SlideShare a Scribd company logo
一次搞懂雲端資安,同步傳授資安絕招
趨勢科技 Justin WU
2 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
Why Trend Micro?
3 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
也許是因為...
4 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
趨勢使用AWS作為主要開發環境
10,000
Total
- Single tenant Infra
- DSM 2 x 2 (HA)
- DS 10.0 version
- DS Agent Mode
- DB Always-On Cluster
- 7,000 On-premise DSA
- 3,000 AWS DSA
- 20 Platforms (70% Linux)
IT DC
on-premise
DCS DC
on-premise
Cloud Platforms
AWS & Others
Hybrid Cloud- 3,000 On-premise DSA
- 7,000 AWS DSA
5 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
同時趨勢也是AWS資安解決方案提供者
Anti-
malware
Integrity
Monitoring
Intrusion
Prevention
Log
Inspection
Web
Reputation
Host
Firewall
病毒防護
網頁信譽評等
日誌異常檢驗變動監控
主機防火牆
入侵防禦
6 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
Continuous Security (Container)
7 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
使用AWS並選擇趨勢科技做為資安解決方案客戶
8 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
資安防護在軟體公司的難處?
9 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
資安 = 效能干擾?
• 零干擾不可能,但是要最低限度干擾
• 資安必須要取得彼此共識
• IT&DCS、InfoSec、Server Owner
– IT&DCS 導入產品與方法協助產品開發效率
與安全
– InfoSec 評估資安程度與制定政策
– Server Owner 配合協助
10 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
我們如何保護雲端環境安全?
11 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
資安政策
• 短期內使用AWS測試環境  不予處置
• 長期運作測試與開發環境強制安裝
• 透過Script達成自動化安裝
• 視環境的資安需求搭配不同政策
• 區分不同事件類型並通報不同單位
12 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
DEUS
DEUS
US
13 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
Private Cloud
Public Cloud
us-west
us-east EMEA
DSA DSA
MS SQL Cluster
DSM Public VIP/FQDN
DSM
WAN
WAN
Centralized Security
Management
WAN
兼具公有雲的彈性, 但仍有安全策略
中央控管的部署效率
Cloud
PlatformsAWS
14 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
EC2
DSA
EC2
DSA
EC2
DSA
EC2
DSA
EC2
DSA
EC2
DSA
EC2
DSA
EC2
DSA
EC2
DSA
Linked to
IT&DCS DSM
IT Operations
DS Cloud Connection API
New
EC2
Auto Deploy
DSA
Amazon EC2
15 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
資安權責區分
DSA
DSA
DSA
IT
DSM
DCS
DSM
SOCRules -> Cases
GSOC 24x7
monitoring team
Server owners
Other sources
Other sources
IT/DCS admin
16 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
Benefit
17 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
異質平台、同等防護
Before Using Deep Security
• Linux Server need to protect
malware & threat
• Legacy system no patch, or
User server unable to deploy
patch on-time. high risk when
zero day attack.
After Using Deep Security
• 100% protection for Linux Server
• IT/DCS strengthen security knowledge and
policy.
• Virtual patch to protect system from legacy
system or server unable to patch
18 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
混合環境、中央管控
• RD teams own AWS account and
run dev-ops model themselves.
• No standard security software for
servers in cloud platforms.
• Integrates with RD dev-ops process
automatically.
• IT/DCS can easily manage hybrid cloud
security status and incidents.
• Reduce operation teams’
communication efforts.
Before Using Deep Security After Using Deep Security
19 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
節省配置、開發快速
• ACL rule is too much, switch
almost unable to handle.
• ACL rule add/update time
take too long.
• ACL rule modify take un-expected
high risk.
• High Level Firewall Rule owned by IT.
• Host/AP level rule owned by user.
• Adopt firewall self-service. release effort
from IT.
Before Using Deep Security After Using Deep Security
20 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
其他產業的應用
21 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
防竄改並能自動回復。──避免竄改與攻擊
保護知名的RoBoHoN機器人網站
採用原因
 提供了包含網路傳輸層到應用層的多層防禦
 提供雲端系統堅強的防護
導入成效
 防護架設於AWS上的網站及對外服務。避免產品與客戶資料遭受網路攻擊
 在RoBoHoN官網上實現了防竄改及自動回復功能。當有未經授權的修改發生時,系統能
自動恢復,同時快速的提供正常服務。
Trend Micro Deep Security™ 客戶案例 / SHARP
行業:電器製造
地區:日本
導入產品/解決方案:
Trend Micro Deep Security™
導入時期:2015年10月
客戶面臨的挑戰
 身為具有高知名度的企業,公司的產品網站和線上服務很容易成為網絡攻擊的目標。
另外,也需要採取措施來避免資料遭受篡改及外洩的業務風險
22 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
將內部系統轉移至AWS上能讓業務執行變得更有效率,且在數個系統上共同
建立一套通用的基礎安全系統,確切落實雲端服務的靈活安全運用。
採用原因
 具有完整的防護功能,也能與既有環境維持一致的管理政策與機制
 對AWS的可擴充性及效能等特性影響極小
 已有許多在AWS上的應用案例
導入成效
 爲公有雲上的系統提供多層式防禦
 輕鬆啟用必要的防禦功能,不影響AWS
上系統的效能
 將安全機制整合在AWS基礎架構中,制
定並落實公司自有的安全政策
Trend Micro Deep Security™ 客戶案例/ LAWSON
客戶面臨的挑戰
 現有設備採買、開發到得以運用等多項作業,已成為阻礙業務推展的因素
 決定以AWS為公司營運基礎後,需要制定一套雲安全的標準。
〈系統架構圖〉
業種:零售業
地域:日本
導入產品/解決方案:
Trend Micro Deep Security™
導入時期:2014年11月
23 Copyright © 2018 Trend Micro Incorporated. All rights reserved.
確保原有網站上的多樣化功能在網站搬移至AWS之後,
能不影響既有服務、且能安全的運作
採用原因
 單一產品即包含防毒、IDS/IPS、WAF等功能。
 已有許多在AWS上的應用案例
導入成效
 導入Deep Security後,得以確保雲端架構上可維持
與On-premises一致的安全等級
 即使在網站使用的尖峰期,也能確保伺服器的資
源及安全對策
 Virtual Patching虛擬補丁協助阻擋每天都在發生
的新威脅
〈系統架構圖〉
Trend Micro Deep Security™ 客戶案例/ H.I.S 有限公司
客戶面臨的挑戰
 需要將旅遊相關網站移至AWS,因此需要評估一套不僅安全且能保持或提高原有服
務水準的安全機制
 由於AWS已有許多運用實績,預期將來會擴大AWS平台的運用
 對於資安產品的技術支援也相當重視
業種:旅遊業
地域:日本
導入產品/ 解決方案:
Trend Micro Deep Security™
導入時期:2014年6月
Thank you

