Kanji
・雲端架構工程師 / 自由職業 ・1993年出生 ・愛媛縣出身 / 現居東京都澀谷區 ・5年 AWS 實戰經驗 個人檔案詳情
目錄
cfn-guard validate \ --rules ~/cis-aws-benchmark-level-1.guard \ --data ./template.yml
s3:PutObject
s3:GetBucketLocation
AWSTemplateFormatVersion: 2010-09-09 Resources: AthenaBucket01: Type: AWS::S3::Bucket Properties: BucketName: !Sub sample-athena-bucket-${AWS::AccountId}-${AWS::Region} BucketEncryption: ServerSideEncryptionConfiguration: - ServerSideEncryptionByDefault: SSEAlgorithm: AES256 LifecycleConfiguration: Rules: - Status: Enabled ExpirationInDays: 45 Prefix: athena-query-resultsd/ - Status: Enabled AbortIncompleteMultipartUpload: DaysAfterInitiation: 7 NoncurrentVersionExpirationInDays: 7 PublicAccessBlockConfiguration: BlockPublicAcls: true BlockPublicPolicy: true IgnorePublicAcls: true RestrictPublicBuckets: true LoggingConfiguration: DestinationBucketName: !Sub sample-server-access-log-bucket-${AWS::AccountId}-${AWS::Region} TargetObjectKeyFormat: PartitionedPrefix: PartitionDateSource: EventTime VersioningConfiguration: Status: Enabled AthenaBucketPolicy01: Type: AWS::S3::BucketPolicy Properties: Bucket: !Ref AthenaBucket01 PolicyDocument: Version: 2012-10-17 Statement: - Sid: AllowAthenaGetBucketLocation Effect: Allow Principal: Service: - !Sub athena.${AWS::Region}.amazonaws.com Action: - s3:GetBucketLocation - s3:PutObject Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* # 參考: https://docs.aws.amazon.com/ja_jp/securityhub/latest/userguide/s3-controls.html#s3-5 - Sid: AllowSSLRequestsOnly Effect: Deny Principal: '*' Action: s3:* Resource: - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01} - !Sub arn:${AWS::Partition}:s3:::${AthenaBucket01}/* Condition: Bool: aws:SecureTransport: false AthenaWorkgroup01: Type: AWS::Athena::WorkGroup Properties: Name: sample-athena-workgroup State: ENABLED WorkGroupConfiguration: EngineVersion: SelectedEngineVersion: AUTO ResultConfiguration: OutputLocation: !Sub s3://${AthenaBucket01}/athena-query-results/ EncryptionConfiguration: EncryptionOption: SSE_S3
以下 CloudFormation 模板配置 Glue 資料庫,用於分析 【IaC】Amazon S3 示例程式碼集合 中描述的稽核日誌儲存桶和伺服器訪問日誌儲存桶中累積的日誌。
支援的 AWS 服務包括 AWS Config、AWS CloudTrail、Amazon GuardDuty、Amazon VPC 流日誌和 S3 伺服器訪問日誌。
建立一個包含五個表的資料庫:
CloudTrail 表
配置表
警衛值班表
VPC流日誌表
伺服器訪問日誌表
對於所有表,使用分割槽投影設定三個分割槽鍵:“account”、“region”和“timestamp”。
account 是一個 12 位整數, region 是 AWS 區域名稱的字串型別,而 timestamp 是日期型別,範圍從七年前到現在。
account
region
timestamp
此外,“region”是列出 AWS 區域名稱的列舉型別。
對於伺服器訪問日誌表,新增了一個額外的分割槽鍵“source_bucket_name”。
設定為記錄伺服器訪問日誌的 S3 儲存桶名稱的分割槽鍵。
