AWS GuardDuty a SIEM?
AWS GuardDuty a SIEM?

Video: AWS GuardDuty a SIEM?

Video: AWS GuardDuty a SIEM?
Video: AWS CloudWatch vs CloudTrail | working with GuardDuty, SIEM, SOC, SOAR 2024, Tej zaum
Anonim

Amazon GuardDuty yog ib qho kev tswj xyuas kev hem thawj uas tau soj ntsuam tas li rau tus cwj pwm phem lossis tsis tau tso cai los pab tiv thaiv koj AWS account thiab workloads.

Ntawm no, AWS puas muaj SIEM?

A SIEM kev daws teeb meem tsim los natively saib xyuas AWS ib puag ncig muab kev pom rau koj rau qhov tshwm sim thiab ua kom muaj kev ruaj ntseg ntawm cov tshuab thiab cov ntaub ntawv. AlienVault USM Txhua qhov chaw nrog nws AWS -native sensor yog huab saib xyuas platform nrog tag nrho AWS SEM muaj peev xwm, suav nrog: CloudTrail Saib Xyuas thiab Ceeb Toom.

Ib yam li ntawd, kuv yuav siv AWS GuardDuty li cas? Kev daws teeb meem

  1. Deploy the CloudFormation template.
  2. Tsim thiab khiav Lambda GuardDuty nrhiav qhov kev tshwm sim.
  3. Txheeb xyuas qhov nkag hauv VPC Network ACL.
  4. Paub meej tias qhov nkag hauv AWS WAF IPSets.
  5. Paub meej tias SNS ceeb toom subscription.
  6. Siv WAF Web ACLs rau cov peev txheej.

Ib yam li ntawd, AWS GuardDuty yog dab tsi?

Amazon GuardDuty yog qhov kev pab cuam tshawb nrhiav kev hem thawj uas tsis tu ncua saib xyuas kev ua phem thiab tus cwj pwm tsis raug tso cai los tiv thaiv koj AWS account thiab workloads. GuardDuty txheeb xyuas kaum tawm txhiab tus txheej xwm thoob plaws ntau yam AWS cov ntaub ntawv, xws li AWS CloudTrail, Amazon VPC Flow Logs, thiab DNS cav.

Puas yog CloudWatch yog SIEM?

CloudTrail tuaj yeem sau tag nrho cov xwm txheej los ntawm IAM thiab yog ib qho ntawm cov kev pabcuam tseem ceeb tshaj plaws los ntawm a SIEM kev xav. CloudWatch Cov log yog qhov txuas ntxiv ntawm cov CloudWatch saib xyuas qhov chaw thiab muab lub peev xwm los txheeb xyuas qhov system, kev pabcuam thiab daim ntawv thov nkag nyob ze lub sijhawm.

Pom zoo: