With Amazon GuardDuty, you possibly can monitor your AWS accounts and workloads to detect malicious exercise. In the present day, we’re including to GuardDuty the aptitude to detect malware. Malware is malicious software program that’s used to compromise workloads, repurpose sources, or achieve unauthorized entry to information. When you will have GuardDuty Malware Safety enabled, a malware scan is initiated when GuardDuty detects that one in all your EC2 cases or container workloads working on EC2 is doing one thing suspicious. For instance, a malware scan is triggered when an EC2 occasion is speaking with a command-and-control server that’s recognized to be malicious or is performing denial of service (DoS) or brute-force assaults towards different EC2 cases.
GuardDuty helps many file system varieties and scans file codecs recognized for use to unfold or include malware, together with Home windows and Linux executables, PDF information, archives, binaries, scripts, installers, e-mail databases, and plain emails.
When potential malware is recognized, actionable safety findings are generated with data such because the risk and file identify, the file path, the EC2 occasion ID, useful resource tags and, within the case of containers, the container ID and the container picture used. GuardDuty helps container workloads working on EC2, together with customer-managed Kubernetes clusters or particular person Docker containers. If the container is managed by Amazon Elastic Kubernetes Service (EKS) or Amazon Elastic Container Service (Amazon ECS), the findings additionally embrace the cluster identify and the process or pod ID so software and safety groups can shortly discover the affected container sources.
As with all different GuardDuty findings, malware detections are despatched to the GuardDuty console, pushed by means of Amazon EventBridge, routed to AWS Safety Hub, and made obtainable in Amazon Detective for incident investigation.
How GuardDuty Malware Safety Works
Once you allow malware safety, you arrange an AWS Id and Entry Administration (IAM) service-linked position that grants GuardDuty permissions to carry out malware scans. When a malware scan is initiated for an EC2 occasion, GuardDuty Malware Safety makes use of these permissions to take a snapshot of the connected Amazon Elastic Block Retailer (EBS) volumes which might be lower than 1 TB in dimension after which restore the EBS volumes in an AWS service account in the identical AWS Area to scan them for malware. You should utilize tagging to incorporate or exclude EC2 cases from these permissions and from scanning. On this method, you don’t must deploy safety software program or brokers to watch for malware, and scanning the volumes doesn’t influence working workloads. The EBS volumes within the service account and the snapshots in your account are deleted after the scan. Optionally, you possibly can protect the snapshots when malware is detected.
The service-linked position grants GuardDuty entry to AWS Key Administration Service (AWS KMS) keys used to encrypt EBS volumes. If the EBS volumes connected to a probably compromised EC2 occasion are encrypted with a customer-managed key, GuardDuty Malware Safety makes use of the identical key to encrypt the reproduction EBS volumes as nicely. If the volumes are usually not encrypted, GuardDuty makes use of its personal key to encrypt the reproduction EBS volumes and guarantee privateness. Volumes encrypted with EBS-managed keys are usually not supported.
Safety in cloud is a shared duty between you and AWS. As a guardrail, the service-linked position utilized by GuardDuty Malware Safety can’t carry out any operation in your sources (corresponding to EBS snapshots and volumes, EC2 cases, and KMS keys) if it has the
GuardDutyExcluded tag. When you mark your snapshots with
GuardDutyExcluded set to
true, the GuardDuty service received’t be capable to entry these snapshots. The
GuardDutyExcluded tag supersedes any inclusion tag. Permissions additionally limit how GuardDuty can modify your snapshot in order that they can’t be made public whereas shared with the GuardDuty service account.
The EBS volumes created by GuardDuty are at all times encrypted. GuardDuty can use KMS keys solely on EBS snapshots which have a GuardDuty scan ID tag. The scan ID tag is added by GuardDuty when snapshots are created after an EC2 discovering. The KMS keys which might be shared with GuardDuty service account can’t be invoked from some other context besides the Amazon EBS service. As soon as the scan completes efficiently, the KMS key grant is revoked and the quantity reproduction in GuardDuty service account is deleted, ensuring GuardDuty service can’t entry your information after finishing the scan operation.
