Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
About Extended Threat Detection in Amazon Guard...
Search
takakuni
December 18, 2024
410
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
About Extended Threat Detection in Amazon GuardDuty
takakuni
December 18, 2024
More Decks by takakuni
See All by takakuni
ECS Express Mode
takakuni
0
36
AWS WAF Anti-DDoS Protection in 5 Minutes!
takakuni
0
610
AWS Backup Air-Gapped Vaults with Multi-Party Approval Explained in 5 Minutes!
takakuni
0
310
5min GuardDuty Extended Threat Detection EKS
takakuni
0
380
OpenAI models overview 202505
takakuni
0
440
[Sample] Validate hyperlink for Amazon Bedrock Data Automation
takakuni
0
300
Classmethod AI Talks #13
takakuni
0
430
SageMaker Hyperpod 101 #regrowth_sapporo
takakuni
1
430
What is Amazon Bedrock knowledge base with an Amazon Kendra GenAI index?
takakuni
0
770
Featured
See All Featured
Darren the Foodie - Storyboard
khoart
PRO
3
3.4k
The AI Search Optimization Roadmap by Aleyda Solis
aleyda
1
5.9k
The untapped power of vector embeddings
frankvandijk
2
1.8k
JAMstack: Web Apps at Ludicrous Speed - All Things Open 2022
reverentgeek
1
480
Design of three-dimensional binary manipulators for pick-and-place task avoiding obstacles (IECON2024)
konakalab
0
460
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
560
The B2B funnel & how to create a winning content strategy
katarinadahlin
PRO
1
390
The Psychology of Web Performance [Beyond Tellerrand 2023]
tammyeverts
49
3.5k
Applied NLP in the Age of Generative AI
inesmontani
PRO
4
2.3k
Data-driven link building: lessons from a $708K investment (BrightonSEO talk)
szymonslowik
1
1.1k
Information Architects: The Missing Link in Design Systems
soysaucechin
0
970
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
Transcript
2024/12/18 クラスメソッド株式会社 たかくに Amazon GuardDuty の Extended Threat Detection について
2 • 部署 ◦ AWS 事業本部コンサルティング部 • 名前(ニックネーム) ◦ たかくに
• ロール ◦ ソリューションアーキテクト ⾃⼰紹介
re:Invent 2024 どうでしたか?
GuardDuty でしたね。
Extended Threat Detection の話をします。
Extended Threat Detection とは
拡張脅威検出 です!
拡張脅威検出とは
拡張された脅威を検出する機能!
10 今までの GuardDuty Threat Detection 1. EC2 finding types 2.
IAM finding types 3. S3 Protection finding types 4. EKS Protection finding types 5. GuardDuty Runtime Monitoring finding types 6. Malware Protection for EC2 finding types 7. Malware Protection for S3 finding type 8. RDS Protection finding types 9. Lambda Protection finding types
11 これからの GuardDuty Threat Detection 1. EC2 finding types 2.
IAM finding types 3. S3 Protection finding types 4. EKS Protection finding types 5. GuardDuty Runtime Monitoring finding types 6. Malware Protection for EC2 finding types 7. Malware Protection for S3 finding type 8. RDS Protection finding types 9. Lambda Protection finding types 10. GuardDuty attack sequence finding types(NEW !)
• 複数の脅威が連なった状態を検出 • 普段の検出タイプに加え、弱いシグナルも評価対象 ◦ 弱いシグナル:普段の検出タイプでは表⽰されな い API アクティビティ •
MITRE ATT&CK のステップ別に重要度を表⽰ 12 GuardDuty attack sequence finding types
• Attack sequence ◦ 複数のイベント(シグナル)の相関関係 • Findings ◦ GuardDuty が発⾒した脅威(≒シグナル)
• Signals ◦ GuardDuty が観察した API アクティビティ 13 単語のおさらい
14 図にすると
15 複数の脅威が連なった状態を検出
16 複数の脅威が連なった状態を検出
17 普段の検出タイプに加え、弱いシグナルも評価対象
18 MITRE ATT&CK のステップ別に重要度を表⽰
• AttackSequence:IAM/CompromisedCredentials ◦ IAM が侵害されている可能性が⾼い場合に検出 • AttackSequence:S3/CompromisedData ◦ S3 が漏洩している可能性が⾼い場合に検出
19 GuardDuty attack sequence finding types
None