AWS security services notification during attack

0

What AWS security services will notify me when there is an adversary in my website and its related database (RDS mySQL) hosted on AWS? It is a notification needed for when an adversary in on my environment, and not for investigation after the adversary has performed malicious actions on the environment.

I'm looking into AWS Detective and Security Hub, but I didn't find if they integrate with SNS. Pls help out.

3回答
0
承認された回答

I think you need to define and build an IDS system in this case. You can’t just rely on AWS services for this type of stuff.

You may need to implement something like VPC mirroring with a 3rd party system and have your website logs sent to a SIEM for analysis.

profile picture
エキスパート
回答済み 8ヶ月前
0

Hello.

I believe GuardDuty can be used to detect unauthorized logins to RDS.
https://docs.aws.amazon.com/guardduty/latest/ug/rds-protection.html
https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html

GuardDuty can also link events to Amazon EventBridge.
So it is possible to have linked events notified via SNS to e-mail or other means.
https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings_cloudwatch.html

profile picture
エキスパート
回答済み 8ヶ月前
profile pictureAWS
エキスパート
レビュー済み 8ヶ月前
profile picture
エキスパート
Steve_M
レビュー済み 8ヶ月前
0

AWS Config can send an alert via SNS when a change is made to the AWS configuration that breaches a compliance rule https://docs.aws.amazon.com/config/latest/developerguide/notifications-for-AWS-Config.html

profile picture
エキスパート
Steve_M
回答済み 8ヶ月前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