AWS Management Console 인증 실패 감지 알람이 없는 CloudWatch

AWS 콘솔 로그인 실패에 대한 알림을 설정하세요.

설명

콘솔 로그인 실패는 비밀번호 입력 실수나 계정 공격 시도로 발생할 수 있습니다. 실패 이벤트를 모니터링해 반복되거나 의심스러운 시도를 조사하세요.

잠재적 영향

알림이 없으면 반복되는 로그인 실패를 늦게 발견하고 조사 시작이 지연될 수 있습니다.

해결 방법

ConsoleLogin과 Failed authentication을 함께 확인하는 로그 메트릭 필터를 구성하세요. 필터 지표에 알람을 연결하고 운영 환경에 맞는 임계값과 알림 대상을 설정하세요.

예시

예시는 5분 동안 한 번 이상 실패하면 알람 상태가 바뀌도록 지표를 연결합니다. CloudTrail 로그 전달과 알림 대상은 별도로 구성하세요.

변경 전

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-ConsoleAuthenticationFailure"
  pattern        = "{ ($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\") }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-ConsoleAuthenticationFailure"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.6-ConsoleAuthenticationFailure"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = "XXX NOT YOUR FILTER"
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

변경 후

hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-ConsoleAuthenticationFailure"
  pattern        = "{ (($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\")) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-ConsoleAuthenticationFailure"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-3.6-ConsoleAuthenticationFailure"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = aws_cloudwatch_log_metric_filter.example.id
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

참조