訂閱 Amazon SNS GuardDuty 公告 - Amazon GuardDuty

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

訂閱 Amazon SNS GuardDuty 公告

本節提供訂閱 Amazon SNS (簡單通知服務) 的相關資訊,以接收有關新發現項目類型的通知、現有發現項目類型的更新,以及其他功能變更的通知。 GuardDuty 所有 Amazon SNS 所支援格式的通知。

GuardDuty SNS 會將有關 GuardDuty 服務更新的公告傳送 AWS 到任何訂閱帳戶。若要接收有關帳戶內調查結果的通知,請參閱使用 Amazon CloudWatch 活動建立自訂回應的 GuardDuty 發現項目

注意

您的 IAM 使用者帳戶必須具有 sns::subscribe 許可,才能訂閱 SNS。

您可以訂閱此通知主題的 Amazon SQS 佇列,但使用的主題 ARN 必須位於相同的區域。如需詳細資訊,請參閱《Amazon Simple Queue Service 開發人員指南》中的教學課程:Subscribing an Amazon SQS queue to an Amazon SNS topic

您也可以使用 AWS Lambda 功能在收到通知時觸發事件。如需詳細資訊,請參閱《Amazon Simple Queue Service 開發人員指南》中的 Invoking Lambda functions using Amazon SNS notifications

每個區域的 Amazon SNS 主題 ARN 如下所示。

AWS 地區 Amazon SNS 主題 ARN
us-east-1 arn:aws:sns:us-east-1:242987662583:GuardDutyAnnouncements
us-east-2 arn:aws:sns:us-east-2:118283430703:GuardDutyAnnouncements
us-west-1 arn:aws:sns:us-west-1:144182107116:GuardDutyAnnouncements
us-west-2 arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements
ca-central-1 arn:aws:sns:ca-central-1:107430051933:GuardDutyAnnouncements
ca-west-1 arn:aws:sns:ca-west-1:440427180217:GuardDutyAnnouncements
eu-north-1 arn:aws:sns:eu-north-1:973841112453:GuardDutyAnnouncements
eu-west-1 arn:aws:sns:eu-west-1:965013871422:GuardDutyAnnouncements
eu-west-2 arn:aws:sns:eu-west-2:506403581195:GuardDutyAnnouncements
eu-west-3 arn:aws:sns:eu-west-3:436163563069:GuardDutyAnnouncements
eu-central-1 arn:aws:sns:eu-central-1:378365507264:GuardDutyAnnouncements
eu-central-2 arn:aws:sns:eu-central-2:383009515534:GuardDutyAnnouncements
ap-east-1 arn:aws:sns:ap-east-1:646602203151:GuardDutyAnnouncements
ap-northeast-1 arn:aws:sns:ap-northeast-1:741172661024:GuardDutyAnnouncements
ap-northeast-2 arn:aws:sns:ap-northeast-2:464168911255:GuardDutyAnnouncements
ap-southeast-1 arn:aws:sns:ap-southeast-1:476419727788:GuardDutyAnnouncements
ap-southeast-2 arn:aws:sns:ap-southeast-2:457615622431:GuardDutyAnnouncements
ap-south-1 arn:aws:sns:ap-south-1:926826061926:GuardDutyAnnouncements
sa-east-1 arn:aws:sns:sa-east-1:955633302743:GuardDutyAnnouncements
us-gov-west-1 arn:aws-us-gov:sns:us-gov-west-1:430639793359:GuardDutyAnnouncements
cn-north-1 arn:aws-cn:sns:cn-north-1:002991280229:GuardDutyAnnouncements
cn-northwest-1 arn:aws-cn:sns:cn-northwest-1:003033775354:GuardDutyAnnouncements
me-south-1 arn:aws:sns:me-south-1:552740612889:GuardDutyAnnouncements
me-central-1 arn:aws:sns:me-central-1:030935290150:GuardDutyAnnouncements
eu-south-1 arn:aws:sns:eu-south-1:188461706213:GuardDutyAnnouncements
eu-south-2 arn:aws:sns:eu-south-2:445632894446:GuardDutyAnnouncements
us-gov-east-1 arn:aws:sns:us-gov-east-1:143972945659:GuardDutyAnnouncements
ap-northeast-3 arn:aws:sns:ap-northeast-3:129086577509:GuardDutyAnnouncements
ap-southeast-3 arn:aws:sns:ap-southeast-3:225965583551:GuardDutyAnnouncements
ap-south-2 arn:aws:sns:ap-south-2:595653072700:GuardDutyAnnouncements
ap-southeast-4 arn:aws:sns:ap-southeast-4:529900636122:GuardDutyAnnouncements
il-central-1 arn:aws:sns:il-central-1:847886274986:GuardDutyAnnouncements
若要在中訂閱 GuardDuty 更新通知電子郵件 AWS Management Console
  1. https://console.aws.amazon.com/sns/v3/home 開啟 Amazon SNS 主控台。

