0% found this document useful (0 votes)
2 views11 pages

Module 20 AWS Security

The document provides an overview of AWS Security, focusing on encryption methods, AWS KMS for key management, and various AWS services for secure data handling. It covers topics such as encryption at rest and in transit, AWS Secrets Manager, AWS Certificate Manager, and security services like AWS WAF, Shield, and Guard Duty. Additionally, it discusses the integration of these services for comprehensive security management in AWS environments.

Uploaded by

premierthesis
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views11 pages

Module 20 AWS Security

The document provides an overview of AWS Security, focusing on encryption methods, AWS KMS for key management, and various AWS services for secure data handling. It covers topics such as encryption at rest and in transit, AWS Secrets Manager, AWS Certificate Manager, and security services like AWS WAF, Shield, and Guard Duty. Additionally, it discusses the integration of these services for comprehensive security management in AWS environments.

Uploaded by

premierthesis
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Pritam Chakraborty

Certified Solutions Architect Associate Exam


Preparation Note

MODULE 20
AWS Security
Encryption

1
▪ 2 Types of Encryption
1. Encryption at Rest

Figure 1 : Data Encryption ~ Rest

2. Encryption during Flight

Figure 2 : Data Encryption ~ Flight

AWS KMS
▪ Anytime you hear "Encryption" for an AWS Service, it's Most Likely KMS AWS
Manages Encryption Keys for us when it is in Encryption at Rest
▪ Fully Integrated with IAM for Authorization***
▪ Easy Way to Control Access to your Data
▪ Able to Audit KMS Key usage Using CloudTrail***
▪ Seamlessly Integrated into Most AWS Services (EBS, S3, RDS, SSM...)
▪ Never ever store your secrets in plaintext, especially in your code!
o KMS Key Encryption also available through API calls (SDK, CLI)
o Encrypted secrets can be stored in the code / environment variables

Pritam
KMS Key Types –

2
▪ KMS Keys is the New Name of KMS Customer Master Key
▪ 2 Types of KMS Keys
1. Symmetric (AES-256 Keys)
o Single Encryption Key that is Used to Encrypt and Decrypt***
o AWS Services that are Integrated with KMS use Symmetric CMKs

Figure 3 : Symmetric Key for Encryption & Decryption

2. Asymmetric (RSA & ECC Key Pairs)


o Public (Encrypt) & Private Key (Decrypt) pair***
o Used for Encrypt/Decrypt, or Sign/Verify operations
o The Public Key is Downloadable can't Access the Private Key (Unencrypted)

Figure 4 : Asymmetric Key for Encryption & Decryption

KMS Multi Region –


▪ Identical KMS keys in different AWS Regions that can be Used Interchangeably Multi-
Region Keys have the Same Key ID, key material, automatic rotation...
▪ Encrypt in One Region and Decrypt in Other Regions***
▪ KMS Multi-Region are NOT Global (Primary + Replicas)***
▪ Each Multi-Region key is managed independently
▪ Use Cases: Global Client-Side Encryption, Encryption on Global DynamoDB, Global
Aurora

Pritam
3
Figure 5 : Multi Region Key

Encrypted AMI Sharing Process –


▪ AMI in Source Account is Encrypted with KMS Key from Source Account***
▪ Must Modify the Image Attribute to Add a Launch Permission which corresponds to
the specified target AWS account
▪ Must Share the KMS Keys used to Encrypted the Snapshot the AMI References with
the Target Account /IAM Role***
▪ The IAM Role/User in the Target Account Must Have the Permissions to DescribeKey,
ReEncrypted, CreateGrant, Decrypt

Figure 6 : Encrypted AMI Sharing Process

Pritam
SSM Parameter Store

4
▪ Secure Storage for Configuration and Secrets***
▪ Optional Seamless Encryption using KMS
▪ Serverless, scalable, durable, easy SDK
▪ Version tracking of configurations/secrets
▪ Security through IAM
▪ Notifications with Amazon EventBridge
▪ Integration with CloudFormation
▪ We can Assign TTL to Parameters