Enabling Malware Safety for an AWS Account
In the event you’re not utilizing GuardDuty but, Malware Safety is enabled by default whenever you activate GuardDuty on your account. As a result of I’m already utilizing GuardDuty, I must allow Malware Safety from the console. In the event you’re utilizing AWS Organizations, your delegated administrator accounts can allow this for current member accounts and configure if new AWS accounts within the group must be mechanically enrolled.
Within the GuardDuty console, I select Malware Safety underneath Settings within the navigation pane. There, I select Allow after which Allow Malware Safety.
Snapshots are mechanically deleted after they’re scanned. In Common settings, I’ve the choice to retain in my AWS account the snapshots the place malware is detected and have them obtainable for additional evaluation.
In Scan choices, I can configure an inventory of inclusion tags, in order that solely EC2 cases with these tags are scanned, or exclusion tags, in order that EC2 cases with tags within the record are skipped.
Testing Malware Safety GuardDuty Findings
To generate a number of Amazon GuardDuty findings, together with the brand new Malware Safety findings, I clone the Amazon GuardDuty Tester repo:
First, I create an AWS CloudFormation stack utilizing the
guardduty-tester.template file. When the stack is prepared, I observe the directions to configure my SSH shopper to log in to the tester occasion by means of the bastion host. Then, I hook up with the tester occasion:
From the tester occasion, I begin the
guardduty_tester.sh script to generate the findings:
After a couple of minutes, the findings seem within the GuardDuty console. On the prime, I see the malicious information discovered by the brand new Malware Safety functionality. One of many findings is expounded to an EC2 occasion, the opposite to an ECS cluster.
First, I choose the discovering associated to the EC2 occasion. Within the panel, I see the knowledge on the occasion and the malicious file, such because the file identify and path. Within the Malware scan particulars part, the Set off discovering ID factors to the unique GuardDuty discovering that triggered the malware scan. In my case, the unique discovering was that this EC2 occasion was performing RDP brute power assaults towards one other EC2 occasion.
Right here, I select Examine with Detective and, immediately from the GuardDuty console, I am going to the Detective console to visualise AWS CloudTrail and Amazon Digital Non-public Cloud (Amazon VPC) move information for the EC2 occasion, the AWS account, and the IP handle affected by the discovering. Utilizing Detective, I can analyze, examine, and determine the basis reason for suspicious actions discovered by GuardDuty.
Once I choose the discovering associated to the ECS cluster, I’ve extra data on the useful resource affected, corresponding to the small print of the ECS cluster, the duty, the containers, and the container photos.
Utilizing the GuardDuty tester scripts makes it simpler to check the general integration of GuardDuty with different safety frameworks you utilize so as to be prepared when an actual risk is detected.
Evaluating GuardDuty Malware Safety with Amazon Inspector
At this level, you may ask your self how GuardDuty Malware Safety pertains to Amazon Inspector, a service that scans AWS workloads for software program vulnerabilities and unintended community publicity. The 2 companies complement one another and supply totally different layers of safety:
- Amazon Inspector provides proactive safety by figuring out and remediating recognized software program and software vulnerabilities that function an entry level for attackers to compromise sources and set up malware.
- GuardDuty Malware Safety detects malware that’s discovered to be current on actively working workloads. At that time, the system has already been compromised, however GuardDuty can restrict the time of an an infection and take motion earlier than a system compromise leads to a business-impacting occasion.
Availability and Pricing
Amazon GuardDuty Malware Safety is on the market right now in all AWS Areas the place GuardDuty is on the market, excluding the AWS China (Beijing), AWS China (Ningxia), AWS GovCloud (US-East), and AWS GovCloud (US-West) Areas.
At launch, GuardDuty Malware Safety is built-in with these companion choices:
With GuardDuty, you don’t must deploy safety software program or brokers to watch for malware. You solely pay for the quantity of GB scanned within the file programs (not for the scale of the EBS volumes) and for the EBS snapshots through the time they’re saved in your account. All EBS snapshots created by GuardDuty are mechanically deleted after they’re scanned except you allow snapshot retention when malware is discovered. For extra data, see GuardDuty pricing and EBS pricing. Word that GuardDuty solely scans EBS volumes lower than 1 TB in dimension. That will help you management prices and keep away from repeating alarms, the identical quantity shouldn’t be scanned extra usually than as soon as each 24 hours.
Detect malicious exercise and shield your functions from malware with Amazon GuardDuty.