{"id":2064,"date":"2022-11-30T09:10:48","date_gmt":"2022-11-30T08:10:48","guid":{"rendered":"https:\/\/keepler.io\/2022\/11\/30\/alertado-de-findings-en-aws-security-hub\/"},"modified":"2023-09-12T10:46:42","modified_gmt":"2023-09-12T10:46:42","slug":"alertado-de-findings-en-aws-security-hub","status":"publish","type":"post","link":"https:\/\/keepler.io\/es\/2022\/11\/30\/alertado-de-findings-en-aws-security-hub\/","title":{"rendered":"Alertado de findings en AWS Security Hub"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Cada vez m\u00e1s empresas alojan sus servicios de IT en la nube. Una de las principales preocupaciones, cuando se est\u00e1 valorando la posibilidad de migrar las cargas de trabajo al cloud, es la seguridad.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Si bien es cierto que AWS es responsable de proteger la infraestructura que ejecuta los servicios provistos por la nube, las redes y las instalaciones, el usuario es el encargado de proteger los datos, redes, sistemas operativos, aplicaciones, identidades, etc.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">En la actualidad, AWS dispone de varios servicios encargados de gestionar la seguridad de las cargas de trabajo, entre los cuales se encuentran:<\/span><\/p>\n<ul>\n<li aria-level=\"1\"><b>AWS Identity and access Management (IAM)<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>Amazon GuardDuty<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>Amazon inspector<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>AWS Config<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>Amazon CloudWatch<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>AWS CloudTrail<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>AWS Shield<\/b><\/li>\n<\/ul>\n<ul>\n<li aria-level=\"1\"><b>AWS Macie<\/b><\/li>\n<\/ul>\n<p><b>Pero, \u00bfc\u00f3mo gestionar los hallazgos que producen todos estos servicios?<\/b><\/p>\n<p><b>AWS Security Hub<\/b><span style=\"font-weight: 400;\"> es el servicio encargado de administrar la posici\u00f3n de seguridad en la nube, realizando comprobaciones de las pr\u00e1cticas recomendadas de seguridad, <\/span><b>agregando alertas y permitiendo la correcci\u00f3n autom\u00e1tica de los <\/b><b><i>findings<\/i><\/b><b> producidos por estos servicios<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cuando se accede a la consola de Security Hub, de inmediato se observa que el n\u00famero de hallazgos es muy grande, pudiendo llegarse a producir miles a lo largo de un mismo d\u00eda.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Es en este punto donde identificamos la necesidad de filtrar estos hallazgos, priorizarlos y notificar a los equipos encargados de resolver las vulnerabilidades.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">\u00bfPor qu\u00e9 es necesaria esta soluci\u00f3n?<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Observamos que estos <\/span><i><span style=\"font-weight: 400;\">findings<\/span><\/i><span style=\"font-weight: 400;\">, hasta que se resuelven, son notificados de forma duplicada por Security Hub, llegando a registrarse incluso varias veces en el mismo d\u00eda, generando un problema en la identificaci\u00f3n, categorizaci\u00f3n y alertado de los incidentes, pudiendo saturar al equipo encargado de la resoluci\u00f3n y provocando as\u00ed una gesti\u00f3n poco eficiente de los riesgos de seguridad.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Es por esto que se ha dise\u00f1ado una soluci\u00f3n capaz de alertar de los <\/span><i><span style=\"font-weight: 400;\">findings<\/span><\/i><span style=\"font-weight: 400;\"> que nos interesen, esto es, filtrando por la criticidad y tipo de servicio de origen (GuardDuty, Inspector y los Benchmarks de CIS y AWS), evitando tambi\u00e9n que los eventos generados se dupliquen, durante un periodo de tiempo personalizable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Por ejemplo puedo elegir que s\u00f3lo se notifiquen los eventos <\/span><i><span style=\"font-weight: 400;\">critical<\/span><\/i><span style=\"font-weight: 400;\"> que lleven m\u00e1s de 5 d\u00edas sin ser resueltos, o los eventos <\/span><i><span style=\"font-weight: 400;\">critical<\/span><\/i><span style=\"font-weight: 400;\"> y <\/span><i><span style=\"font-weight: 400;\">high<\/span><\/i><span style=\"font-weight: 400;\">, que no se resuelvan en 15 d\u00edas.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">\u00bfC\u00f3mo funciona?