Figure 7 : SSM Parameters

Standard & Advanced Parameter Tiers***

Pritam
AWS Secrets Manager

5
▪ Newer Service Meant for Storing Secrets***
▪ Capability to Force Rotation of secrets Every X Days
▪ Automate generation of secrets on rotation (uses Lambda) Integration with Amazon RDS
(MySQL, PostgreSQL, Aurora)
▪ Secrets are Encrypted using KMS***
▪ Mostly meant for RDS Integration

AWS Secrets Manager - Multi Region Secrets –


▪ Replicate Secrets across Multiple AWS Regions***
▪ Secrets Manager Keeps Read Replicas in Sync with the Primary Secret ***
▪ Ability to promote a read replica Secret to a standalone Secret
▪ Use cases: multi-region apps, disaster recovery strategies, multi-region DB...

Figure 8 : Secret Managers ~ Multi Region Secrets

AWS Certificate Manager - ACM


▪ Easily Provision, Manage & deploy TLS Certificates***
▪ Provide In-Flight Encryption for Websites (HTTPS)
▪ Supports Both public and Private TLS Certificates
▪ Free of Charge for Public TLS Certificates Automatic TLS Certificate Renewal***
▪ Integrations with (load TLS certificates on)
o Elastic Load Balancers (CLB, ALB, NLB)
o CloudFront Distributions
o APIs on API Gateway
▪ Cannot Use ACM with EC2***

Pritam
ACM -Importing Public Certificates –

6
▪ Option to Generate the Certificate Outside of ACM and then Import It***
▪ No Automatic Renewal, must Import a New Certificate Before Expiry***
▪ ACM Sends Daily Expiration Events Starting 45 Days Prior to Expiration
o The # of Days can be Configured
o Events are appearing in EventBridge
▪ AWS Config Has a Managed Rule Named ACM-Certificate-Expiration-Check to
Check for Expiring Certificates (configurable number of days)***

Figure 9 : Certificates Manager

API Gateway - Endpoint Types


1. Edge-Optimized (default): For global clients
o Requests are Routed through the CloudFront Edge Locations (improves latency)
o The API Gateway still lives in only one region
2. Regional
o For Clients within the Same Region
o Could Manually Combine with CloudFront (more control over the caching
strategies and the distribution)
3. Private
o Can only be Accessed from your VPC using an Interface VPC Endpoint (ENI)
o Use a resource policy to define access

Pritam
ACM With API Gateway

7
1. Edge-Optimized (default): For global clients
o Requests are Routed through the CloudFront Edge Locations (improves latency)
o The API Gateway still lives in Only One Region
o The TLS Certificate Must be in the Same Region as CloudFront, in Us-East-1
o Then Setup CNAME or (better) A-Alias Record in Route 53
2. Regional:
o For Clients within the Same Region
o The TLS Certificate must be Imported on API Gateway, in the same region as
the API Stage
o Then setup CNAME or (better) A-Alias Record in Route 53

AWS WAF -Web Application Firewall


▪ Protects your Web Applications from Common Web Exploits (Layer 7)***
▪ Layer 7 is HTTP (vs Layer 4 is TCP/UDP)
▪ Deploy on
o Application Load Balancer***
o API Gateway***
o CloudFront
o AppSync
o GraphQL API
o Cognito User Pool
▪ Define Web ACL (Web Access Control List) Rules:
o IP Set: up to 10,000 IP addresses - use multiple Rules for more IPs
o HTTP headers, HTTP body, or URI strings Protects from common attack - SQL
injection and Cross-Site Scripting (XSS)
o Size constraints, geo-match (block countries)
o Rate-based rules (to count occurrences of events) - for DDoS protection
▪ WAF are Regional Except for CloudFront
▪ A rule group is a reusable set of rules that you can add to WAF

Pritam
WAF - Fixed IP while using WAF with a LoadBalancer –

8
▪ WAF doesn’t Support the NLB as Layer 4***
▪ We can use Global Accelerator for Fixed Ip and WAF on the ALB***