  2. 在區域清單中,選擇與您要訂閱的主題 ARN 相同的區域。此範例使用 us-west-2 區域。

  3. 在左側導覽窗格中,選擇訂閱建立訂閱

  4. 建立訂閱對話方塊中,針對主題 ARN,貼上主題 ARN:arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements

  5. 對於通訊協定,選擇電子郵件。針對端點,輸入可用於接收通知的電子郵件地址。

  6. 選擇建立訂閱

  7. 在您的電子郵件應用程式中,開啟「 AWS 通知」中的訊息,然後開啟連結以確認您的訂閱。

    您的 Web 瀏覽器顯示自 Amazon SNS 的確認回覆。

若要使用訂閱 GuardDuty 更新通知電子郵件 AWS CLI
  1. 使用 AWS CLI執行下列命令:

    aws sns --region us-west-2 subscribe --topic-arn arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements --protocol email --notification-endpoint your_email@your_domain.com
  2. 在您的電子郵件應用程式中,開啟「 AWS 通知」中的訊息,然後開啟連結以確認您的訂閱。

    您的 Web 瀏覽器顯示自 Amazon SNS 的確認回覆。

Amazon SNS 訊息格式

有關新發現項目的 GuardDuty 更新通知訊息範例如下所示:

{ "Type" : "Notification", "MessageId" : "9101dc6b-726f-4df0-8646-ec2f94e674bc", "TopicArn" : "arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements", "Message" : "{\"version\":\"1\",\"type\":\"NEW_FINDINGS\",\"findingDetails\":[{\"link\":\"https://docs.aws.amazon.com//guardduty/latest/ug/guardduty_unauthorized.html\",\"findingType\":\"UnauthorizedAccess:EC2/TorClient\",\"findingDescription\":\"This finding informs you that an EC2 instance in your AWS environment is making connections to a Tor Guard or an Authority node. Tor is software for enabling anonymous communication. Tor Guards and Authority nodes act as initial gateways into a Tor network. This traffic can indicate that this EC2 instance is acting as a client on a Tor network. A common use for a Tor client is to circumvent network monitoring and filter for access to unauthorized or illicit content. Tor clients can also generate nefarious Internet traffic, including attacking SSH servers. This activity can indicate that your EC2 instance is compromised.\"}]}", "Timestamp" : "2018-03-09T00:25:43.483Z", "SignatureVersion" : "1", "Signature" : "XWox8GDGLRiCgDOXlo/fG9Lu/88P8S0FL6M6oQYOmUFzkucuhoblsdea3BjqdCHcWR7qdhMPQnLpN7y9iBrWVUqdAGJrukAI8athvAS+4AQD/V/QjrhsEnlj+GaiW+ozAu006X6GopOzFGnCtPMROjCMrMonjz7Hpv/8KRuMZR3pyQYm5d4wWB7xBPYhUMuLoZ1V8YFs55FMtgQV/YLhSYuEu0BP1GMtLQauxDkscOtPP/vjhGQLFx1Q9LTadcQiRHtNIBxWL87PSI+BVvkin6AL7PhksvdQ7FAgHfXsit+6p8GyOvKCqaeBG7HZhR1AbpyVka7JSNRO/6ssyrlj1g==", "SigningCertURL" : "https://sns.us-west-2.amazonaws.com/SimpleNotificationService-433026a4050d206028891664da859041.pem", "UnsubscribeURL" : "https://sns.us-west-2.amazonaws.com/?Action=Unsubscribe&SubscriptionArn=arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements:9225ed2b-7228-4665-8a01-c8a5db6859f4" }

已經移除逸出引號的剖析訊息數值會如下所示:

{ "version": "1", "type": "NEW_FINDINGS", "findingDetails": [{ "link": "https://docs.aws.amazon.com//guardduty/latest/ug/guardduty_unauthorized.html", "findingType": "UnauthorizedAccess:EC2/TorClient", "findingDescription": "This finding informs you that an EC2 instance in your AWS environment is making connections to a Tor Guard or an Authority node. Tor is software for enabling anonymous communication. Tor Guards and Authority nodes act as initial gateways into a Tor network. This traffic can indicate that this EC2 instance is acting as a client on a Tor network. A common use for a Tor client is to circumvent network monitoring and filter for access to unauthorized or illicit content. Tor clients can also generate nefarious Internet traffic, including attacking SSH servers. This activity can indicate that your EC2 instance is compromised." }] }

關於 GuardDuty 功能 GuardDuty 更新的範例更新通知訊息如下所示:

{ "Type" : "Notification", "MessageId" : "9101dc6b-726f-4df0-8646-ec2f94e674bc", "TopicArn" : "arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements", "Message" : "{\"version\":\"1\",\"type\":\"NEW_FEATURES\",\"featureDetails\":[{\"featureDescription\":\"Customers with high-volumes of global CloudTrail events should see a net positive impact on their GuardDuty costs.\",\"featureLink\":\"https://docs.aws.amazon.com//guardduty/latest/ug/guardduty_data-sources.html#guardduty_cloudtrail\"}]}", "Timestamp" : "2018-03-09T00:25:43.483Z", "SignatureVersion" : "1", "Signature" : "XWox8GDGLRiCgDOXlo/fG9Lu/88P8S0FL6M6oQYOmUFzkucuhoblsdea3BjqdCHcWR7qdhMPQnLpN7y9iBrWVUqdAGJrukAI8athvAS+4AQD/V/QjrhsEnlj+GaiW+ozAu006X6GopOzFGnCtPMROjCMrMonjz7Hpv/8KRuMZR3pyQYm5d4wWB7xBPYhUMuLoZ1V8YFs55FMtgQV/YLhSYuEu0BP1GMtLQauxDkscOtPP/vjhGQLFx1Q9LTadcQiRHtNIBxWL87PSI+BVvkin6AL7PhksvdQ7FAgHfXsit+6p8GyOvKCqaeBG7HZhR1AbpyVka7JSNRO/6ssyrlj1g==", "SigningCertURL" : "https://sns.us-west-2.amazonaws.com/SimpleNotificationService-433026a4050d206028891664da859041.pem", "UnsubscribeURL" : "https://sns.us-west-2.amazonaws.com/?Action=Unsubscribe&SubscriptionArn=arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements:9225ed2b-7228-4665-8a01-c8a5db6859f4" }

已經移除逸出引號的剖析訊息數值會如下所示:

{ "version": "1", "type": "NEW_FEATURES", "featureDetails": [{ "featureDescription": "Customers with high-volumes of global CloudTrail events should see a net positive impact on their GuardDuty costs.", "featureLink": "https://docs.aws.amazon.com//guardduty/latest/ug/guardduty_data-sources.html#guardduty_cloudtrail" }] }

有關 GuardDuty 更新發現項目的更新通知訊息範例如下所示:

{ "Type": "Notification", "MessageId": "9101dc6b-726f-4df0-8646-ec2f94e674bc", "TopicArn": "arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements", "Message": "{\"version\":\"1\",\"type\":\"UPDATED_FINDINGS\",\"findingDetails\":[{\"link\":\"https://docs.aws.amazon.com//guardduty/latest/ug/guardduty_unauthorized.html\",\"findingType\":\"UnauthorizedAccess:EC2/TorClient\",\"description\":\"Increased severity value from 5 to 8.\"}]}", "Timestamp": "2018-03-09T00:25:43.483Z", "SignatureVersion": "1", "Signature": "XWox8GDGLRiCgDOXlo/fG9Lu/88P8S0FL6M6oQYOmUFzkucuhoblsdea3BjqdCHcWR7qdhMPQnLpN7y9iBrWVUqdAGJrukAI8athvAS+4AQD/V/QjrhsEnlj+GaiW+ozAu006X6GopOzFGnCtPMROjCMrMonjz7Hpv/8KRuMZR3pyQYm5d4wWB7xBPYhUMuLoZ1V8YFs55FMtgQV/YLhSYuEu0BP1GMtLQauxDkscOtPP/vjhGQLFx1Q9LTadcQiRHtNIBxWL87PSI+BVvkin6AL7PhksvdQ7FAgHfXsit+6p8GyOvKCqaeBG7HZhR1AbpyVka7JSNRO/6ssyrlj1g==", "SigningCertURL": "https://sns.us-west-2.amazonaws.com/SimpleNotificationService-433026a4050d206028891664da859041.pem", "UnsubscribeURL": "https://sns.us-west-2.amazonaws.com/?Action=Unsubscribe&SubscriptionArn=arn:aws:sns:us-west-2:934957504740:GuardDutyAnnouncements:9225ed2b-7228-4665-8a01-c8a5db6859f4" }

已經移除逸出引號的剖析訊息數值會如下所示:

{ "version": "1", "type": "UPDATED_FINDINGS", "findingDetails": [{ "link": "https://docs.aws.amazon.com//guardduty/latest/ug/guardduty_unauthorized.html", "findingType": "UnauthorizedAccess:EC2/TorClient", "description": "Increased severity value from 5 to 8." }] }