````yaml AWSTemplateFormat版本:2010-09-09 資源: 膠水資料庫01: 型別:AWS::Glue::資料庫 特性: 資料庫輸入: 名稱:sample_glue_database CatalogId: !Ref AWS::AccountId
雲蹤表01: 型別:AWS::Glue::Table 特性: 資料庫名稱:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表輸入: 表型別:EXTERNAL_TABLE 名稱:cloud_trail 分割槽鍵: - 名稱:賬戶 型別:字串 - 名稱:地區 型別:字串 - 名稱:時間戳 型別:字串 引數: 投影.啟用:true 投影.帳戶.型別:整數 投影.帳戶.數字: 12 投影.帳戶.範圍: 000000000000,999999999999 projection.timestamp.type:日期 投影.時間戳.範圍:現在-7年,現在 投影.時間戳.格式:yyyy/MM/dd 投影.時間戳.間隔: 1 投影.時間戳.間隔.單位:天 投影.區域.型別:列舉 投影.區域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 外部:正確 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C l o u d T r a i l / {!region}/ ! t i m e s t a m p 儲 存 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 輸入格式:com.amazon.emr.cloudtrail.CloudTrailInputFormat 輸出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 壓縮:假 序列資訊: 序列化庫:com.amazon.emr.hive.serde.CloudTrailSerde 儲存為子目錄: false 欄目: - 名稱:事件版本 型別:字串 - 名稱:使用者身份 型別: struct<type:string,principalId:string,arn:string,accountId:string,invokedBy:string,accessKeyId:string,userName:string,sessionContext:struct<attributes:struct<mfaAuthenticated:string,creationDate:string>,sessionIssuer:struct<type:string,principalId:string,arn:string,accountId:string,userName:string>>> - 名稱:活動時間 型別:字串 - 名稱:事件源 型別:字串 - 名稱:活動名稱 型別:字串 - 名稱:awsregion 型別:字串 - 名稱:源 IP 地址 型別:字串 - 名稱:使用者代理 型別:字串 - 名稱:錯誤程式碼 型別:字串 - 名稱:錯誤訊息 型別:字串 - 名稱:請求引數 型別:字串 - 名稱:響應元素 型別:字串 - 名稱:附加事件資料 型別:字串 - 名稱:請求ID 型別:字串 - 名稱:事件ID 型別:字串 - 名稱:資源 型別:陣列<struct<arn:string,accountId:string,type:string>> - 名稱:事件型別 型別:字串 - 名稱:apiversion 型別:字串 - 名稱:只讀 型別:字串 - 名稱:收件人帳戶 ID 型別:字串 - 名稱:服務事件詳細資訊 型別:字串 - 名稱:sharedeventid 型別:字串 - 名稱:vpcendpointid 型別:字串
配置表01: 型別:AWS::Glue::Table 特性: CatalogId: !Ref AWS::AccountId 資料庫名稱:!Ref GlueDatabase01 表輸入: 名稱:配置 分割槽鍵: - 名稱:賬戶 型別:字串 - 名稱:地區 型別:字串 - 名稱:時間戳 型別:字串 引數: 投影.啟用:true 投影.帳戶.型別:整數 投影.帳戶.數字: 12 投影.帳戶.範圍: 000000000000,999999999999 projection.timestamp.type:日期 投影.時間戳.範圍:現在-7年,現在 投影.時間戳.格式:yyyy/MM/dd 投影.時間戳.間隔: 1 投影.時間戳.間隔.單位:天 投影.區域.型別:列舉 投影.區域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / C o n f i g / {!region}/ ! t i m e s t a m p 表 型 別 : E X T E R N A L T A B L E 儲 存 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 輸入格式:com.amazon.emr.cloudtrail.CloudTrailInputFormat 輸出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 序列資訊: 序列化庫:org.apache.hive.hcatalog.data.JsonSerDe 欄目: - 名稱:檔案版本 型別:字串 - 名稱:configSnapshotId 型別:字串 - 名稱:配置項 型別:陣列<結構<configurationItemVersion:字串,configurationItemCaptureTime:字串,configurationStateId:bigint,awsAccountId:字串,configurationItemStatus:字串,resourceType:字串,resourceId:字串,resourceName:字串,ARN:字串,awsRegion:字串,availabilityZone:字串,configurationStateMd5Hash:字串,resourceCreationTime:字串>>
