๐Ÿ’ญ Minji's Archive

[KT Cloud TechUp] AWS KMS / S3 / Kinesis / SHIELD

October 13, 2025

KMS

  • Key Management Service
  • ๊ฐœ๋ฐœ์„ ํ•˜๋‹ค ๋ณด๋ฉด ํ™˜๊ฒฝ๋ณ€์ˆ˜/์„ค์ • ํŒŒ์ผ์— ๋น„๋ฐ€๋ฒˆํ˜ธ, API ํ‚ค, DB ๋น„๋ฐ€๋ฒˆํ˜ธ ๋“ฑ ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ๋„ฃ์–ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ์Œ
  • ์—ฌ๋Ÿฌ ๋ช…๊ณผ ํ˜‘์—…ํ•˜๊ฑฐ๋‚˜ ๋ฐฐํฌ ์‹ค์ˆ˜ํ•˜์—ฌ ๋ณด์•ˆ ๊ด€๋ จ ๋ฌธ์ œ ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ
  • ๋Œ€์นญ/๋น„๋Œ€์นญํ‚ค ๊ด€๋ฆฌ
  • ๊ถŒํ•œ ์ œ์–ด
  • ํ†ตํ•ฉ ๋ณด์•ˆ: S3/RDS/Lambda์™€ ๊ฐ™์ด ์—ฐ๊ณ„ํ•ด์„œ ํ™œ์šฉ
  • ๊ฐ์‚ฌ ๋กœ๊ทธ: AWS CloudTrail๊ณผ ํ†ตํ•ฉํ•ด ํ‚ค ์‚ฌ์šฉ ๋‚ด์—ญ ์ถ”์  ๊ฐ€๋Šฅ
  • ํ‚ค ๊ฐœ์ˆ˜๋ณ„๋กœ ์›” $1, ์•”๋ณตํ˜ธํ™” ์š”์ฒญ $0.03/1000๊ฑด, AWS ์„œ๋น„์Šค ๋‚ด ํ†ตํ•ฉ ์‚ฌ์šฉ
  • AWS Managed Key: AWS ์„œ๋น„์Šค๋“ค์ด KMS๋ฅผ ํ†ตํ•ด Key๋ฅผ ์„œ๋น„์Šค๋ฐ›๋Š” ๊ฒƒ์œผ๋กœ ๋‚ด๋ถ€์ ์œผ๋กœ ์ž๋™์œผ๋กœ ์ผ์–ด๋‚˜๋ฉฐ ์‚ฌ์šฉ์ž์˜ ์ง์ ‘์ ์ธ ์ œ์–ด ๋ถˆ๊ฐ€
  • CMK (Customer Managed Key): ์‚ฌ์šฉ์ž๊ฐ€ ์ง์ ‘ ํ‚ค ์ƒ์„ฑ/๊ด€๋ฆฌ
  • Custom Key Stores: CloudHSM์„ ํ™œ์šฉํ•œ ํ‚ค ๊ด€๋ฆฌ
    • CloudHSM: AWS์˜ ํ•˜๋“œ์›จ์–ด ์•”ํ˜ธํ™” ์žฅ๋น„๋ฅผ ํ†ตํ•œ ํ•˜๋“œ์›จ์–ด ๋ฐฉ์‹ ์•”ํ˜ธํ™”. ์•”ํ˜ธํ™” ํ‚ค ๊ด€๋ฆฌ๋ฅผ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ํ•ด์•ผ ํ•จ