AWS Shield: Protect from DDoS attack


▪ DDOs: Distributed Denial of Service - Many Requests at The Same Time
▪ AWS Shield Standard:
o Free Service that is Activated for Every AWS Customer***
o Provides Protection from Attacks such as SYN/UDP Floods, Reflection Attacks
and other Layer 3/Layer 4 Attacks
▪ AWS Shield Advanced:
o Optional DDoS Mitigation Service ($3,000 per month Per Organization)***
o Protect Against More Sophisticated Attack on Amazon EC2, Elastic Load
Balancing (ELB), Amazon CloudFront, AWS Global Accelerator, and Route 53
o 24/7 Access to AWS DDOS Response Team (DRP)***
o Protect Against Higher Fees during usage spikes due to DDoS
o Shield Advanced Automatic Application Layer DDoS mitigation automatically
creates, evaluates and deploys AWS WAF rules to mitigate layer 7 attacks

AWS Firewall Manager


▪ Manage Rules in All Accounts of an AWS Organization***
▪ Security Policy: Common Set of Security Rules
o WAF Rules (Application Load Balancer, API Gateways, CloudFront)
o AWS Shield Advanced (ALB, CLB, NLB, Elastic IP, CloudFront)
o Security Groups for EC2, Application Load Balancer and ENI resources in VPC
o AWS Network Firewall (VPC Level)
o Amazon Route 53 Resolver DNS Firewall
o Policies are created at the region level
▪ Rules are applied to new resources as they are created (good for compliance) across all
and future accounts in your Organization

Pritam
AWS WAF vs Firewall Manager vs Shield

9
▪ WAF, Shield and Firewall Manager are Used Together for Comprehensive Protection
Define your Web ACL rules in WAF
▪ For Granular Protection of your resources, WAF alone is the Correct Choice***
▪ If you Want to Use AWS WAF Across Accounts, accelerate WAF Configuration,
automate the protection of new resources, use Firewall Manager with AWS WAF
▪ Shield Advanced adds additional features on top of AWS WAF, such as dedicated support
from the Shield Response Team (SRT) and advanced reporting.
▪ If you're Prone to Frequent DDoS Attacks, Consider Purchasing Shield Advanced***

AWS Guard Duty


▪ Intelligent Threat Discovery to Protect your AWS Account***
▪ Uses Machine Learning Algorithms for Anomaly Detection***
▪ One click to enable (30 days trial), no need to install software
▪ Input data includes:
o Cloud Trail Events Logs - Unusual API Calls, Unauthorized Deployments
▪ CloudTrail Management Events - create VPC subnet, create trail,...
▪ Cloud Trail S3 Data Events - get object, list objects, delete object, …
o VPC Flow Logs - Unusual Internal Traffic, Unusual IP Address
o DNS Logs - compromised EC2 instances sending encoded data within DNS queries
o Optional Features - EKS Audit Logs, RDS & Aurora, EBS, Lambda, S3 Data
Events...
▪ Can Setup EventBridge rules to be Notified in Case of Findings
▪ EventBridge rules can Target AWS Lambda or SNS

AWS Inspector
▪ Automated Security Assessments***
▪ For EC2 Instances
o Leveraging the AWS System Manager (SSM) agent
o Analyze against unintended network accessibility
o Analyze the Running OS Against Known Vulnerabilities***

Pritam
▪ For Container Images push to Amazon ECR

10
o Assessment of Container Images as they are pushed
▪ For Lambda Functions
o Identifies Software Vulnerabilities in Function Code and Package
Dependencies***
o Assessment of functions as they are deployed
▪ Reporting & Integration with AWS Security Hub
▪ Send Findings to Amazon Event Bridge

AWS Macie
▪ Amazon Macie is a Fully Managed Data Security & Data Privacy Service that Uses
Machine Learning & Pattern Matching to Discover & Protect your Sensitive Data in
AWS***
▪ Macie Helps Identify & Alert You to Sensitive Data such as Personally Identifiable
Information (PII)

Figure 10 : Macie for Discover Sensitive Data

Pritam

You might also like