More Related Content

What's hot

低延遲多人遊戲的全球佈署
低延遲多人遊戲的全球佈署低延遲多人遊戲的全球佈署
低延遲多人遊戲的全球佈署Amazon Web Services
 
Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)
Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)
Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)
Wales Chen
 
2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管
2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管
2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管
ChiaHsien Lee
 
2021 二月 Kasten K10 介紹與概觀
2021 二月 Kasten K10 介紹與概觀2021 二月 Kasten K10 介紹與概觀
2021 二月 Kasten K10 介紹與概觀
Wales Chen
 
深入探討雲端安全
深入探討雲端安全深入探討雲端安全
深入探討雲端安全
Amazon Web Services
 
賽門鐵克 VMware 完整解決方案
賽門鐵克 VMware 完整解決方案賽門鐵克 VMware 完整解決方案
賽門鐵克 VMware 完整解決方案
Wales Chen
 
遷移數據到雲端的最佳策略
遷移數據到雲端的最佳策略遷移數據到雲端的最佳策略
遷移數據到雲端的最佳策略
Amazon Web Services
 
Keynote_Welcome_Remarks
Keynote_Welcome_RemarksKeynote_Welcome_Remarks
Keynote_Welcome_Remarks
Amazon Web Services
 
雲端上的遊戲伺服器營運秘笈
雲端上的遊戲伺服器營運秘笈雲端上的遊戲伺服器營運秘笈
雲端上的遊戲伺服器營運秘笈Amazon Web Services
 
AWS新手上路快速育成手冊
AWS新手上路快速育成手冊AWS新手上路快速育成手冊
AWS新手上路快速育成手冊
Amazon Web Services
 
Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗
Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗
Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗Amazon Web Services
 
深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具
Amazon Web Services
 
Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式
Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式
Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式
Amazon Web Services
 
AWS reInvent 2018 Recap - Solutions Updates part 1
AWS reInvent 2018 Recap - Solutions Updates part 1AWS reInvent 2018 Recap - Solutions Updates part 1
AWS reInvent 2018 Recap - Solutions Updates part 1
Amazon Web Services
 
深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具
Amazon Web Services
 
Customer Sharing: Hiiir
Customer Sharing: HiiirCustomer Sharing: Hiiir
Customer Sharing: Hiiir
Amazon Web Services
 
Building IoT Backends
Building IoT BackendsBuilding IoT Backends
Building IoT Backends
Amazon Web Services
 
如何規劃與執行大型資料中心遷移和案例分享
如何規劃與執行大型資料中心遷移和案例分享如何規劃與執行大型資料中心遷移和案例分享
如何規劃與執行大型資料中心遷移和案例分享
Amazon Web Services
 
A10 networks產品與核心價值介紹 2014-03-04
A10 networks產品與核心價值介紹 2014-03-04A10 networks產品與核心價值介紹 2014-03-04
A10 networks產品與核心價值介紹 2014-03-04
Michael Lin
 

What's hot (20)

低延遲多人遊戲的全球佈署
低延遲多人遊戲的全球佈署低延遲多人遊戲的全球佈署
低延遲多人遊戲的全球佈署
 
Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)
Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)
Veeam 整合地端與 Azure 雲端的資料保護 (2021 版本)
 
2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管
2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管
2016 AWS Summit TPE - Hiiir 如何透過 AWS IAM 做好雲端權限控管
 
2021 二月 Kasten K10 介紹與概觀
2021 二月 Kasten K10 介紹與概觀2021 二月 Kasten K10 介紹與概觀
2021 二月 Kasten K10 介紹與概觀
 
深入探討雲端安全
深入探討雲端安全深入探討雲端安全
深入探討雲端安全
 
賽門鐵克 VMware 完整解決方案
賽門鐵克 VMware 完整解決方案賽門鐵克 VMware 完整解決方案
賽門鐵克 VMware 完整解決方案
 
遷移數據到雲端的最佳策略
遷移數據到雲端的最佳策略遷移數據到雲端的最佳策略
遷移數據到雲端的最佳策略
 
Keynote_Welcome_Remarks
Keynote_Welcome_RemarksKeynote_Welcome_Remarks
Keynote_Welcome_Remarks
 
雲端上的遊戲伺服器營運秘笈
雲端上的遊戲伺服器營運秘笈雲端上的遊戲伺服器營運秘笈
雲端上的遊戲伺服器營運秘笈
 
AWS新手上路快速育成手冊
AWS新手上路快速育成手冊AWS新手上路快速育成手冊
AWS新手上路快速育成手冊
 
Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗
Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗
Track 2 Session 6_利用 Amazon Personalize 個人化推薦提升玩家體驗
 
建構雲端遊戲數據分析
建構雲端遊戲數據分析建構雲端遊戲數據分析
建構雲端遊戲數據分析
 
深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具
 
Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式
Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式
Getting Started with Serverless Architecture - 深入淺出無伺服器架構應用程式
 