S3

  • Amazon Simple Storage Service
  • ๊ฐ์ฒด ์Šคํ† ๋ฆฌ์ง€ ์„œ๋น„์Šค
  • ์ธํ„ฐ๋„ท์„ ํ†ตํ•ด ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ณ  ๊ฒ€์ƒ‰ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ํ™•์žฅ์„ฑ/๋‚ด๊ตฌ์„ฑ/๋ณด์•ˆ์„ฑ์ด ๋†’์€ ๊ตฌ์กฐ๋ฅผ ๊ฐ–๊ณ  ์žˆ์–ด ์›น ํ˜ธ์ŠคํŒ…, ๋ฐฑ์—…, ๋กœ๊ทธ ์ €์žฅ, ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ๋“ฑ ๋‹ค์–‘ํ•œ ์šฉ๋„๋กœ ํ™œ์šฉ
  • ๊ฐ„๋‹จํ•œ html ํ™ˆํŽ˜์ด์ง€๋กœ๋„ ์šด์˜ ๊ฐ€๋Šฅ
  • ๊ตฌ์„ฑ ์š”์†Œ
    • Bucket: ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๋Š” ๊ธฐ๋ณธ ์ปจํ…Œ์ด๋„ˆ (๋ชจ๋“  ๋ฆฌ์ „์—์„œ ๊ณ ์œ ๊ฐ’ ์ด๋ฆ„ ํ•„์š”)
      • ๋ฒ”์šฉ ๋ฒ„ํ‚ท: ๋‹จ์ˆœ ๊ฐ์ฒด ์ €์žฅ์šฉ. TREE ์—†์ด ๋‹จ์ผ flat ๊ตฌ์กฐ. ์Šคํฌ๋ฆฝํŠธ/์ž๋™ํ™” ์ฒ˜๋ฆฌ ๊ตฌํ˜„์ด ํŽธ๋ฆฌํ•˜์ง€๋งŒ flatํ•˜๊ธฐ ๋–„๋ฌธ์— ์ง๊ด€์ ์œผ๋กœ ๋ณด๊ธฐ ์–ด๋ ต๊ณ , ๊ฐ์ฒด๊ฐ€ ๋งŽ์ด ์Œ“์ด๋ฉด Key ๊ด€๋ฆฌ๊ฐ€ ๋ณต์žกํ•ด์ง
      • ๋””๋ ‰ํ„ฐ๋ฆฌ ๋ฒ„ํ‚ท: ๊ฐ์ฒด key์— /๋ฅผ ์‚ฌ์šฉํ•ด ํด๋”์ฒ˜๋Ÿผ ๊ณ„์ธตํ™”. ์‚ฌ๋žŒ ๋ˆˆ์œผ๋กœ ๋ณด๊ธฐ ํŽธํ•จ (S3 ์ฝ˜์†”์—์„œ๋„ ํด๋”๊ฐ€ ํ‘œ์‹œ๋จ) ๋””๋ ‰ํ† ๋ฆฌ ๋‹จ์œ„๋กœ ๊ถŒํ•œ/์ •์ฑ…์ด ๋ถ€์—ฌ ๊ฐ€๋Šฅํ•จ. ํ•˜์ง€๋งŒ ๊ฐ์ฒด ์ด๋™/์‚ญ์ œ ์‹œ ์ „์ฒด Key ์ด๋ฆ„ ์ˆ˜์ •์ด ํ•„์š”
    • Object: S3์— ์ €์žฅ๋˜๋Š” ๋ฐ์ดํ„ฐ ๋‹จ์œ„ (ํŒŒ์ผ + ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ)
    • Key: ๋ฒ„ํ‚ท ๋‚ด ๊ฐ์ฒด๋ฅผ ์‹๋ณ„ํ•˜๋Š” ๊ณ ์œ  ๊ฒฝ๋กœ ๋˜๋Š” ์ด๋ฆ„
    • Region: ๋ฒ„ํ‚ท์ด ์œ„์น˜ํ•œ AWS ์ง€์—ญ
    • Versioning: ๊ฐ์ฒด์˜ ๋ฒ„์ „์„ ๊ด€๋ฆฌํ•˜๋Š” ๊ธฐ๋Šฅ (์‚ญ์ œ/๋ฎ์–ด์“ฐ๊ธฐ ๋ฐฉ์ง€)
    • Storage Class: ๋ฐ์ดํ„ฐ ์ ‘๊ทผ ๋นˆ๋„ ๋ฐ ๋‚ด๊ตฌ์„ฑ์— ๋”ฐ๋ฅธ ์ €์žฅ ํด๋ž˜์Šค (Standard/IA/Glacier)
  • ๋ณด์•ˆ ๊ธฐ๋Šฅ: IAM ์ •์ฑ…
  • ์„œ๋ฒ„ ์ธก ์•”ํ˜ธํ™” (์ €์žฅ ์ƒํƒœ ์•”ํ˜ธํ™”): SSE-S3, SSE-KMS(๊ถŒ์žฅ), SSE-C
    • SSE-S3: Amazon S3 ๊ด€๋ฆฌํ˜• ํ‚ค (๋ฌด๋ฃŒ)
    • SSE-KMS: AWS KMS๋ฅผ ์ด์šฉํ•œ ์„œ๋ฒ„ ์ธก ์•”ํ˜ธํ™” (์œ ๋ฃŒ)
    • DDSE-KMS: AWS KMS ํ‚ค๋ฅผ ์‚ฌ์šฉํ•œ ์ด์ค‘ ๊ณ„์ธต ์„œ๋ฒ„ ์ธก ์•”ํ˜ธํ™”
  • ACLs (Access Control Lists): ๋น„๊ถŒ์žฅ, ๋ฒ„ํ‚ท ๋ฐ ๊ฐ์ฒด์— ๋Œ€ํ•œ ์ฝ๊ธฐ/์“ฐ๊ธฐ ์ ‘๊ทผ ๊ถŒํ•œ ๋ถ€์—ฌ (์„ธ๋ฐ€ํ•œ ์ œ์–ด๋Š” ๋ฒ„ํ‚ท ์ •์ฑ…/IAM ์‚ฌ์šฉ ๊ถŒ์žฅ)
  • MFA Delete: ๋ฒ„์ „ ์‚ญ์ œ์‹œ MFA ์ธ์ฆ ์š”๊ตฌ

