北京——2023年6月15日,亞(ya)馬(ma)遜云(yun)科(ke)技(ji)在(zai)re:Inforce 2023全球(qiu)大會上宣布,推(tui)出十多項安全新服務及功能,包括Amazon Verified Permissions正式可(ke)用、擴展Amazon Detective發現組的范圍、Amazon Inspector全面支持Lambda函數的代碼掃描、推(tui)出Amazon CodeGuru Security預覽版以及Amazon Build-in Partner Solutions預覽版等。
Amazon Verified Permissions正式可用
Amazon Verified Permissions可(ke)以(yi)(yi)為用(yong)(yong)(yong)戶(hu)(hu)(hu)構建(jian)的(de)(de)應(ying)用(yong)(yong)(yong)程序(xu)(xu)提(ti)供細(xi)粒(li)度(du)授(shou)權(quan)(quan)和(he)權(quan)(quan)限管(guan)理(li)。Verified Permissions使(shi)(shi)用(yong)(yong)(yong)了(le)用(yong)(yong)(yong)于(yu)訪問(wen)控制(zhi)的(de)(de)開源(yuan)語(yu)言(yan)Cedar,用(yong)(yong)(yong)戶(hu)(hu)(hu)使(shi)(shi)用(yong)(yong)(yong)Cedar可(ke)以(yi)(yi)將(jiang)權(quan)(quan)限定(ding)義為更(geng)容易(yi)理(li)解的(de)(de)策(ce)略。用(yong)(yong)(yong)戶(hu)(hu)(hu)可(ke)以(yi)(yi)使(shi)(shi)用(yong)(yong)(yong)Verified Permissions管(guan)理(li)其應(ying)用(yong)(yong)(yong)程序(xu)(xu)的(de)(de)角色和(he)屬性(xing)的(de)(de)訪問(wen)控制(zhi)。Amazon Verified Permissions旨在實現(xian)高可(ke)用(yong)(yong)(yong)性(xing)和(he)可(ke)擴展性(xing),可(ke)以(yi)(yi)持續(xu)評估用(yong)(yong)(yong)戶(hu)(hu)(hu)的(de)(de)授(shou)權(quan)(quan)決(jue)策(ce)。用(yong)(yong)(yong)戶(hu)(hu)(hu)使(shi)(shi)用(yong)(yong)(yong)Verified Permissions可(ke)將(jiang)授(shou)權(quan)(quan)與應(ying)用(yong)(yong)(yong)程序(xu)(xu)邏輯分離,并(bing)借(jie)助集中式策(ce)略存儲、可(ke)重(zhong)復使(shi)(shi)用(yong)(yong)(yong)的(de)(de)策(ce)略模板和(he)策(ce)略測試,實現(xian)更(geng)快(kuai)速地構建(jian)更(geng)安全的(de)(de)應(ying)用(yong)(yong)(yong)程序(xu)(xu)。用(yong)(yong)(yong)戶(hu)(hu)(hu)可(ke)以(yi)(yi)使(shi)(shi)用(yong)(yong)(yong)現(xian)有身份權(quan)(quan)限(管(guan)理(li)用(yong)(yong)(yong)戶(hu)(hu)(hu)及用(yong)(yong)(yong)戶(hu)(hu)(hu)組(zu))管(guan)理(li)應(ying)用(yong)(yong)(yong)程序(xu)(xu)并(bing)控制(zhi)訪問(wen)。現(xian)在,用(yong)(yong)(yong)戶(hu)(hu)(hu)可(ke)以(yi)(yi)使(shi)(shi)用(yong)(yong)(yong)整合(he)其應(ying)用(yong)(yong)(yong)程序(xu)(xu)的(de)(de)身份驗(yan)證(zheng)和(he)授(shou)權(quan)(quan)解決(jue)方(fang)案。用(yong)(yong)(yong)戶(hu)(hu)(hu)可(ke)以(yi)(yi)基于(yu)Amazon Cognito的(de)(de)屬性(xing)進行(xing)驗(yan)證(zheng)策(ce)略,并(bing)通過Amazon Cognito口令處理(li)授(shou)權(quan)(quan)請求(qiu)。欲了(le)解更(geng)多Amazon Verified Permissions信息(xi),請訪問(wen):
Amazon Detective擴大發現組的范圍至Amazon Inspector
Amazon Detective現(xian)已擴大(da)其發(fa)(fa)現(xian)組的(de)范(fan)圍,將Amazon Inspector網絡觸達、軟件漏(lou)洞發(fa)(fa)現(xian)結果(guo)以(yi)(yi)(yi)及發(fa)(fa)現(xian)結果(guo)納(na)入其中(zhong)。整合的(de)威脅和(he)漏(lou)洞發(fa)(fa)現(xian)可(ke)以(yi)(yi)(yi)幫助企(qi)業的(de)安全(quan)(quan)分析(xi)人員優先處理更重(zhong)要(yao)事務(wu)。Amazon Detective可(ke)以(yi)(yi)(yi)自動地從Amazon Inspector、Amazon GuardDuty以(yi)(yi)(yi)及如Amazon Security Hub等亞(ya)馬遜(xun)云科技的(de)其他安全(quan)(quan)服(fu)務(wu)收集(ji)發(fa)(fa)現(xian)結果(guo),來(lai)提升對相關安全(quan)(quan)事件的(de)感知。Detective發(fa)(fa)現(xian)組利(li)用機(ji)器學習(xi)技術(shu),可(ke)以(yi)(yi)(yi)幫助專(zhuan)業安全(quan)(quan)人員加快調(diao)查過程、確定(ding)根本原因,并(bing)利(li)用MITRE ATT&CK框架映射來(lai)快速(su)解(jie)決安全(quan)(quan)問(wen)題。用戶(hu)要(yao)使用該(gai)擴展功能,可(ke)以(yi)(yi)(yi)在Detective管理控(kong)制臺中(zhong)啟用亞(ya)馬遜(xun)云科技安全(quan)(quan)發(fa)(fa)現(xian)的(de)可(ke)選(xuan)數據源(yuan)。欲了(le)解(jie)更多信息,請訪問(wen):
