Securing Your AWS Resources

Ben Piper, David Clinton · 2018

This chapter explore the tools Amazon Web Services (AWS) provides to help you with that responsibility. The industry-standard tool for safely encrypting remote login sessions is the Secure Shell (SSH) protocol. Without encryption, all commands and keystrokes you enter during a terminal session run over an insecure network will be easily readable by anyone with access to that network. When that “network” is the internet, that can add up to a lot of unfriendly eyes on your data. Encryption converts those plain-text data packets into what looks like gibberish. Indeed, ideally-assuming no one has yet cracked the encryption algorithm you're using-that text is and will remain gibberish, unless you happen to have the decryption key required to decrypt it. The SSH protocol manages the encryption and decryption steps in the process as long as compatible keys are present at both ends of the connection. An IAM role is a set of permissions permitting access to a beneficiary process to a defined set of resources. This is an important tool for securely enabling functionality between parts of your AWS infrastructure.

Read the paper · More papers on PaperTik