Kinesis

  • ์ŠคํŠธ๋ฆฌ๋ฐ ๋ฐ์ดํ„ฐ๋ฅผ ๋‹ค๋ฃจ๋Š” ์„œ๋น„์Šค

  • ๋Œ€๋Ÿ‰์˜ ๋ฐ์ดํ„ฐ ์†Œ์Šค๋กœ ์ธํ•ด ์‹ค์‹œ๊ฐ„์œผ๋กœ ์—ฐ์†์ ์œผ๋กœ ์ƒ์„ฑ๋˜๋Š” ๋ฐ์ดํ„ฐ (๋กœ๊ทธ, IoT ๋ฐ์ดํ„ฐ)

  • Kinesis Data Streams

  • Kinesis Data Firehose (Amazon Data Firehose)

    • SIEM์—์„œ S3๋กœ ๋ณด๋‚ผ๋•Œ ์‚ฌ์šฉ
    • ์ˆ˜์ง‘ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅ์†Œ/๋ถ„์„ ํˆด๋กœ ์ „์†กํ•˜๋Š” ์„œ๋น„์Šค
    • ๋ณต์žกํ•œ ์„ค์ • ์—†์ด ๋ฐ์ดํ„ฐ ์ „์†ก ๊ฐ€๋Šฅ, Serverles ์„œ๋น„์Šค๋ผ์„œ ์šฉ๋Ÿ‰ ์„ค์ •๋„ ํ•„์š”์—†์Œ
    • ์ „์†ก๋œ ๋ฐ์ดํ„ฐ ์–‘์— ๋”ฐ๋ผ ์š”๊ธˆ ๋ฐœ์ƒ, ๋ฐ์ดํ„ฐ๋ฅผ ๋‹ค๋ฅธ ํ˜•ํƒœ๋กœ ๋ณ€ํ™˜ํ•˜๋Š” ๊ฒฝ์šฐ์— ์š”๊ธˆ ๋ฐœ์ƒ (ex: Lambda ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•œ ๋ณ€ํ™˜)
    • ๊ตฌ์กฐ
      • Input > Logs
      • Transform (Lambda)
  • Kinesis Data Analytics (Amazon Managed Service for Apache Flink)

  • Kinesis Video Streams

Shield

  • Shield Advanced๋Š” ์›” $3000
  • Shield Standard
    • CloudFront, ELB (Elastic Load Balancing), Route 53, Global Accelerator
    • ๋„คํŠธ์›Œํฌ/์ „์†ก ๊ณ„์ธต(DDoS) ์ž๋™ ๋ฐฉ์–ด, ์ถ”๊ฐ€ ์š”๊ธˆ ์—†์ด ๊ธฐ๋ณธ์  ์ž๋™ ๋ณดํ˜ธ ์ ์šฉ
    • ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ณ„์ธต (HTTP flood ๋“ฑ) ๋ณดํ˜ธ ์ผ๋ถ€ ์ œํ•œ์ 