amazon web services: security overview€¦ · amazon web services cloud secure vpn connection over...

24
Amazon Web Services: Security Overview

Upload: others

Post on 13-Jun-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

Amazon Web Services:Security Overview

Page 2: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet
Page 3: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

Security White Paper

RESOURCES

aws.amazon.com/security

Updated twice a year - Feedback welcome

Page 4: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

CERTIFICATION

Shared responsibility model

PHYSICAL INFRASTRUCTURE

FIREWALL AND SECURITY GROUPS

HOST OS and VIRTUAL INTERFACES

HYPERVISOR

GUEST OS

APPLICATION and DATA

Page 5: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

CERTIFICATION

Sarbanes-Oxley (SOX)

SAS70 Type II Audit

Pursuing:

FISMA (NIST) C&A

Certified:

ISO 27001

Page 6: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

CERTIFICATION

HIPAA (health care)

DSS (credit card)

Deployed:

Page 7: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

PHYSICAL SECURITY

Many years of experience in building large-scale, secure facilities.

Non-descript buildings

Robust perimeter controls

Strictly controlled physical access

2 or more levels of two-factor authentication

Page 8: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

PHYSICAL SECURITY

Controlled, need-based access

All access is logged and reviewed

Page 9: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

FAULT SEPARATION

A

B

C

D

US East

BA

US West

BA

EU West

BA

APACAutoscalingMonitoring

Load balancing

CloudWatch

Page 10: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

BACKUP

Redundant storage

Multiple physical locations

EBS redundancy remains in single Availability Zone

S3 and SimpleDB objects replicated across multiple Availability Zones

EC2 local data must be copied to EBS or S3 for redundancy

Page 11: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

MULTI FACTOR

Multifactor authenticationto protect credentials

Recommended. Opt in.

Page 12: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

S3 SECURITY

Access controls for buckets and objects

Read, write, full

Owner has full control

Owner should encrypt when stored

Time limited URLs

Versioning (with MFA delete)

Detailed access logging

Page 13: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

S3 SECURITY

Storage Drive Decommissioning

Military grade data destructionDoD 5220.22-M/NIST 800-88

Page 14: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

EC2 SECURITY

PHYSICAL INFRASTRUCTURE

FIREWALL AND SECURITY GROUPS

HOST OS and VIRTUAL INTERFACES

HYPERVISOR

GUEST OS

APPLICATION and DATA

Security at every level

Page 15: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

EC2 SECURITY

Guest OS - Customer controlledCertificate based root login

Customer generated keypairsNo access for AWS admins

Host OS - AWS controlledSSH keyed logins via Bastion hostAll access logged and reviewed

Page 16: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

EC2 SECURITY

Security groupsCustomer controlled

Fine grained access control

Stateful firewallMandatory inbound firewall

Default deny

Signed API callsRequires X.509 certificate or secret key

Page 17: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

NETWORK SECURITY

Distributed Denial of ServiceStandard mitigation techniques in effect

Man in the MiddleAll endpoints protected by SSL

Fresh EC2 host keys generated at boot

IP spoofingProhibited at Host OS level

Page 18: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

NETWORK SECURITY

Unauthorised port scanningTerms of Service violation

Actively monitoredDetected, stopped and blocked

Ineffective since inbound ports blocked by default

Packet sniffingPromiscuous mode is ineffectiveProtection at hypervisor level

Page 19: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

NETWORK SECURITY

Configuration management

Configuration changes are:authorised, logged, tested approved and

documented

Most updates are done without affectingcustomers

Communication via email and Service Health Dashboard

Page 20: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

VIRTUAL PRIVATE CLOUD

Amazon Web Services Cloud

Secure VPN connection over the internet

VPN Gateway Router

Customer’s isolated AWS resources

Subnet 1 Subnet 2

Subnet 4Subnet 3

Customer’s network

Page 21: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

Create isolate environment within AWS

Establish subnets for access control

Connect your isolated AWS resources andIT infrastructure via a VPN

Launch AWS resources within the isolated network

VIRTUAL PRIVATE CLOUD

Page 22: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

Extend existing security and networkingtechnologies to examine traffic toand from your isolated resources

VIRTUAL PRIVATE CLOUD

Extend existing security and managementpolicies within you IT infrastructure to your

isolated AWS resources as if they were running within your own infrastructure

Page 23: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

Thank you

Page 24: Amazon Web Services: Security Overview€¦ · Amazon Web Services Cloud Secure VPN connection over the internet VPN Gateway Router Customer’s isolated AWS resources Subnet 1 Subnet

[email protected]

aws.amazon.com