Skip to main content

ikb42603-cloud-security-labs

AWS cloud computing security essentials lab exercises covering IAM, encryption, network security, and monitoring

الانتقال إلى التثبيت

معلومات المصدر

المستودع
reason-machines/security-skills
آخر نشاط في المصدر
٣١ يوليو ٢٠٢٦ في ١٦:١١
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
١٢
التفرعات
١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
ikb42603-cloud-security-labs
description
AWS cloud computing security essentials lab exercises covering IAM, encryption, network security, and monitoring
triggers
["how do I complete the cloud security labs","setup AWS IAM lab exercise","configure cloud encryption with KMS","implement AWS security group rules","setup CloudTrail and CloudWatch monitoring","create secure VPC isolation","configure AWS multi-factor authentication","troubleshoot AWS security configurations"]
# IKB42603 Cloud Security Labs Skill > Skill by [ara.so](https://ara.so) — Security Skills collection. ## Overview This project provides hands-on laboratory exercises for learning AWS cloud computing security essentials. It covers five core security domains: account security and IAM, secure isolation and multitenancy, encryption and key management, access control and network security, and monitoring/logging/incident detection. The labs are designed for educational purposes and follow a structured approach to implementing AWS security best practices using real AWS services. ## Repository Structure The project organizes labs into separate markdown files: ``` IKB42603-CLOUD-COMPUTING-SECURITY-ESSENTIALS/ ├── README.md ├── Lab0_Environment_Setup.md ├── Lab1_Account_Security_and_IAM.md ├── Lab2_Secure_Isolation_and_Multitenancy.md ├── Lab3_Encryption_and_Key_Management.md ├── Lab4_Access_Control_and_Network_Security.md └── Lab5_Monitoring_Logging_and_Incident_Detection.md ``` ## Prerequisites ### Required Tools 1. **AWS Account** - Free tier eligible 2. **AWS CLI** - Command line interface for AWS services 3. **Git** - Version control 4. **Text Editor** - VS Code, Vim, or similar ### AWS CLI Installation ```bash # macOS brew install awscli # Linux curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" unzip awscliv2.zip sudo ./aws/install # Windows (PowerShell) msiexec.exe /i https://awscli.amazonaws.com/AWSCLIV2.msi ``` ### AWS CLI Configuration ```bash # Configure AWS credentials aws configure # Enter your credentials when prompted # AWS Access Key ID: ${AWS_ACCESS_KEY_ID} # AWS Secret Access Key: ${AWS_SECRET_ACCESS_KEY} # Default region: us-east-1 # Default output format: json ``` ## Lab 1: Account Security and IAM ### Creating IAM Users ```bash # Create a new IAM user aws iam create-user --user-name lab-user-01 # Create access key for programmatic access aws iam create-access-key --user-name lab-user-01 # Attach policy to user aws iam attach-user-policy \ --user-name lab-user-01 \ --policy-arn arn:aws:iam::aws:policy/ReadOnlyAccess ``` ### Creating IAM Groups and Roles ```bash # Create IAM group aws iam create-group --group-name Developers # Add user to group aws iam add-user-to-group \ --user-name lab-user-01 \ --group-name Developers # Create IAM role with trust policy cat > trust-policy.json <<EOF { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "ec2.amazonaws.com" }, "Action": "sts:AssumeRole" } ] } EOF aws iam create-role \ --role-name EC2-S3-ReadOnly-Role \ --assume-role-policy-document file://trust-policy.json # Attach policy to role aws iam attach-role-policy \ --role-name EC2-S3-ReadOnly-Role \ --policy-arn arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess ``` ### Enabling MFA ```bash # Create virtual MFA device aws iam create-virtual-mfa-device \ --virtual-mfa-device-name lab-user-mfa \ --outfile qr-code.png \ --bootstrap-method QRCodePNG # Enable MFA for user (requires two consecutive authentication codes) aws iam enable-mfa-device \ --user-name lab-user-01 \ --serial-number arn:aws:iam::${ACCOUNT_ID}:mfa/lab-user-mfa \ --authentication-code-1 123456 \ --authentication-code-2 789012 ``` ### Custom IAM Policy Example ```json { "Version": "2012-10-17", "Statement": [ { "Sid": "AllowS3ReadWriteSpecificBucket", "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject", "s3:DeleteObject" ], "Resource": "arn:aws:s3:::my-lab-bucket/*" }, { "Sid": "AllowListBucket", "Effect": "Allow", "Action": "s3:ListBucket", "Resource": "arn:aws:s3:::my-lab-bucket" } ] } ``` Apply custom policy: ```bash aws iam put-user-policy \ --user-name lab-user-01 \ --policy-name S3BucketAccess \ --policy-document file://custom-policy.json ``` ## Lab 2: Secure Isolation and Multitenancy ### Creating VPC with Subnets ```bash # Create VPC aws ec2 create-vpc \ --cidr-block 10.0.0.0/16 \ --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=LabVPC}]' # Store VPC ID VPC_ID=$(aws ec2 describe-vpcs \ --filters "Name=tag:Name,Values=LabVPC" \ --query 'Vpcs[0].VpcId' \ --output text) # Create public subnet aws ec2 create-subnet \ --vpc-id ${VPC_ID} \ --cidr-block 10.0.1.0/24 \ --availability-zone us-east-1a \ --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=PublicSubnet}]' # Create private subnet aws ec2 create-subnet \ --vpc-id ${VPC_ID} \ --cidr-block 10.0.2.0/24 \ --availability-zone us-east-1b \ --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=PrivateSubnet}]' ``` ### Internet Gateway and Route Tables ```bash # Create and attach Internet Gateway aws ec2 create-internet-gateway \ --tag-specifications 'ResourceType=internet-gateway,Tags=[{Key=Name,Value=LabIGW}]' IGW_ID=$(aws ec2 describe-internet-gateways \ --filters "Name=tag:Name,Values=LabIGW" \ --query 'InternetGateways[0].InternetGatewayId' \ --output text) aws ec2 attach-internet-gateway \ --vpc-id ${VPC_ID} \ --internet-gateway-id ${IGW_ID} # Create route table for public subnet aws ec2 create-route-table \ --vpc-id ${VPC_ID} \ --tag-specifications 'ResourceType=route-table,Tags=[{Key=Name,Value=PublicRouteTable}]' RT_ID=$(aws ec2 describe-route-tables \ --filters "Name=tag:Name,Values=PublicRouteTable" \ --query 'RouteTables[0].RouteTableId' \ --output text) # Add route to Internet Gateway aws ec2 create-route \ --route-table-id ${RT_ID} \ --destination-cidr-block 0.0.0.0/0 \ --gateway-id ${IGW_ID} # Associate route table with public subnet SUBNET_ID=$(aws ec2 describe-subnets \ --filters "Name=tag:Name,Values=PublicSubnet" \ --query 'Subnets[0].SubnetId' \ --output text) aws ec2 associate-route-table \ --route-table-id ${RT_ID} \ --subnet-id ${SUBNET_ID} ``` ### NAT Gateway for Private Subnet ```bash # Allocate Elastic IP aws ec2 allocate-address --domain vpc EIP_ID=$(aws ec2 describe-addresses \ --query 'Addresses[0].AllocationId' \ --output text) # Create NAT Gateway in public subnet aws ec2 create-nat-gateway \ --subnet-id ${SUBNET_ID} \ --allocation-id ${EIP_ID} \ --tag-specifications 'ResourceType=natgateway,Tags=[{Key=Name,Value=LabNAT}]' ``` ## Lab 3: Encryption and Key Management ### Creating KMS Keys ```bash # Create customer managed key aws kms