[AWS Explained] Security
CloudTrail
You can use
- CloudTrail to stream log into CloudWatch Logs
- Then in the CloudWatch, you can setup Metric Filters based on certain condition, (e.g count occurrenencs)
- Set up a CloudWatch Alaram based on Metric filter, trigger alarm once over the limit
- Can notifiy by SNS
You can set up Organization Trail to collect all the CloudTrail events from Children account.
- Organization Trail has to be setup in Mangement account
How to react faster?
Overall, CloudTrail may takeup 15 mins to deliver events
To Speed up:
- CloudWatch Events: Which can be triggered by any API call in CloudTrail, the fastest, most reactive way
- CloudTrail Delivery in CloudWatch Logs: Events are streamed, can perform a metric filter to analyze occurrences and detect anomalies
- CloudTrail Delivery in S3: Events are delivered every 5 mins, possibility of analyzing logs integrity, deliver cross account, long-term storage
S3 Access Points
Previously, you can restrict S3 access by using
- IAM role
- S3 bucket policy
The problem for both is the complexity of the policy / role rules can grow fast and complex.
Access points breaks the complex by two parts:
- Access points only do the mappings, which access points access which buckets
- One policy per access point
- For each VPC, using VPC Gateway Endpoint to access S3
- Define Endpoint Policy rules inside Each VPC
- Access point for Bucket only allow access From VPC
SSL
Normally handle SSL on ALB
It is also possible to handle SSL on EC2 server.
EC2 can retrieve SSL private key at EC2 boot time.
EC2 need to performing SSL encryption / decryption
But it requries CPU, might slow down the applications
One way to improve it is by using CloudHSM SSL Offloading
分类:
AWS
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 阿里最新开源QwQ-32B,效果媲美deepseek-r1满血版,部署成本又又又降低了!
· Manus重磅发布:全球首款通用AI代理技术深度解析与实战指南
· 开源Multi-agent AI智能体框架aevatar.ai,欢迎大家贡献代码
· 被坑几百块钱后,我竟然真的恢复了删除的微信聊天记录!
· AI技术革命,工作效率10个最佳AI工具
2020-03-04 [AST Babel] Babel Template
2020-03-04 [HTML5] Layout Reflow & thrashing
2019-03-04 [Transducer] Make Transducer works for Iteratable collection and Object
2019-03-04 [Algorithm -- Dynamic programming] 91. Decode Ways <How Many Ways to Decode This Message?>
2016-03-04 [CSS] CSS Transitions: Delays and Multiple Properties
2016-03-04 [ReactJS] DOM Event Listeners in a React Component
2015-03-04 [Javascript + lodash] sortBy and sortedIndex