AWS reInvent 2018 Recap - Solutions Updates part 1
AWS reInvent 2018 Recap - Solutions Updates part 1AWS reInvent 2018 Recap - Solutions Updates part 1
AWS reInvent 2018 Recap - Solutions Updates part 1
 
深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具深入淺出 AWS 大數據工具
深入淺出 AWS 大數據工具
 
Customer Sharing: Hiiir
Customer Sharing: HiiirCustomer Sharing: Hiiir
Customer Sharing: Hiiir
 
Building IoT Backends
Building IoT BackendsBuilding IoT Backends
Building IoT Backends
 
如何規劃與執行大型資料中心遷移和案例分享
如何規劃與執行大型資料中心遷移和案例分享如何規劃與執行大型資料中心遷移和案例分享
如何規劃與執行大型資料中心遷移和案例分享
 
A10 networks產品與核心價值介紹 2014-03-04
A10 networks產品與核心價值介紹 2014-03-04A10 networks產品與核心價值介紹 2014-03-04
A10 networks產品與核心價值介紹 2014-03-04
 

Similar to 一次搞懂雲端資安,同步傳授資安絕招

深入浅出 V cloud director
深入浅出 V cloud director深入浅出 V cloud director
深入浅出 V cloud director
ITband
 
Huawei cloud computing
Huawei cloud computingHuawei cloud computing
Huawei cloud computing
ssuser220dc6
 
开源+自主开发 - 淘宝软件基础设施构建实践
开源+自主开发  - 淘宝软件基础设施构建实践开源+自主开发  - 淘宝软件基础设施构建实践
开源+自主开发 - 淘宝软件基础设施构建实践
Wensong Zhang
 
Citrix total solution 2010 q3
Citrix total solution 2010 q3Citrix total solution 2010 q3
Citrix total solution 2010 q3Jimzhao719
 
Taobao图片存储与cdn系统到服务
Taobao图片存储与cdn系统到服务Taobao图片存储与cdn系统到服务
Taobao图片存储与cdn系统到服务
Wensong Zhang
 
淘宝对象存储与Cdn系统到服务
淘宝对象存储与Cdn系统到服务淘宝对象存储与Cdn系统到服务
淘宝对象存储与Cdn系统到服务drewz lin
 
03 李实恭-乘云之势以智致远 0611
03 李实恭-乘云之势以智致远 061103 李实恭-乘云之势以智致远 0611
03 李实恭-乘云之势以智致远 0611ikewu83
 
企業郵件系統的私有雲架構教戰守則
企業郵件系統的私有雲架構教戰守則企業郵件系統的私有雲架構教戰守則
企業郵件系統的私有雲架構教戰守則OFMKT
 
Internet System Security Overview
Internet System Security OverviewInternet System Security Overview
Internet System Security Overview
ChinaNetCloud
 
开源软件营销策略
开源软件营销策略开源软件营销策略
开源软件营销策略
linhaicaoyuan
 
Challenges and opportunities computing Kuo-Yi Chen
Challenges and opportunities computing   Kuo-Yi ChenChallenges and opportunities computing   Kuo-Yi Chen
Challenges and opportunities computing Kuo-Yi Chenkuoyichen
 
云计算时代的新安全挑战与机会
云计算时代的新安全挑战与机会云计算时代的新安全挑战与机会
云计算时代的新安全挑战与机会
ITband
 
今日如何建立一个安全的私有云
今日如何建立一个安全的私有云今日如何建立一个安全的私有云
今日如何建立一个安全的私有云
ITband
 
云网锦绣 SDN实战研讨会
云网锦绣 SDN实战研讨会云网锦绣 SDN实战研讨会
云网锦绣 SDN实战研讨会
Hardway Hou
 
Comboware ComboStack 202105
Comboware ComboStack 202105Comboware ComboStack 202105
Comboware ComboStack 202105
Elroy Peng
 
