Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

천만 사용자를 위한 AWS 아키텍처 보안 모범 사례 (윤석찬, 테크에반젤리스트)

6,580 views

Published on

클라우드에서 보안은 매우 중요한 요소로서 클라우드 내에서 실행중인 애플리케이션에 대한 보안 인증 정책과 접근 제어 및 변경 사항 추적 및 알림 등의 기능이 필수적입니다. 본 온라인 세미나에서는 AWS 클라우드의 보안에 대한 기초 지식과 아울러 서비스 규모의 확장에 따른 AWS 아키텍처 변화에 맞는 보안 서비스 활용 방법과 모범 사례 등을 소개합니다.

Published in: Technology
  • Hello! Get Your Professional Job-Winning Resume Here - Check our website! https://vk.cc/818RFv
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here

천만 사용자를 위한 AWS 아키텍처 보안 모범 사례 (윤석찬, 테크에반젤리스트)

  1. 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  2. 2. • • • • • •
  3. 3. ü ü ü ü ü ü ü ü ü ü ü
  4. 4. AWS CLOUDTRAIL AMAZON INSPECTOR AMAZON VPC AWS WAF AWS IAM AWS KEY MANAGEMENT SERVICE SERVER-SIDE ENCRYPTION ENCRYPTION SDK
  5. 5. WhatsCat™ WhatsCat™ LOL cats »
  6. 6. WhatsCat™
  7. 7. § § § § Amazon Route 53
  8. 8. Amazon Route 53 AWS Identity & Access Management MFA token Developers Network Team User
  9. 9. Amazon Virtual Private Cloud Amazon Route 53 ü ü ü ü
  10. 10. Amazon Route 53 VPC Security Groups ü ü
  11. 11. WhatsCat™
  12. 12. WhatsCat™ LOL cats »
  13. 13. Amazon Route 53 RDS DB instance § § § §
  14. 14. Amazon CloudWatch ü ü Amazon Route 53 RDS DB instance
  15. 15. AWS CloudTrail ü ü ü Amazon Route 53 RDS DB instance
  16. 16. WhatsCat™
  17. 17. Amazon Route 53 Web instance RDS DB instance active (Multi-AZ) Availability Zone RDS DB instance standby (Multi-AZ) Elastic Load Balancing Availability Zone Web instance § § § §
  18. 18. Web instance RDS DB instance active (Multi-AZ) Availability Zone RDS DB instance standby (Multi-AZ) Elastic Load Balancing Availability Zone Web instance SSL Amazon Certificate Manager Service ü ü ü ü Amazon Route 53
  19. 19. Web instance RDS DB instance active (Multi-AZ) Availability Zone RDS DB instance standby (Multi-AZ) Elastic Load Balancing Availability Zone Web instance Amazon Route 53 1. EC2 2. RDS
  20. 20. Web instance RDS DB instance active (Multi-AZ) Availability Zone RDS DB instance standby (Multi-AZ) Elastic Load Balancing Availability Zone Web instance Amazon Route 53 AWS Key Management Service (KMS) ü ü AWS KMS Customer master keys Data key 1 S3 object EBS volume Redshift cluster Data key 2 Data key 3 Data key 4 Custom application
  21. 21. WhatsCat™
  22. 22. WhatsCat™ LOL cats » Cat photos »
  23. 23. Amazon Route 53 Web instance RDS DB instance active (Multi-AZ) Availability Zone Elastic Load Balancing Amazon S3 Amazon Cloudfront § § § § DynamoDBElastiCache
  24. 24. MySQL • • • • • • •
  25. 25. Good Cats Bad Dogs AWS WAF Amazon CloudFront Elastic Load Balancing Amazon Route 53 DynamoDB Application RDS ElastiCache
  26. 26. • • • • • • • • • • •
  27. 27. Cats > 100,000 WhatsCat™
  28. 28. Availability Zone Amazon Route 53 Amazon S3 Amazon Cloudfront Availability Zone Elastic Load Balancer DynamoDB RDS DB Instance Read Replica Web Instance Web Instance Web Instance ElastiCache RDS DB Instance Read Replica Web Instance Web Instance Web Instance ElastiCacheRDS DB Instance Standby (Multi-AZ) RDS DB Instance Active (Multi-AZ)
  29. 29. Product Release App Code Infrastructure Code Security Code
  30. 30. • • • • • • • OPS SEC DEV 확장성 - 자동화 - 피드백
  31. 31. • • • AWS IAM AWS CloudTrail Amazon CloudWatch Security CI/CD PipelineAWS CodeCommit AWS CodeDeploy AWS CodePipeline AWS CodeBuild
  32. 32. • • • Amazon Inspector Security CI/CD Pipeline
  33. 33. • • • • • • • • • •
  34. 34. • ü ü
  35. 35. InstancePublic AMI Golden AMI Launch instance EC2 Configure instance Hardened instance Bake AMI Hardening and configuration User administration Operating system Running instances Launch AWS Config AWS Lambda Automate AMI baking Amazon Inspector Amazon Inspector Amazon Inspector Decommission
  36. 36. IAM stack Infrastructure stack Logging stack AWS CodeCommit
  37. 37. AWS Trusted Advisor - Security
  38. 38. AWS Trusted Advisor - Security
  39. 39. WhatsCat™ Cats > 1 million
  40. 40. • • • • •
  41. 41. Amazon CloudFront Amazon CloudFront Elastic Load Balancer DynamoDB Application Amazon RDS Elastic Load Balancer DynamoDB Application Amazon RDS Elastic Load Balancer DynamoDB Application Amazon RDS
  42. 42. • • •

×