설명
콘솔 로그인 실패는 비밀번호 입력 실수나 계정 공격 시도로 발생할 수 있습니다. 실패 이벤트를 모니터링해 반복되거나 의심스러운 시도를 조사하세요.
잠재적 영향
알림이 없으면 반복되는 로그인 실패를 늦게 발견하고 조사 시작이 지연될 수 있습니다.
해결 방법
ConsoleLogin과 Failed authentication을 함께 확인하는 로그 메트릭 필터를 구성하세요. 필터 지표에 알람을 연결하고 운영 환경에 맞는 임계값과 알림 대상을 설정하세요.
예시
예시는 5분 동안 한 번 이상 실패하면 알람 상태가 바뀌도록 지표를 연결합니다. CloudTrail 로그 전달과 알림 대상은 별도로 구성하세요.
변경 전
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-ConsoleAuthenticationFailure"
pattern = "{ ($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\") }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-ConsoleAuthenticationFailure"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.6-ConsoleAuthenticationFailure"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = "XXX NOT YOUR FILTER"
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}
변경 후
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-ConsoleAuthenticationFailure"
pattern = "{ (($.eventName = ConsoleLogin) && ($.errorMessage = \"Failed authentication\")) }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-ConsoleAuthenticationFailure"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.6-ConsoleAuthenticationFailure"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = aws_cloudwatch_log_metric_filter.example.id
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}