Amazon Inspector現已支持Amazon Lambda函數代碼掃描
Amazon Inspector的(de)功能(neng)擴(kuo)展(zhan)(zhan)至(zhi)支(zhi)持掃描(miao)Lambda函(han)數及相關層(ceng)以查(cha)找應用程(cheng)序(xu)包(bao)依賴(lai)項中的(de)軟件漏(lou)(lou)洞。基于亞馬遜云科技安(an)全(quan)(quan)最(zui)佳實(shi)踐,Amazon Inspector的(de)擴(kuo)展(zhan)(zhan)新(xin)功能(neng)將支(zhi)持掃描(miao)Lambda函(han)數中的(de)自定義專有應用程(cheng)序(xu)代碼(ma)(ma),并查(cha)找代碼(ma)(ma)安(an)全(quan)(quan)漏(lou)(lou)洞,比(bi)如(ru)注(zhu)入缺陷、數據(ju)泄漏(lou)(lou)、弱加(jia)密(mi)或(huo)加(jia)密(mi)缺失。一旦檢測到(dao)(dao)Lambda函(han)數或(huo)層(ceng)中的(de)代碼(ma)(ma)漏(lou)(lou)洞,Amazon Inspector就會(hui)生成可執行的(de)安(an)全(quan)(quan)發(fa)現結果(guo),具體包(bao)括提(ti)供安(an)全(quan)(quan)檢測器名稱、受影響的(de)代碼(ma)(ma)片(pian)段和修復漏(lou)(lou)洞的(de)補(bu)救(jiu)建(jian)議等細節。所(suo)有發(fa)現結果(guo)都將匯集(ji)到(dao)(dao)Amazon Inspector控制臺()中,無縫傳輸至(zhi)Amazon Security Hub,并推(tui)送(song)到(dao)(dao)Amazon EventBridge以實(shi)現工作流(liu)程(cheng)自動化。欲了解更(geng)多信息,請(qing)訪問:
推出Amazon CodeGuru Security預覽版
Amazon CodeGuru Security預覽版是一款靜(jing)態應用(yong)程(cheng)(cheng)序安全測試(SAST)工(gong)(gong)具,利用(yong)機器(qi)學習技術(shu)幫助(zhu)用(yong)戶(hu)識別代(dai)(dai)(dai)碼(ma)(ma)漏(lou)(lou)洞,并提(ti)供(gong)修復(fu)漏(lou)(lou)洞的(de)(de)指導意見。CodeGuru Security還為(wei)某(mou)些類(lei)型的(de)(de)漏(lou)(lou)洞提(ti)供(gong)上(shang)下文(wen)代(dai)(dai)(dai)碼(ma)(ma)補丁,幫助(zhu)用(yong)戶(hu)減少修復(fu)代(dai)(dai)(dai)碼(ma)(ma)漏(lou)(lou)洞所需(xu)的(de)(de)工(gong)(gong)作量。通過對應用(yong)程(cheng)(cheng)序代(dai)(dai)(dai)碼(ma)(ma)進行深入的(de)(de)語(yu)義分析,CodeGuru Security以低誤報率檢(jian)測漏(lou)(lou)洞,使工(gong)(gong)程(cheng)(cheng)和安全團隊(dui)能夠更(geng)高效地篩選發現結果。CodeGuru Security可以標記一系列廣泛(fan)問題,比如日志注入、硬編(bian)碼(ma)(ma)憑據和資源泄露(lu)等,并可以集成在開發工(gong)(gong)作流(liu)程(cheng)(cheng)的(de)(de)不(bu)同階段(duan)(代(dai)(dai)(dai)碼(ma)(ma)存儲庫、持續集成/持續交付管道和容器(qi)注冊等)。欲了解更(geng)多信息(xi),請訪問:
推出Amazon Build-in Partner Solutions預覽版
Amazon Build-in Partner Solutiosn預覽(lan)版現(xian)(xian)已在(zai)Amazon Marketplace上推出,致(zhi)力于幫助(zhu)更(geng)多客(ke)(ke)戶(hu)更(geng)快(kuai)的(de)(de)發展(zhan)業(ye)務(wu)并(bing)實(shi)現(xian)(xian)規(gui)模化。該(gai)(gai)解決(jue)方案基于亞馬遜云(yun)科技的(de)(de)最佳(jia)實(shi)踐,旨在(zai)客(ke)(ke)戶(hu)多賬戶(hu)環境中實(shi)現(xian)(xian)自動(dong)化,并(bing)進行資源配置和規(gui)模擴(kuo)展(zhan)。該(gai)(gai)解決(jue)方案為客(ke)(ke)戶(hu)在(zai)其業(ye)務(wu)快(kuai)速發展(zhan)以及擴(kuo)大規(gui)模的(de)(de)過程(cheng)中,提供始終一致(zhi)的(de)(de)體驗,同時借助(zhu)云(yun)服務(wu)提升自身的(de)(de)安全。欲(yu)了解更(geng)多信息(xi),請訪(fang)問(wen):