© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
S E O U L | M A Y 3 , 2 0 2 3
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Native Security 서비스를 활용한
Perimeter Security
김형주
팀장
SK쉴더스
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Zero Trust Architecture, 네트워크 보안의 패러다임
Perimeter Security Materialization
Native Security Materialization CASE
Remember
Agenda
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Zero Trust Architecture,
네트워크 보안의 패러다임
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
ZTA, 네트워크 보안 패러다임
ZTA, “네크워크 상 일부 행위자는 적대적이며, 이를 완전히
보호하기 위해서는 진입점이 너무 많다는 가정하에
운영될 수 있는 네트워크 보안 패러다임” by Gartner
Thomas Lintemuth,
"네트워크 보안은 복잡할 수 있지만 다른 모든 정보 보안
시스템의 기본입니다." By Gartner
[ 주제 ]
- On-Prem. Perimeter와
동일 수준의 Cloud Perimeter
: ZTA 활용,
가장 기본적인 Perimeter Security 구현
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
별첨#1. Cloud Workload 보호 모델
인증
접근제어
암호화
Perimeter
Security Visibility
DLP & Audit
And so on.
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Perimeter Security Materialization
: In-Built(Native) or Third-Party Tools
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
3rd Party
- Compliance 대응
- 정책의 일관성
- 편리한 사용성
WAF
Web
Server
Internet
Workstation
DDoS
FW
IPS
On-Premise
SIEM
DDoS
Logging
ALB
VPC
Auto Scaling Group
FW
WAF
UTM
Amazon Route53
IPS
Amazon S3
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Logging
Amazon CloudFront
AWS Network Firewall
5-Tuple
Domain
IPS
(Suricata)
ALB
Auto Scaling Group
VPC
AWS WAF
AWS Shield
Advanced
Amazon
Route53
Amazon CloudWatch
Amazon Kinesis
Amazon S3
3rd Party SIEM
- 고가용성
- IT 부서 협업 용이
- 도입/구축 신속성 등
In-Built(Native)
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
3rd-Party 및 Native 특징 비교
Cloud 3rd Party AWS Native
Compliance 대응
제조사의 기술지원
사용성(편의성)
하이브리드 클라우드
가용성
신속성(도입/구축)
탄력성
자동화
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Native Materialization CASE
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Native Perimeter Security Materialization Model
Amazon
CloudWatch
Amazon Kinesis
Amazon S3 3rd Party SIEM
Amazon CloudWatch Metrics
Metrics
Logging
보안 관제/운영 센터
관제/운영
Amazon CloudFront
AWS Network Firewall
5-Tuple
Domain
IPS
(Suricata)
Application
Load Balancer
Auto Scaling Group
VPC
AWS WAF
AWS Shield
Advanced
Amazon
Route53
①
② ③
④
VPC
Amazon EC2
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
#1. AWS Shield Advanced(L7. DDoS)
⊙ A기업, 신규 웹서비스 운영
⊙ DDoS 공격으로 서비스 중단
⊙ 3rd-Party / SaaS ?
⊙ AWS Shield Advanced ?
☞ 내부 보안 정책
☞ 한정된 예산
☞ 대응 시간
☞ 관제∙운영 Knowledge
⊙ AWS Shield Advanced 적용
: 보안 정책, 예산, 대응시간 극복
⊙ 24 X 365 관제∙운영 서비스
: Knowledge 이슈 해소
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
#2. AWS Network Firewall(FW)
⊙ B기업, StartUp 핀테크 기업
⊙ All Cloud 환경
⊙ 보안 부재(Self Innovation)
⊙ 가장 기본적이며 효율적인
보안대책?
☞ 트래픽 추정 곤란
(신규/폐기/확장 빈발)
☞ 담당 인력채용 이슈
⊙ AWS Network Firewall(F/W) 적용
: Traffic 변동성 해소
⊙ 잦은 정책 변동, Expert(보안) 부재
: NP for AWS, 방화벽 운영서비스
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
#3. AWS Network Firewall(IPS)
⊙ C기업, 제조업, Top-Down
⊙ 일부 서비스 All Migration(AWS)
⊙ 내부 보안조직 활용
: Perimeter Security 구현
⊙ IPS Rule : Managed Service
☞ Customizing !
☞ Professional
Knowledge & Mgmt.
⊙ SK쉴더스 "NP for AWS“ 서비스 中
AWS IPS 관제 운영 서비스 도입
⊙ 원격관제 & Rule Mgmt.
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
#4. AWS WAF
⊙ D기업, E-커머스
⊙ 초기 Needs : AWS WAF
: 최우선 - Availability
⊙ 보안관제 서비스 선택
☞ Rule Customizing !
☞ 24 x 365
☞ 대용량 로그 처리
(월 10 Tb +)
⊙ log 유효성 분석, 저장방식 효율화
등 최적화 서비스 적용
: 월 3Gb + → 분석 & Cost
⊙ 원격관제 & Rule Mgmt.
AWS WAF
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Remember
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
First, ZTA faithful to the Basic
Second, ZTA considering business
strategy
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
별첨#2. Cloud 보안 프레임워크 by SK쉴더스
Cloud 보안 프레임워크 by SK쉴더스
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank you!
© 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved.
