Upgrade to Pro — share decks privately, control downloads, hide ads and more …

20200209MINI_INFRA

Avatar for delphinz delphinz
February 09, 2020

 20200209MINI_INFRA

Avatar for delphinz

delphinz

February 09, 2020
Tweet

More Decks by delphinz

Other Decks in Technology

Transcript

  1. ࣗݾ঺հ ▸ ా୺ ੓߂(Masahiro Tabata )@delphinz ▸ ීஈ͸ձܭγεςϜίϯαϧλϯτ ▸ MINI

    HardeningӡӦϦʔμʔ(໾ׂ:ࣾ௕) ▸ OWASP JAPANϓϩϞʔγϣϯνʔϜॴଐ ▸ 2019೥ηΩϡΞཱྀஂ ࢀՃ ▸ “झຯͰηΩϡϦςΟΛ΍͍ͬͯΔऀ”Ͱ͢
  2. MINI Hardeningͱ͸ ▸ Hardening Project ͔Β೿ੜͨ͠ϛχϓϩδΣΫτ
 2014೥ͷ Hardening 10 Evolutions

    Πϕϯτʹ͓͍ͯɺ
 ΞϯΧϯϑΝϨϯεͷ੒Ռͱͯ͠ൃ଍ ▸ ΧδϡΞϧʹHardeningΛମݧ–MINI HardeningͰ͸
 ൒೔ఔ౓ͰHardeningڝٕ΍ৼΓฦΓ·ͰମݧͰ͖Δ ▸ ͋͘·Ͱʮॳ৺ऀ޲͚ΠϕϯτʯͰ͢ ίϯηϓτɿ ʮηΩϡϦςΟΠϯγσϯτΛΧδϡΞϧʹମݧʂʯ https://minihardening.connpass.com
  3. Πϯϑϥ୲౰ऀ΁ͷಓ ▸ AWS-CLIɺGitɺAnsibleͷΠϯετʔϧ(׼)
 2018೥2݄຤͔Β2018೥5݄GW໌͚·Ͱ1೔1σϓϩΠमߦʂ ▸ ࣅͨΑ͏ͳ؀ڥΛߏங͍ͯ͠ΔࣄྫΛௐࠪ ▸ Micro Hardening(઒ޱઃܭ)
 ࢀՃऀ͸45෼ͱ͍͏ݶΒΕͨ࣌ؒͷͳ͔Ͱɺఏڙ͞ΕͨECαΠτʹ

    ର͢Δ༷ʑͳαΠόʔ߈ܸʹରॲ͢Δ
 (͘͞ΒͷΫϥ΢υͰTerraform,PackerΛ࢖༻) ▸ 2017/09/14 ʮϛχϓϩάϥϜίϯςετʯ
 ʮαΠόʔԋश؀ڥͷࣗಈߏங(Seed(KBC))ʯ
 (OpenStack্Ͱ࣮ݱ) https://microhardening.connpass.com
  4. ؀ڥల։༻ίʔυΛॻ͘·Ͱ४උ ▸ ݩͷ؀ڥ͔ΒTerraformͷల։༻ίʔυΛϦόʔεΤϯδχ ΞϦϯάʂ MINI Hardening؀ڥ͔Β
 TerraformingΛ࢖ͬͯ ઃఆϑΝΠϧ(*.tf)Λੜ੒ ੜ੒ͨ͠tfϑΝΠϧͷ ݻ༗IDΛશͯม਺Խ

    ڞ௨ม਺Λઃఆ AWSͷߏஙʹඞཁͳઃఆϑΝΠϧ ec2.tf igw.tf nif.tf r53z.tf rta.tf sn.tf eip.tf nacl.tf r53r.tf rt.tf sg.tf vpc.tf ڞ௨߲໨ ɾόʔδϣϯ ɾڝٕνʔϜ਺(࠷େ26νʔϜ) ɾϩʔΧϧυϝΠϯ໊ ɾIPΞυϨε(ୈ2ΦΫςοτ·Ͱʣ ɾΠϯελϯεαΠζ
  5. ͜Ε͔Β΍Γ͍ͨ͜ͱ ▸ Terraformͷ0.12όʔδϣϯΞοϓ ▸ WindowsͷAnsibleద༻(ݱࡏ͸Poweshell) ▸ AWSػೳͷࣗಈԽ(cloudtrailɺcloudwatchɺguard duty౳ʣ ▸ CIɺCDͷಋೖ

    ▸ ίʔυͷΦʔϓϯιʔεԽ ▸ ΍ΒΕαʔόΛmetasploitable3Ͱ࡞Δ(ݕূத) ▸ ϞχλϦϯάπʔϧಋೖ(elastic search?) ݸਓͰձࣾͰίϛϡχςΟͰݕূɾԋश΍ͬͪΌ͍ͳΑʂ