Source: AWS Security Blog
Author: Nisha Amthul
URL: https://aws.amazon.com/blogs/security/navigating-amazon-guardduty-protection-plans-and-extended-threat-detection/
ONE SENTENCE SUMMARY:
Organizations leverage Amazon GuardDuty’s AI-driven threat detection services to enhance security across AWS environments with various protection plans.
MAIN POINTS:
- Amazon GuardDuty uses AI and ML for continuous AWS environment threat detection.
- Protection plans extend GuardDuty’s capabilities to specific AWS services like S3 and EKS.
- S3 Protection detects data exfiltration and unauthorized bucket changes.
- EKS Protection analyzes Kubernetes audit logs for malicious activities.
- Runtime Monitoring identifies threats at the operating system level on EC2 and container workloads.
- Malware Protection scans EBS volumes and S3 objects for known threats.
- RDS Protection analyzes login activities for potential unauthorized database access.
- Lambda Protection monitors network activities to detect serverless function threats.
- Enabling relevant protection plans offers cost-effective, comprehensive monitoring.
- Extended Threat Detection leverages AI to correlate security signals and highlight active threats.
TAKEAWAYS:
- Align protection plans with workload types for optimal threat detection.
- Use Extended Threat Detection for enhanced security insights.
- Protection plans are flexible, enabling customized security strategies.
- GuardDuty maps findings to MITRE ATT&CK® for context.
- Each plan includes a 30-day trial to evaluate security needs.