2010中国云计算调查报告
2010中国云计算调查报告2010中国云计算调查报告
2010中国云计算调查报告ITband
 
雲端分散架構的駭客事件與安全問題
雲端分散架構的駭客事件與安全問題雲端分散架構的駭客事件與安全問題
雲端分散架構的駭客事件與安全問題
Alan Lee
 
稳定、高效、低碳 -淘宝软件基础设施构建实践
稳定、高效、低碳  -淘宝软件基础设施构建实践稳定、高效、低碳  -淘宝软件基础设施构建实践
稳定、高效、低碳 -淘宝软件基础设施构建实践
Wensong Zhang
 
AWS 雲端環境的資安佈局.pdf
AWS 雲端環境的資安佈局.pdfAWS 雲端環境的資安佈局.pdf
AWS 雲端環境的資安佈局.pdf
ssuser293781
 

Similar to 一次搞懂雲端資安,同步傳授資安絕招 (20)

深入浅出 V cloud director
深入浅出 V cloud director深入浅出 V cloud director
深入浅出 V cloud director
 
Huawei cloud computing
Huawei cloud computingHuawei cloud computing
Huawei cloud computing
 
开源+自主开发 - 淘宝软件基础设施构建实践
开源+自主开发  - 淘宝软件基础设施构建实践开源+自主开发  - 淘宝软件基础设施构建实践
开源+自主开发 - 淘宝软件基础设施构建实践
 
Dell
DellDell
Dell
 
Citrix total solution 2010 q3
Citrix total solution 2010 q3Citrix total solution 2010 q3
Citrix total solution 2010 q3
 
Taobao图片存储与cdn系统到服务
Taobao图片存储与cdn系统到服务Taobao图片存储与cdn系统到服务
Taobao图片存储与cdn系统到服务
 
淘宝对象存储与Cdn系统到服务
淘宝对象存储与Cdn系统到服务淘宝对象存储与Cdn系统到服务
淘宝对象存储与Cdn系统到服务
 
03 李实恭-乘云之势以智致远 0611
03 李实恭-乘云之势以智致远 061103 李实恭-乘云之势以智致远 0611
03 李实恭-乘云之势以智致远 0611
 
企業郵件系統的私有雲架構教戰守則
企業郵件系統的私有雲架構教戰守則企業郵件系統的私有雲架構教戰守則
企業郵件系統的私有雲架構教戰守則
 
Internet System Security Overview
Internet System Security OverviewInternet System Security Overview
Internet System Security Overview
 
开源软件营销策略
开源软件营销策略开源软件营销策略
开源软件营销策略
 
Challenges and opportunities computing Kuo-Yi Chen
Challenges and opportunities computing   Kuo-Yi ChenChallenges and opportunities computing   Kuo-Yi Chen
Challenges and opportunities computing Kuo-Yi Chen
 
云计算时代的新安全挑战与机会
云计算时代的新安全挑战与机会云计算时代的新安全挑战与机会
云计算时代的新安全挑战与机会
 
今日如何建立一个安全的私有云
今日如何建立一个安全的私有云今日如何建立一个安全的私有云
今日如何建立一个安全的私有云
 
云网锦绣 SDN实战研讨会
云网锦绣 SDN实战研讨会云网锦绣 SDN实战研讨会
云网锦绣 SDN实战研讨会
 
Comboware ComboStack 202105
Comboware ComboStack 202105Comboware ComboStack 202105
Comboware ComboStack 202105
 
2010中国云计算调查报告
2010中国云计算调查报告2010中国云计算调查报告
2010中国云计算调查报告
 
雲端分散架構的駭客事件與安全問題
雲端分散架構的駭客事件與安全問題雲端分散架構的駭客事件與安全問題
雲端分散架構的駭客事件與安全問題
 
稳定、高效、低碳 -淘宝软件基础设施构建实践
稳定、高效、低碳  -淘宝软件基础设施构建实践稳定、高效、低碳  -淘宝软件基础设施构建实践
稳定、高效、低碳 -淘宝软件基础设施构建实践
 