김형주
(hyung0925@sk.com)

AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안

  • 1.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. S E O U L | M A Y 3 , 2 0 2 3
  • 2.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Native Security 서비스를 활용한 Perimeter Security 김형주 팀장 SK쉴더스
  • 3.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. Zero Trust Architecture, 네트워크 보안의 패러다임 Perimeter Security Materialization Native Security Materialization CASE Remember Agenda
  • 4.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Zero Trust Architecture, 네트워크 보안의 패러다임
  • 5.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. ZTA, 네트워크 보안 패러다임 ZTA, “네크워크 상 일부 행위자는 적대적이며, 이를 완전히 보호하기 위해서는 진입점이 너무 많다는 가정하에 운영될 수 있는 네트워크 보안 패러다임” by Gartner Thomas Lintemuth, "네트워크 보안은 복잡할 수 있지만 다른 모든 정보 보안 시스템의 기본입니다." By Gartner [ 주제 ] - On-Prem. Perimeter와 동일 수준의 Cloud Perimeter : ZTA 활용, 가장 기본적인 Perimeter Security 구현
  • 6.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. 별첨#1. Cloud Workload 보호 모델 인증 접근제어 암호화 Perimeter Security Visibility DLP & Audit And so on.
  • 7.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Perimeter Security Materialization : In-Built(Native) or Third-Party Tools
  • 8.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. 3rd Party - Compliance 대응 - 정책의 일관성 - 편리한 사용성 WAF Web Server Internet Workstation DDoS FW IPS On-Premise SIEM DDoS Logging ALB VPC Auto Scaling Group FW WAF UTM Amazon Route53 IPS Amazon S3
  • 9.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. Logging Amazon CloudFront AWS Network Firewall 5-Tuple Domain IPS (Suricata) ALB Auto Scaling Group VPC AWS WAF AWS Shield Advanced Amazon Route53 Amazon CloudWatch Amazon Kinesis Amazon S3 3rd Party SIEM - 고가용성 - IT 부서 협업 용이 - 도입/구축 신속성 등 In-Built(Native)
  • 10.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. 3rd-Party 및 Native 특징 비교 Cloud 3rd Party AWS Native Compliance 대응 제조사의 기술지원 사용성(편의성) 하이브리드 클라우드 가용성 신속성(도입/구축) 탄력성 자동화
  • 11.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Native Materialization CASE
  • 12.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. Native Perimeter Security Materialization Model Amazon CloudWatch Amazon Kinesis Amazon S3 3rd Party SIEM Amazon CloudWatch Metrics Metrics Logging 보안 관제/운영 센터 관제/운영 Amazon CloudFront AWS Network Firewall 5-Tuple Domain IPS (Suricata) Application Load Balancer Auto Scaling Group VPC AWS WAF AWS Shield Advanced Amazon Route53 ① ② ③ ④ VPC Amazon EC2
  • 13.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. #1. AWS Shield Advanced(L7. DDoS) ⊙ A기업, 신규 웹서비스 운영 ⊙ DDoS 공격으로 서비스 중단 ⊙ 3rd-Party / SaaS ? ⊙ AWS Shield Advanced ? ☞ 내부 보안 정책 ☞ 한정된 예산 ☞ 대응 시간 ☞ 관제∙운영 Knowledge ⊙ AWS Shield Advanced 적용 : 보안 정책, 예산, 대응시간 극복 ⊙ 24 X 365 관제∙운영 서비스 : Knowledge 이슈 해소
  • 14.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. #2. AWS Network Firewall(FW) ⊙ B기업, StartUp 핀테크 기업 ⊙ All Cloud 환경 ⊙ 보안 부재(Self Innovation) ⊙ 가장 기본적이며 효율적인 보안대책? ☞ 트래픽 추정 곤란 (신규/폐기/확장 빈발) ☞ 담당 인력채용 이슈 ⊙ AWS Network Firewall(F/W) 적용 : Traffic 변동성 해소 ⊙ 잦은 정책 변동, Expert(보안) 부재 : NP for AWS, 방화벽 운영서비스
  • 15.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. #3. AWS Network Firewall(IPS) ⊙ C기업, 제조업, Top-Down ⊙ 일부 서비스 All Migration(AWS) ⊙ 내부 보안조직 활용 : Perimeter Security 구현 ⊙ IPS Rule : Managed Service ☞ Customizing ! ☞ Professional Knowledge & Mgmt. ⊙ SK쉴더스 "NP for AWS“ 서비스 中 AWS IPS 관제 운영 서비스 도입 ⊙ 원격관제 & Rule Mgmt.
  • 16.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. #4. AWS WAF ⊙ D기업, E-커머스 ⊙ 초기 Needs : AWS WAF : 최우선 - Availability ⊙ 보안관제 서비스 선택 ☞ Rule Customizing ! ☞ 24 x 365 ☞ 대용량 로그 처리 (월 10 Tb +) ⊙ log 유효성 분석, 저장방식 효율화 등 최적화 서비스 적용 : 월 3Gb + → 분석 & Cost ⊙ 원격관제 & Rule Mgmt. AWS WAF
  • 17.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Remember
  • 18.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. First, ZTA faithful to the Basic Second, ZTA considering business strategy
  • 19.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. 별첨#2. Cloud 보안 프레임워크 by SK쉴더스 Cloud 보안 프레임워크 by SK쉴더스
  • 20.
    © 2023, AmazonWeb Services, Inc. or its affiliates. All rights reserved. Thank you! © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. 김형주 ([email protected])