create-key \ --description "Lab encryption key for S3" \ --key-usage ENCRYPT_DECRYPT \ --origin AWS_KMS KEY_ID=$(aws kms list-keys --query 'Keys[0].KeyId' --output text) # Create alias for the key aws kms create-alias \ --alias-name alias/lab-s3-key \ --target-key-id ${KEY_ID} # Get key details aws kms describe-key --key-id alias/lab-s3-key ``` ### S3 Bucket Encryption ```bash # Create S3 bucket with encryption aws s3api create-bucket \ --bucket my-encrypted-lab-bucket-${RANDOM} \ --region us-east-1 BUCKET_NAME=$(aws s3api list-buckets \ --query 'Buckets[-1].Name' \ --output text) # Enable default encryption with KMS aws s3api put-bucket-encryption \ --bucket ${BUCKET_NAME} \ --server-side-encryption-configuration '{ "Rules": [ { "ApplyServerSideEncryptionByDefault": { "SSEAlgorithm": "aws:kms", "KMSMasterKeyID": "'${KEY_ID}'" }, "BucketKeyEnabled": true } ] }' # Upload encrypted object aws s3 cp document.txt s3://${BUCKET_NAME}/ \ --sse aws:kms \ --sse-kms-key-id ${KEY_ID} ``` ### EBS Volume Encryption ```bash # Create encrypted EBS volume aws ec2 create-volume \ --size 10 \ --encrypted \ --kms-key-id ${KEY_ID} \ --availability-zone us-east-1a \ --tag-specifications 'ResourceType=volume,Tags=[{Key=Name,Value=EncryptedVolume}]' # Enable encryption by default for the region aws ec2 enable-ebs-encryption-by-default ``` ### RDS Encryption ```bash # Create encrypted RDS instance aws rds create-db-instance \ --db-instance-identifier lab-encrypted-db \ --db-instance-class db.t3.micro \ --engine mysql \ --master-username admin \ --master-user-password ${DB_PASSWORD} \ --allocated-storage 20 \ --storage-encrypted \ --kms-key-id ${KEY_ID} ``` ## Lab 4: Access Control and Network Security ### Security Groups ```bash # Create security group for web server aws ec2 create-security-group \ --group-name WebServerSG \ --description "Security group for web servers" \ --vpc-id ${VPC_ID} SG_ID=$(aws ec2 describe-security-groups \ --filters "Name=group-name,Values=WebServerSG" \ --query 'SecurityGroups[0].GroupId' \ --output text) # Allow HTTP traffic aws ec2 authorize-security-group-ingress \ --group-id ${SG_ID} \ --protocol tcp \ --port 80 \ --cidr 0.0.0.0/0 # Allow HTTPS traffic aws ec2 authorize-security-group-ingress \ --group-id ${SG_ID} \ --protocol tcp \ --port 443 \ --cidr 0.0.0.0/0 # Allow SSH from specific IP aws ec2 authorize-security-group-ingress \ --group-id ${SG_ID} \ --protocol tcp \ --port 22 \ --cidr ${MY_IP}/32 ``` ### Network ACLs ```bash # Create Network ACL aws ec2 create-network-acl \ --vpc-id ${VPC_ID} \ --tag-specifications 'ResourceType=network-acl,Tags=[{Key=Name,Value=CustomNACL}]' NACL_ID=$(aws ec2 describe-network-acls \ --filters "Name=tag:Name,Values=CustomNACL" \ --query 'NetworkAcls[0].NetworkAclId' \ --output text) # Allow inbound HTTP aws ec2 create-network-acl-entry \ --network-acl-id ${NACL_ID} \ --rule-number 100 \ --protocol tcp \ --port-range From=80,To=80 \ --cidr-block 0.0.0.0/0 \ --egress false \ --rule-action allow # Allow outbound traffic aws ec2 create-network-acl-entry \ --network-acl-id ${NACL_ID} \ --rule-number 100 \ --protocol -1 \ --cidr-block 0.0.0.0/0 \ --egress true \ --rule-action allow ``` ### VPC Flow Logs ```bash # Create CloudWatch Log Group aws logs create-log-group --log-group-name /aws/vpc/flowlogs # Create IAM role for Flow Logs cat > flow-logs-trust.json <<EOF { "Version": "2012-10-17", "Statement": [ {
عرض على GitHub
ملف SKILL.md هذا كبير جدا، لذلك يعرض SkillsMP القسم الاول فقط هنا. عرض على GitHub