AWS 雲端環境的資安佈局.pdf
AWS 雲端環境的資安佈局.pdfAWS 雲端環境的資安佈局.pdf
AWS 雲端環境的資安佈局.pdf
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
Amazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
Amazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
Amazon Web Services
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Amazon Web Services
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
Amazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
Amazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Amazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
Amazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Amazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

一次搞懂雲端資安,同步傳授資安絕招

  • 2. 2 Copyright © 2018 Trend Micro Incorporated. All rights reserved. Why Trend Micro?
  • 3. 3 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 也許是因為...
  • 4. 4 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 趨勢使用AWS作為主要開發環境 10,000 Total - Single tenant Infra - DSM 2 x 2 (HA) - DS 10.0 version - DS Agent Mode - DB Always-On Cluster - 7,000 On-premise DSA - 3,000 AWS DSA - 20 Platforms (70% Linux) IT DC on-premise DCS DC on-premise Cloud Platforms AWS & Others Hybrid Cloud- 3,000 On-premise DSA - 7,000 AWS DSA
  • 5. 5 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 同時趨勢也是AWS資安解決方案提供者 Anti- malware Integrity Monitoring Intrusion Prevention Log Inspection Web Reputation Host Firewall 病毒防護 網頁信譽評等 日誌異常檢驗變動監控 主機防火牆 入侵防禦
  • 6. 6 Copyright © 2018 Trend Micro Incorporated. All rights reserved. Continuous Security (Container)
  • 7. 7 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 使用AWS並選擇趨勢科技做為資安解決方案客戶
  • 8. 8 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 資安防護在軟體公司的難處?
  • 9. 9 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 資安 = 效能干擾? • 零干擾不可能,但是要最低限度干擾 • 資安必須要取得彼此共識 • IT&DCS、InfoSec、Server Owner – IT&DCS 導入產品與方法協助產品開發效率 與安全 – InfoSec 評估資安程度與制定政策 – Server Owner 配合協助
  • 10. 10 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 我們如何保護雲端環境安全?
  • 11. 11 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 資安政策 • 短期內使用AWS測試環境  不予處置 • 長期運作測試與開發環境強制安裝 • 透過Script達成自動化安裝 • 視環境的資安需求搭配不同政策 • 區分不同事件類型並通報不同單位
  • 12. 12 Copyright © 2018 Trend Micro Incorporated. All rights reserved. DEUS DEUS US
  • 13. 13 Copyright © 2018 Trend Micro Incorporated. All rights reserved. Private Cloud Public Cloud us-west us-east EMEA DSA DSA MS SQL Cluster DSM Public VIP/FQDN DSM WAN WAN Centralized Security Management WAN 兼具公有雲的彈性, 但仍有安全策略 中央控管的部署效率 Cloud PlatformsAWS
  • 14. 14 Copyright © 2018 Trend Micro Incorporated. All rights reserved. EC2 DSA EC2 DSA EC2 DSA EC2 DSA EC2 DSA EC2 DSA EC2 DSA EC2 DSA EC2 DSA Linked to IT&DCS DSM IT Operations DS Cloud Connection API New EC2 Auto Deploy DSA Amazon EC2
  • 15. 15 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 資安權責區分 DSA DSA DSA IT DSM DCS DSM SOCRules -> Cases GSOC 24x7 monitoring team Server owners Other sources Other sources IT/DCS admin
