Many cloud-enabled organizations leverage Amazon Web Services' (AWS) virtual private cloud (VPC), an on-demand managed cloud-computing service that isolates tenants' computing resources as an added layer of security. Amazon VPC provides clients with a private, non-routable subnet and a means to create IPSEC tunnels between the home network and the AWS VPC. The traffic that flows in and out of this VPC can be controlled via network access-control rules and security groups.
It all sounds perfectly ducky...until the moment you realize attackers could abuse your AWS infrastructure with insecure VPCs in their efforts to co-opt AWS resources for command-and-control nodes, data exfiltration, or a number of other nefarious ends. Once an EC2 instance is compromised, an attacker *could* initiate outbound network connections for malicious reasons.
Monitoring network traffic behaviors is crucial to understanding the types of traffic flowing in and out of your network and to alert you to suspicious activities. A new Analytic Story in the May 9 release of Enterprise Security Content Update, "Suspicious AWS Traffic," will monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors that could be indicative of malicious activity within your VPC. At that point, you can determine whether to investigate further.
Other updates included in this week's ESCU release are new detection, contextual, and support searches for the previously released "AWS Network ACL Activity" Analytic Story, which can help you monitor your AWS network infrastructure for bad configurations and malicious activity.
Update the Enterprise Security Content Update app now on Splunkbase to ensure you always have the latest analytics!
The Splunk platform removes the barriers between data and action, empowering observability, IT and security teams to ensure their organizations are secure, resilient and innovative.
Founded in 2003, Splunk is a global company — with over 7,500 employees, Splunkers have received over 1,020 patents to date and availability in 21 regions around the world — and offers an open, extensible data platform that supports shared data across any environment so that all teams in an organization can get end-to-end visibility, with context, for every interaction and business process. Build a strong data foundation with Splunk.