警衛值班表01: 型別:AWS::Glue::Table 特性: 資料庫名稱:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表輸入: 表型別:EXTERNAL_TABLE 名稱:守衛值班 分割槽鍵: - 名稱:賬戶 型別:字串 - 名稱:地區 型別:字串 - 名稱:時間戳 型別:字串 引數: 投影.啟用:true 投影.帳戶.型別:整數 投影.帳戶.數字: 12 投影.帳戶.範圍: 000000000000,999999999999 projection.timestamp.type:日期 投影.時間戳.範圍:NOW-1年,現在 投影.時間戳.格式:yyyy/MM/dd 投影.時間戳.間隔: 1 投影.時間戳.間隔.單位:天 投影.區域.型別:列舉 投影.區域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 外部:正確 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / G u a r d D u t y / {!region}/ ! t i m e s t a m p 儲 存 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 輸入格式:org.apache.hadoop.mapred.TextInputFormat 輸出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 壓縮:假 序列資訊: 序列化庫:org.openx.data.jsonserde.JsonSerDe 儲存為子目錄: false 欄目: - 名稱:架構版本 型別:字串 - 名稱:賬戶ID 型別:字串 - 名稱:地區 型別:字串 - 名稱:分割槽 型別:字串 - 姓名:身份證號 型別:字串 - 姓名:阿恩 型別:字串 - 名稱:型別 型別:字串 - 名稱:資源 型別: struct<resourcetype:string,accesskeydetails:struct<accesskeyid:string,principalid:string,usertype:string,username:string>> - 名稱:服務 型別:struct<servicename:string,Detectorid:string,action:struct<actiontype:string,awsapicallaction:struct<api:string,servicename:string,callertype:string,remoteipdetails:struct<ipaddressv4:string,organization:struct<asn:string,asnorg:string,isp:string,org:string>,country:struct<國家/地區名稱:字串>,城市:結構<城市名稱:字串>,地理位置:結構<緯度:浮點,經度:浮點>>,受影響的資源:字串>>,資源角色:字串,附加資訊:結構<recentapicalls:陣列<結構<api:字串,計數:int>>>,證據:字串,eventfirstseen:字串,eventlastseen:字串,存檔:布林值,計數:int> - 名稱:嚴重性 型別:整數 - 名稱:建立於 型別:字串 - 名稱:更新日期 型別:字串 - 姓名:標題 型別:字串 - 名稱:描述 型別:字串
VPCFlowLogs表01: 型別:AWS::Glue::Table 特性: 資料庫名稱:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表輸入: 表型別:EXTERNAL_TABLE 名稱:vpc_flow_logs 分割槽鍵: - 名稱:賬戶 型別:字串 - 名稱:地區 型別:字串 - 名稱:時間戳 型別:字串 引數: 投影.啟用:true 投影.帳戶.型別:整數 投影.帳戶.數字: 12 投影.帳戶.範圍: 000000000000,999999999999 projection.timestamp.type:日期 投影.時間戳.範圍:現在-7年,現在 投影.時間戳.格式:yyyy/MM/dd 投影.時間戳.間隔: 1 投影.時間戳.間隔.單位:天 投影.區域.型別:列舉 投影.區域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 外部:正確 storage.location.template: !Sub s3://sample-audit-bucket- A W S : : A c c o u n t I d − {AWS::Region}/AWSLogs/ ! a c c o u n t / v p c f l o w l o g s / {!region}/ ! t i m e s t a m p 儲 存 描 述 符 : 位 置 :! S u b s 3 : // s a m p l e − a u d i t − b u c k e t − {AWS::AccountId}-${AWS::Region}/AWSLogs/ 輸入格式:org.apache.hadoop.mapred.TextInputFormat 