  • 16. 16 Copyright © 2018 Trend Micro Incorporated. All rights reserved. Benefit
  • 17. 17 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 異質平台、同等防護 Before Using Deep Security • Linux Server need to protect malware & threat • Legacy system no patch, or User server unable to deploy patch on-time. high risk when zero day attack. After Using Deep Security • 100% protection for Linux Server • IT/DCS strengthen security knowledge and policy. • Virtual patch to protect system from legacy system or server unable to patch
  • 18. 18 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 混合環境、中央管控 • RD teams own AWS account and run dev-ops model themselves. • No standard security software for servers in cloud platforms. • Integrates with RD dev-ops process automatically. • IT/DCS can easily manage hybrid cloud security status and incidents. • Reduce operation teams’ communication efforts. Before Using Deep Security After Using Deep Security
  • 19. 19 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 節省配置、開發快速 • ACL rule is too much, switch almost unable to handle. • ACL rule add/update time take too long. • ACL rule modify take un-expected high risk. • High Level Firewall Rule owned by IT. • Host/AP level rule owned by user. • Adopt firewall self-service. release effort from IT. Before Using Deep Security After Using Deep Security
  • 20. 20 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 其他產業的應用
  • 21. 21 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 防竄改並能自動回復。──避免竄改與攻擊 保護知名的RoBoHoN機器人網站 採用原因  提供了包含網路傳輸層到應用層的多層防禦  提供雲端系統堅強的防護 導入成效  防護架設於AWS上的網站及對外服務。避免產品與客戶資料遭受網路攻擊  在RoBoHoN官網上實現了防竄改及自動回復功能。當有未經授權的修改發生時,系統能 自動恢復,同時快速的提供正常服務。 Trend Micro Deep Security™ 客戶案例 / SHARP 行業:電器製造 地區:日本 導入產品/解決方案: Trend Micro Deep Security™ 導入時期:2015年10月 客戶面臨的挑戰  身為具有高知名度的企業,公司的產品網站和線上服務很容易成為網絡攻擊的目標。 另外,也需要採取措施來避免資料遭受篡改及外洩的業務風險
  • 22. 22 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 將內部系統轉移至AWS上能讓業務執行變得更有效率,且在數個系統上共同 建立一套通用的基礎安全系統,確切落實雲端服務的靈活安全運用。 採用原因  具有完整的防護功能,也能與既有環境維持一致的管理政策與機制  對AWS的可擴充性及效能等特性影響極小  已有許多在AWS上的應用案例 導入成效  爲公有雲上的系統提供多層式防禦  輕鬆啟用必要的防禦功能,不影響AWS 上系統的效能  將安全機制整合在AWS基礎架構中,制 定並落實公司自有的安全政策 Trend Micro Deep Security™ 客戶案例/ LAWSON 客戶面臨的挑戰  現有設備採買、開發到得以運用等多項作業,已成為阻礙業務推展的因素  決定以AWS為公司營運基礎後,需要制定一套雲安全的標準。 〈系統架構圖〉 業種:零售業 地域:日本 導入產品/解決方案: Trend Micro Deep Security™ 導入時期:2014年11月
  • 23. 23 Copyright © 2018 Trend Micro Incorporated. All rights reserved. 確保原有網站上的多樣化功能在網站搬移至AWS之後, 能不影響既有服務、且能安全的運作 採用原因  單一產品即包含防毒、IDS/IPS、WAF等功能。  已有許多在AWS上的應用案例 導入成效  導入Deep Security後,得以確保雲端架構上可維持 與On-premises一致的安全等級  即使在網站使用的尖峰期,也能確保伺服器的資 源及安全對策  Virtual Patching虛擬補丁協助阻擋每天都在發生 的新威脅 〈系統架構圖〉 Trend Micro Deep Security™ 客戶案例/ H.I.S 有限公司 客戶面臨的挑戰  需要將旅遊相關網站移至AWS,因此需要評估一套不僅安全且能保持或提高原有服 務水準的安全機制  由於AWS已有許多運用實績,預期將來會擴大AWS平台的運用  對於資安產品的技術支援也相當重視 業種:旅遊業 地域:日本 導入產品/ 解決方案: Trend Micro Deep Security™ 導入時期:2014年6月