Detecting threats with Amazon GuardDuty
Amazon GuardDuty gives you a new type of threat detection service that was made specifically for the cloud. GuardDuty continuously monitors feeds from one or more accounts. It then continuously analyzes the network and account activity from the sources that are being driven into the GuardDuty service. From the input sources, the GuardDuty service then uses threat intelligence coupled with behavior models and machine learning to intelligently detect threats to your environment:
From the preceding diagram, we can see that getting GuardDuty up and running in your account takes a few simple steps:
- Enable the GuardDuty service – Activating the GuardDuty service will then start to analyze multiple types of logs within your account: VPC Flow Logs, DNS log entries, and CloudTrail Events.
- Continuously analyze the incoming events –...