365x Filetype PPTX File size 0.77 MB Source: itcommunity.stanford.edu
Discussion Outline
• AWS
• Security Basics – How to secure a basic web application
• AWS Cloud Security at Stanford
• Open Q&A
AWS Security Basics
• Patch management
- use sudo yum update
• Identity and Access Management (IAM)
- don’t use superuser to login, create users and roles
• Security Groups and VPC Access Control List
- only allow traffic from protocols and ip addresses that
you
expect
Example of Security Group settings
AWS Security Basics
• Enable Multi Factor Authentication
-example using Google Authenticator
• Monitor application logs and system logs
- example is catalina.out and syslog
• Use host based Firewall
- example is iptables
sudo iptables -S
sudo iptables -A INPUT -s 191.86.249.0/24 -j DROP
AWS Security at Stanford
• All of previous mentioned plus:
minsec – http://uit.Stanford.edu/guide/securitystandards
https://uit.stanford.edu/guide/securitystandards#security-standards-servers
Vulnerability Management – use Qualys scan, a commercial vulnerability and web application
scanner
https://uit.stanford.edu/service/qualys
no reviews yet
Please Login to review.