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 압축: 거짓 Serde정보: 직렬화 라이브러리: org.openx.data.jsonserde.JsonSerDe StoredAsSubDirectories: 거짓 열: - 이름: 스키마버전 유형: 문자열 - 이름 : 계정아이디 유형: 문자열 - 이름 : 지역 유형: 문자열 - 이름 : 파티션 유형: 문자열 - 이름 : 아이디 유형: 문자열 - 이름 : 아르 유형: 문자열 - 이름 : 종류 유형: 문자열 - 이름 : 자원 유형: struct<resourcetype:string,accesskeydetails:struct<accesskeyid:string,principalid:string,usertype:string,username:string>> - 이름 : 서비스 유형:struct<servicename:string,Detectorid:string,action:struct<actiontype:string,awsapicallaction:struct<api:string,servicename:string,callertype:string,remoteipdetails:struct<ipaddressv4:string,organization:struct<asn:string,asnorg:string,isp:string,org:string>,country:struct ,city:struct ,geolocation:struct<lat:float,lon:float>>,affectedresources:string>>,resourcerole:string,additionalinfo:struct<recentapicalls:array<struct<api:string,count:int>>>,evidence:string,eventfirstseen:string,eventlastseen:string,archived:boolean,count:int> - 이름 : 심각도 유형: 정수 - 이름 : 생성일 유형: 문자열 - 이름 : 업데이트 날짜 유형: 문자열 - 이름 : 제목 유형: 문자열 - 이름 : 설명 유형: 문자열
VPCFlowLogsTable01: 유형: AWS::Glue::테이블 속성: 데이터베이스 이름: !Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 테이블 입력: 테이블 유형: EXTERNAL_TABLE 이름: vpc_flow_logs 파티션키: - 이름 : 계정 유형: 문자열 - 이름 : 지역 유형: 문자열 - 이름: 타임스탬프 유형: 문자열 매개변수: 투영.활성화: 사실 투영.계정.유형: 정수 투영.계정.숫자: 12 투영.계정.범위: 000000000000,999999999999 투영.타임스탬프.유형: 날짜 투영.타임스탬프.범위: 지금~7년,지금 투영.타임스탬프.형식: yyyy/MM/dd 투영.타임스탬프.간격: 1 투영.타임스탬프.간격.단위: DAYS 투영.지역.유형: 열거형 투영.지역.값:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 외부: 사실 Storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / v p c f l o w l o g s / {!region}/ ! t i m e s t a m p 저 장 소 설 명 자 : 위 치 : ! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 입력 형식: org.apache.hadoop.mapred.TextInputFormat 출력 형식: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat Serde정보: 직렬화 라이브러리: org.apache.hadoop.hive.serde2.lazy.LazySimpleSerDe 매개변수: field.delim: ’ ’ Skip.header.line.count: 1 매개변수: 분류: 텍스트파일 Skip.header.line.count: 1 열: - 이름 : 버전 유형: 정수 - 이름 : account_id 유형: 문자열 - 이름 : 인터페이스_ID 유형: 문자열 - 이름 : srcaddr 유형: 문자열 - 이름 : dstaddr 유형: 문자열 - 이름 : srcport 유형: 정수 - 이름 : dstport 유형: 정수 - 이름 : 프로토콜 유형: bigint - 이름 : 패킷 유형: bigint - 이름 : 바이트 유형: bigint - 이름 : 시작 유형: bigint - 이름 : 끝 유형: bigint - 이름 : 액션 유형: 문자열 - 이름 : vpc_id 유형: 문자열 - 이름 : subnet_id 유형: 문자열 - 이름 : 인스턴스_ID 유형: 문자열 - 이름: tcp_flags 유형: 정수 - 이름 : 종류 유형: 문자열 - 이름 : pkt_srcaddr 유형: 문자열 - 이름 : pkt_dstaddr 유형: 문자열 - 이름: az_id 유형: 문자열 - 이름: 하위 위치_유형 유형: 문자열 - 이름: sublocation_id 유형: 문자열 - 이름: pkt_src_aws_service 유형: 문자열 - 이름: pkt_dst_aws_service 유형: 문자열 - 이름 : flow_direction 유형: 문자열 - 이름: Traffic_path 유형: 정수
서버액세스로그테이블01: 유형: AWS::Glue::테이블 속성: 데이터베이스 이름: !Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 테이블 입력: 이름: server_access_log 테이블 유형: EXTERNAL_TABLE 파티션키: - 이름 : 계정 유형: 문자열 - 이름 : 지역 유형: 문자열 - 이름: 타임스탬프 유형: 문자열 - 이름: source_bucket_name 유형: 문자열 매개변수: 투영.활성화: 사실 투영.계정.유형: 정수 투영.계정.숫자: 12 투영.계정.범위: 000000000000,999999999999 투영.타임스탬프.형식: yyyy/MM/dd 투영.타임스탬프.간격: 1 투영.타임스탬프.간격.단위: DAYS 투영.타임스탬프.범위: 지금~7년,지금 투영.타임스탬프.유형: 날짜 투영.지역.유형: 열거형 투영.지역.값:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2,ap-northeast-1,ca-central-1,eu-central-1,eu-west-1,eu-west-2,eu-south-1,eu-west-3,eu-north-1,me-south-1,sa-east-1 projection.source_bucket_name.type: 삽입됨 Storage.location.template: !Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ ! a c c o u n t / {!region}/ ! s o u r c e b u c k e t n a m e / {!timestamp} 저장소 설명자: 위치: !Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ 입력 형식: org.apache.hadoop.mapred.TextInputFormat 출력 형식: org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat Serde정보: 직렬화 라이브러리: org.apache.hadoop.hive.serde2.RegexSerDe 매개변수: input.regex: ’([^ ] ) ([^ ] ) [(. ?)] ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ("[^\"] "|-) (-|[0-9] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] )([^ ] ) ([^ ] ) ("[^\"] "|-) ([^ ] )(?: ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ))?.*$’ 열: - 이름: 버킷소유자 유형: 문자열 - 이름: bucket_name 유형: 문자열 - 이름: requestdatetime 유형: 문자열 - 이름 : 리모트ip 유형: 문자열 - 이름 : 요청자 유형: 문자열 - 이름 : 요청ID 유형: 문자열 - 이름 : 작업 유형: 문자열 - 이름 : 열쇠 유형: 문자열 - 이름 : request_uri 유형: 문자열 - 이름 : httpsstatus 유형: 문자열 - 이름 : 오류코드 유형: 문자열 - 이름: 바이트센트 유형: bigint - 이름 : 객체화 유형: bigint - 이름 : 토탈타임 유형: 문자열 - 이름 : 처리시간 유형: 문자열 - 이름 : 추천인 유형: 문자열 - 이름 : 사용자 에이전트 유형: 문자열 - 이름 : versionid 유형: 문자열 - 이름 : 호스트ID 유형: 문자열 - 이름 : sigv 유형: 문자열 - 이름 : 암호 모음 유형: 문자열 - 이름 : 인증 유형 유형: 문자열 - 이름: 엔드포인트 유형: 문자열 - 이름 : tlsversion 유형: 문자열 - 이름 : accesspointarn 유형: 문자열 - 이름 : acl필수 유형: 문자열