Saturday, February 4, 2023

What do you mean by Amazon Macie, Amazon Inspector and Amazon GuardDuty?

 

Amazon Macie is a security service that uses machine learning to automatically discover, classify, and protect sensitive data in AWS. Amazon Macie recognizes sensitive data such as personally identifiable information (PII) or intellectual property. It provides you with dashboards and alerts that give visibility into how this data is being accessed or moved. Amazon Macie is a fully managed service that continuously monitors data access activity for anomalies, and it generates detailed alerts when it detects risk of unauthorized access or inadvertent data leaks. Amazon Macie is currently available to protect data that is stored in Amazon S3.

Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications that are deployed on AWS. Amazon Inspector automatically assesses applications for exposure, vulnerabilities, and deviations from best practices. After performing an assessment, Amazon Inspector produces a detailed list of security findings that are listed by level of severity. These findings can be reviewed directly or as part of detailed assessment reports that are available via the Amazon Inspector console or the API.

Amazon GuardDuty is a threat-detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads. With the cloud, the collection and aggregation of account and network activities is simplified, but it can be time consuming for security teams to continuously analyze event log data for potential threats. GuardDuty uses machine learning, anomaly detection, and integrated threat intelligence to identify and rank potential threats. GuardDuty analyzes tens of billions of events across multiple AWS data sources, such as AWS CloudTrail, Amazon VPC Flow Logs, and Domain Name System(DNS) logs.




No comments:

Post a Comment

Explain the purpose of Data Link Layer and also draw the diagram for the same.

The Data Link layer is responsible for  Communications between end-device network interface cards. It allows upper layer protocols to access...