輸出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 序列資訊: 序列化庫:org.apache.hadoop.hive.serde2.lazy.LazySimpleSerDe 引數: 欄位.delim: ’ ’ 跳過標題行數:1 引數: 分類: 文字檔案 跳過標題行數:1 欄目: - 名稱:版本 型別:整數 - 名稱:account_id 型別:字串 - 名稱:interface_id 型別:字串 - 名稱:srcaddr 型別:字串 - 名稱:dstaddr 型別:字串 - 名稱:srcport 型別:整數 - 名稱:目的地埠 型別:整數 - 名稱:協議 型別:bigint - 名稱:資料包 型別:bigint - 名稱:位元組 型別:bigint - 名稱:開始 型別:bigint - 名稱:結束 型別:bigint - 名稱:行動 型別:字串 - 名稱:vpc_id 型別:字串 - 名稱:subnet_id 型別:字串 - 名稱:instance_id 型別:字串 - 名稱:tcp_flags 型別:整數 - 名稱:型別 型別:字串 - 名稱:pkt_srcaddr 型別:字串 - 名稱:pkt_dstaddr 型別:字串 - 名稱:az_id 型別:字串 - 名稱:子位置_型別 型別:字串 - 名稱:sublocation_id 型別:字串 - 名稱:pkt_src_aws_service 型別:字串 - 名稱:pkt_dst_aws_service 型別:字串 - 名稱:流向 型別:字串 - 名稱:交通路徑 型別:整數
伺服器訪問日誌表01: 型別:AWS::Glue::Table 特性: 資料庫名稱:!Ref GlueDatabase01 CatalogId: !Ref AWS::AccountId 表輸入: 名稱:伺服器訪問日誌 表型別:EXTERNAL_TABLE 分割槽鍵: - 名稱:賬戶 型別:字串 - 名稱:地區 型別:字串 - 名稱:時間戳 型別:字串 - 名稱:源儲存桶名稱 型別:字串 引數: 投影.啟用:true 投影.帳戶.型別:整數 投影.帳戶.數字: 12 投影.帳戶.範圍: 000000000000,999999999999 投影.時間戳.格式:yyyy/MM/dd 投影.時間戳.間隔: 1 投影.時間戳.間隔.單位:天 投影.時間戳.範圍:現在-7年,現在 projection.timestamp.type:日期 投影.區域.型別:列舉 投影.區域.值:us-east-1,us-east-2,us-west-1,us-west-2,af-south-1,ap-east-1,ap-south-1,ap-northeast-2,ap-southeast-1,ap-southeast-2、ap-northeast-1、ca-central-1、eu-central-1、eu-west-1、eu-west-2、eu-south-1、eu-west-3、eu-north-1、me-south-1、sa-east-1 projection.source_bucket_name.type:注入 storage.location.template: !Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ ! a c c o u n t / {!region}/ ! s o u r c e b u c k e t n a m e / {!timestamp} 儲存描述符: 位置:!Sub s3://sample-server-access-log-bucket- A W S : : A c c o u n t I d − {AWS::Region}/ 輸入格式:org.apache.hadoop.mapred.TextInputFormat 輸出格式:org.apache.hadoop.hive.ql.io.HiveIgnoreKeyTextOutputFormat 序列資訊: 序列化庫:org.apache.hadoop.hive.serde2.RegexSerDe 引數: input.regex: ’([^ ] ) ([^ ] ) [(. ?)] ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ("[^\"] "|-) (-|[0-9] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] )([^ ] ) ([^ ] ) ("[^\"] "|-) ([^ ] )(?: ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ) ([^ ] ))?.*$’ 欄目: - 姓名:bucketowner 型別:字串 - 名稱:bucket_name 型別:字串 - 名稱:請求日期時間 型別:字串 - 名稱:remoteip 型別:字串 - 姓名:請求者 型別:字串 - 名稱:請求ID 型別:字串 - 名稱:操作 型別:字串 - 名稱:鑰匙 型別:字串 - 名稱:request_uri 型別:字串 - 名稱:httpstatus 型別:字串 - 名稱:錯誤程式碼 型別:字串 - 名稱:位元組傳送 型別:bigint - 名稱:物件大小 型別:bigint - 名稱:總時間 型別:字串 - 名稱:週轉時間 型別:字串 - 姓名:推薦人 型別:字串 - 名稱:使用者代理 型別:字串 - 名稱:版本號 型別:字串 - 名稱:主機ID 型別:字串 - 名稱:sigv 型別:字串 - 名稱:密碼套件 型別:字串 - 名稱:驗證型別 型別:字串 - 名稱:端點 型別:字串 - 名稱:tlsversion 型別:字串 - 名稱:接入點arn 型別:字串 - 名稱:acl必填 型別:字串