AWS EC2 VPC-如何从EC2实例中找到高意外流量的目的地和数据?

发布于 2025-01-24 11:09:00 字数 785 浏览 2 评论 0原文

对于EC2实例(Linux),它遇到了大量意外的网络流量,进出。从500 MB/5分钟到6GB/5分钟,连续6小时以上。我们没有启用VPC流量日志。据怀疑安全漏洞,是数据的不必要传输。 我们有兴趣知道传输了哪些数据和哪些数据。 问题:

  1. 由于这发生在过去,并且我们没有启用VPC流量日志,因此AWS是否有办法确定数据传输何处(IP,HostName)?
  2. 在将来发生的情况下,我想解决方案是在EC2实例接口上启用了AWS VPC Flowlogs https://docs.aws.amazon.com/vpc/latest/userguide/userguide/flow-lflows.html#flow-logs-logs-default 并检查DSTADDR和PKT-DSTADDR是否有外向流量。您可以确认吗?
  3. 我想要找到传输哪些数据(哪些文件),AWS不可能告诉您哪种本地(EC2)解决方案会建议?我想拥有一个CloudWatch Monitor,以提醒我们,当吞吐量达到设定的阈值时,我可以运行一个数据包捕获工具(TCPDUMP)以捕获该接口上的流量(本地或S3上的流量 - 取决于大小)。
  4. 除了AWS流量日志外,这意味着额外的费用,哪种本地(EC2,Linux)数据流量工具您会建议运行24/7并保存日志吗? 谢谢。

For an EC2 instance (Linux) it was encountered huge unexpected network traffic, in and out. From 500 MB/5min to 6GB/5min for 6+ hours continuously. We do not have VPC flow logs enabled. It is suspected a security breach, an unwanted transferring of data.
We would be interested in knowing where and what data was transferred.
Questions:

  1. Since this happened in the past and we did not have VPC flow logs enabled, is there a way for AWS to determine where the data was transferred (IP, hostname)?
  2. In the case it happens in the future, I guess the solution is to have enabled AWS VPC Flowlogs on the EC2 instance interface https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html#flow-logs-default and check for dstaddr and pkt-dstaddr for outgoing traffic. May you confirm?
  3. I guess to find what data (which files) was transmitted it is not possible for AWS to tell but which local (on EC2) solution would you advise? I am thinking to have a Cloudwatch monitor to alert us when throughput reaches a set threshold and then I can run a packet capture tool (tcpdump) to capture traffic on that interface (locally or on S3 - depending on the size).
  4. Except AWS Flow Logs which implies additional costs, which local (on EC2, Linux)data traffic tool for monitoring would you recommend to run 24/7 and save logs?
    Thank you.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

梅窗月明清似水 2025-01-31 11:09:00

AWS Shield总是在所有AWS帐户上运行。如果您有业务或企业支持计划,则可以升级为AWS Shield响应团队(SRT),他们可以为您提供帮助。 aws支持

AWS Shield is always running on all AWS accounts. If you have a Business or Enterprise support plan you could escalate to the AWS Shield Response Team (SRT) and they could assist you. AWS Support

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文