Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Security-JAWS IAMの設計を言語化する

Takuro SASAKI
November 11, 2019

Security-JAWS IAMの設計を言語化する

2019年11月11日にSecurity-JAWSで発表した資料です
https://s-jaws.doorkeeper.jp/events/99569

Takuro SASAKI

November 11, 2019
Tweet

More Decks by Takuro SASAKI

Other Decks in Technology

Transcript

  1. "84ͱηΩϡϦςΟ #secjaws "84ͷηΩϡϦςΟ͸ͭͷ࣠Ͱߟ͑Δ ᶃ"84಺ʹߏஙͨ͠ωοτϫʔΫͱαʔόʔͷηΩϡϦςΟ ᶄ"84ͷαʔϏε܈ͷઃܭɾઃఆ ᶅ"84ૢ࡞ʹؔ͢Δݖݶʢ*".ʣ ᶆηΩϡϦςΟΛҡ࣋؅ཧ͢ΔͨΊͷ"84αʔϏε AWS Management Console

    Role VPC AWS Cloud Subnet Internet gateway Amazon Simple Storage Service (S3) VPN gateway Endpoints User ૢ࡞ݖݶ Instance Instance Instance AWS Lambda Role ᶅ ᶄ ᶃ AWS Command Line Interface AWS Config AWS Systems Manager AWS Service Catalog AWS Trusted Advisor AWS CloudTrail ᶆ ηΩϡϦςΟΛҡ࣋ ؅ཧ͢ΔαʔϏε
  2. ڐՄ͢ΔݖݶͷΈ෇༩͍ͯ͘͠ύλʔϯɹɹ &$΍4ͱ͍ͬͨαʔϏε୯Ґ΍ɺߋʹࡉ͔͘ΞΫγϣϯ୯ҐͰ෇༩ "84؅ཧϙϦγʔ΋ɺ͋ΔҙຯϗϫΠτϦετύλʔϯ ˞Ͱ΋ɺͦͷ··࢖͏ʹ͸ૈ͍ #secjaws ϗϫΠτϦετɾύλʔϯ FD %FTDSJCF 4UPQ 4UBSU

    ಛఆͷαʔϏεɾΞΫγϣϯͷΈڐՄ ڋ൱ ڐՄ ڐՄ ڐՄ ڋ൱ ϝϦοτɹ ࠷খݖݶͷઃܭ͕Ͱ͖Δ ཧղͯ͠࡞Ε͹ɺҰ൪ηΩϡΞ σϝϦοτɹ ઃܭ͕ਐ·ͳ͍ͱઃఆͰ͖ͳ͍ ؅ཧෛՙ͕ߴ͍
  3. ڋ൱Λ௥Ճ͍ͯ͘͠ύλʔϯɹɹ ڐՄͯ͠͸͍͚ͳ͍ݖݶΛണୣ͍ͯ͘͠ #secjaws ϒϥοΫϦετɾύλʔϯ ڐՄ 4 &D *". ಛఆͷαʔϏεɾΞΫγϣϯͷΈڋ൱ ڐՄ

    ڋ൱ ڋ൱ ڋ൱ ϝϦοτɹ ઃܭ͕࠷খݶʹͰ͖Δ ࣗ༝౓͕ߴ͍ σϝϦοτɹ ༧ظͤ͵αʔϏε͕ಥવ࢖͑ΔΑ͏ ʹͳΔϦεΫ͕͋Δ
  4. ڞ௨Ͱར༻͢ΔϙϦγʔͰ·ͣݕ౼͢Δͷ͸͜ͷͭ .'"ඞਢԽ͸ඞͣ͢Δ͜ͱ *1੍ݶ͸ɺӡ༻ϙϦγʔͱ૬ஊɻ࡞ۀ৔ॴΛ੍ݶͰ͖Δͱ͍͏ޮՌ͕͋Δ #secjaws .'"ඞਢԽͱ*1੍ݶ \ &⒎FDU%FOZ  "DUJPO 

     $POEJUJPO\ /PU*Q"EESFTT\ BXT4PVSDF*Q<  > ^ ^  3FTPVSDF  ^ \ &⒎FDU%FOZ  /PU"DUJPO< JBN  >  3FTPVSDF   $POEJUJPO\ #PPM*G&YJTUT\ BXT.VMUJ'BDUPS"VUI1SFTFOUGBMTF ^ ^ ^
  5. 1SJODJQBMΛߜΒͳ͍ͱɺશϢʔβʔ͕εΠονͰ͖Δ σϑΥϧτςϯϓϨʔτͷઃఆ͸ɺΞΧ΢ϯτ಺ͷϢʔβʔʹରͯ͠ ߜΔඞཁ͕͋ΓɺϢʔβʔࢦఆͰߜΔʢάϧʔϓ͸Ͱ͖ͳ͍ʣ ผղͱͯ͠"TTVNF3PMFͷݖݶΛ͢΂ͯണୣͷ͏͑ͰɺඞཁͳϢʔβʔʹ ෇༩͢Δͱ͍͏ํ๏΋͋Δ #secjaws εΠονϩʔϧͷ஫ҙ఺ \ 7FSTJPO 

    4UBUFNFOU< \ &⒎FDU"MMPX  1SJODJQBM\ "84BSOBXTJBN SPPU ^  "DUJPOTUT"TTVNF3PMF  $POEJUJPO\^ ^ > ^ \ 7FSTJPO  4UBUFNFOU< \ &⒎FDU"MMPX  1SJODJQBM\ "84BSOBXTJBNVTFSUFTU VTFS ^  "DUJPOTUT"TTVNF3PMF  $POEJUJPO\^ ^ > ^