<\/span><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Una <\/span><i><span style=\"font-weight: 400;\">Event Rule<\/span><\/i><span style=\"font-weight: 400;\"> monitoriza los hallazgos de Security Hub. Los <\/span><i><span style=\"font-weight: 400;\">Findings<\/span><\/i><span style=\"font-weight: 400;\"> son filtrados por el servicio de origen. Actualmente esta soluci\u00f3n soporta <\/span><i><span style=\"font-weight: 400;\">findings<\/span><\/i><span style=\"font-weight: 400;\"> originados en Security Hub (CIS and Foundational benchmarks), GuardDuty e Inspector.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cuando la <\/span><i><span style=\"font-weight: 400;\">Event Rule<\/span><\/i><span style=\"font-weight: 400;\"> detecta un evento, lanza una ejecuci\u00f3n del flujo de trabajo de la State Machine de Step Function.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Si el <\/span><i><span style=\"font-weight: 400;\">finding<\/span><\/i><span style=\"font-weight: 400;\"> es nuevo o ha estado activo por m\u00e1s de 15 d\u00edas, env\u00eda un correo al equipo encargado de revisar las incidencias de seguridad, informando de los detalles del hallazgo. El evento original est\u00e1 en formato JSON por lo que previamente se formatea en HTML, para que sea m\u00e1s sencillo identificar las partes importantes del finding a simple vista, cuando se recibe el correo.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adicionalmente, una lambda se ejecuta diariamente, comprobando si cada registro de la base de datos est\u00e1 activo o no en Security Hub. En caso de no estar activo, se elimina el registro para que, en caso de que vuelva a ocurrir m\u00e1s adelante, se vuelva a procesar correctamente.<\/span><\/li>\n<\/ol>\n<h3><span style=\"font-weight: 400;\">\u00bfQu\u00e9 elementos componen esta soluci\u00f3n?<\/span><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/logs\/MonitoringPolicyExamples.html\" target=\"_blank\" rel=\"noopener\"><b>EventBridge Event Rule<\/b><\/a> <span style=\"font-weight: 400;\">&#8211;&gt; Dos Events Rules. Una para monitorizar los findings producidos en Security Hub y la otra para que diariamente se comnpruebe qu\u00e9 findings est\u00e1n resueltos y eliminar la alerta.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.aws.amazon.com\/step-functions\/latest\/dg\/welcome.html\" target=\"_blank\" rel=\"noopener\"><b>Step Function<\/b><\/a> <span style=\"font-weight: 400;\">&#8211;&gt; Flujo de trabajo Serverless para procesar los findings registrados en Security Hub.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.aws.amazon.com\/lambda\/latest\/dg\/welcome.html\" target=\"_blank\" rel=\"noopener\"><b>Lambda Function<\/b><\/a> <span style=\"font-weight: 400;\">&#8211;&gt; Cuatro funciones Lambda encargadas de gestionar las acciones necesarias durante el flujo de trabajo alojado en Step Functions.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.aws.amazon.com\/amazondynamodb\/latest\/developerguide\/Introduction.html\" target=\"_blank\" rel=\"noopener\"><b>DynamoDB Table<\/b><\/a> <span style=\"font-weight: 400;\">&#8211;&gt; Tabla que guarda los registros con la informaci\u00f3n de todos los findings activos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudWatch\/latest\/logs\/Working-with-log-groups-and-streams.html\" target=\"_blank\" rel=\"noopener\"><b>Cloudwatch Log Group<\/b><\/a> <span style=\"font-weight: 400;\">&#8211;&gt; Log Groups que contienen los logs de las ejecuciones de Lambda.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/id_roles.html\" target=\"_blank\" rel=\"noopener\"><b>IAM Role<\/b><\/a> <span style=\"font-weight: 400;\">&#8211;&gt; Seis IAM Roles encargados de aprovisionar a Lambda, DynamoDB y Step Functions de los permisos necesarios para el procesado, an\u00e1lisis y notificaci\u00f3n de los hallazgos.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/docs.aws.amazon.com\/ses\/latest\/dg\/creating-identities.html\" target=\"_blank\" rel=\"noopener\"><b>SES Identity<\/b><\/a> &#8211;&gt; Servicio encargado del env\u00edo de los correos con los findings.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Arquitectura de alto nivel<\/span><\/h3>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i0.wp.com\/keepler.io\/wp-content\/uploads\/2022\/11\/high-level-architecture-aws-security-hub.png?resize=242%2C579&#038;ssl=1\" width=\"242\" height=\"579\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Flujo de trabajo en Step Function<\/span><\/h3>\n<p><b>Descripci\u00f3n del flujo de trabajo:<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">La primera funci\u00f3n Lambda comprueba si el registro se encuentra en la base de datos de Dynamo. Si no est\u00e1 all\u00ed, significa que es un finding nuevo as\u00ed que lo a\u00f1ade a la tabla, env\u00eda el evento a la siguiente Lambda que formatear\u00e1 el evento en HTML y lo env\u00eda por correo al equipo de soporte, v\u00eda SES.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Si el item existe en la base de datos, significa que el finding se ha duplicado y est\u00e1 activo todav\u00eda as\u00ed que otra funci\u00f3n Lambda se ejecuta para comprobar si el finding ha estado activo por m\u00e1s de 15 d\u00edas. Si es as\u00ed, ejecuta la Lambda que parsea el evento en HTML para notificar al equipo de soporte. Si el finding lleva menos de 15 d\u00edas activo, no se realiza ninguna acci\u00f3n.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">A continuaci\u00f3n se observa un gr\u00e1fico con el flujo de trabajo utilizado para analizar los eventos de seguridad:<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i0.wp.com\/keepler.io\/wp-content\/uploads\/2022\/11\/security-events-workflow-aws-security-hub.png?resize=408%2C482&#038;ssl=1\" width=\"408\" height=\"482\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2><span style=\"font-weight: 400;\">Uso<\/span><\/h2>\n<p><b>1. Clonar<\/b><span style=\"font-weight: 400;\"> el <\/span><b>repositorio<\/b><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">$ git clone <a href=\"https:\/\/github.com\/lorenzocampo\/alerting-securityhub-findings.git\" rel=\"nofollow\">https:\/\/github.com\/lorenzocampo\/alerting-securityhub-findings.git<\/a><\/span><\/p>\n<p><b>2. Inicializar<\/b><span style=\"font-weight: 400;\"> el <\/span><b>directorio de trabajo<\/b><span style=\"font-weight: 400;\"> que contienen los ficheros de terraform:<\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">$ terraform init<\/span><\/p>\n<p><b>3. Crear<\/b><span style=\"font-weight: 400;\"> un <\/span><b>plan de ejecuci\u00f3n<\/b><span style=\"font-weight: 400;\">, que permite previsualizar los recursos que se van a desplegar:<\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">$ terraform plan<\/span><\/p>\n<p><b>4. Ejecutar<\/b><span style=\"font-weight: 400;\"> las <\/span><b>acciones propuestas <\/b><span style=\"font-weight: 400;\">en el plan de Terraform:<\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"font-weight: 400;\">$ terraform apply<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"font-weight: 400;\">Conclusi\u00f3n<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">La seguridad es uno de los principales pilares sobre los que sustenta cualquier servicio de TI. Con la ayuda de esta soluci\u00f3n, facilitamos la <\/span><b>detecci\u00f3n y resoluci\u00f3n temprana de los incidentes<\/b><span style=\"font-weight: 400;\"> que se registren, agilizando y optimizando el proceso de notificaci\u00f3n al equipo de soporte, consiguiendo as\u00ed que los equipos que gestionan estos incidentes se centren en lo m\u00e1s importante, resolver los problemas.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>Imagen: Unsplash | @fakurian<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cada vez m\u00e1s empresas alojan sus servicios de IT en la nube. Una de las principales preocupaciones, cuando se est\u00e1 valorando la posibilidad de migrar las cargas de trabajo al cloud, es la seguridad. Si bien es cierto que AWS es responsable de proteger la infraestructura que ejecuta los servicios provistos por la nube, las [&hellip;]<\/p>\n","protected":false},"author":134360170,"featured_media":34823,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false},"categories":[224],"tags":[236,277,283],"class_list":["post-2064","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","tag-aws","tag-seguridad","tag-tecnologia"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/p9CeZw-xi","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/keepler.io\/wp-content\/uploads\/2022\/11\/keepler-aws-security-hub-finding-alerts-2.jpg?fit=1280%2C452&ssl=1","_links":{"self":[{"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/posts\/2064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/users\/134360170"}],"replies":[{"embeddable":true,"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/comments?post=2064"}],"version-history":[{"count":1,"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/posts\/2064\/revisions"}],"predecessor-version":[{"id":2300,"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/posts\/2064\/revisions\/2300"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/media\/34823"}],"wp:attachment":[{"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/media?parent=2064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/categories?post=2064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/keepler.io\/es\/wp-json\/wp\/v2\/tags?post=2064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}