{"id":36476,"date":"2022-02-01T12:46:04","date_gmt":"2022-02-01T12:46:04","guid":{"rendered":"https:\/\/www.vmengine.net\/2022\/02\/01\/cloud-security-manage-vulnerabilities-automatically-with-aws\/"},"modified":"2025-05-23T17:32:49","modified_gmt":"2025-05-23T17:32:49","slug":"cloud-security-manage-vulnerabilities-automatically-with-aws","status":"publish","type":"post","link":"http:\/\/temp_new.vmenginelab.com\/en\/2022\/02\/01\/cloud-security-manage-vulnerabilities-automatically-with-aws\/","title":{"rendered":"Cloud &amp; Security, Manage Vulnerabilities Automatically with AWS"},"content":{"rendered":"<div class=\"et_pb_section et_pb_section_369 et_section_regular\" >\n<div class=\"et_pb_row et_pb_row_467\">\n<div class=\"et_pb_column et_pb_column_4_4 et_pb_column_473  et_pb_css_mix_blend_mode_passthrough et-last-child\">\n<div class=\"et_pb_module et_pb_text et_pb_text_1596  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>Have a service that can instantly discover and scan<a href=\"https:\/\/aws.amazon.com\/it\/?nc2=h_lg\"><br \/>\n  <strong> Amazon Web Services<\/strong><br \/>\n<\/a> workloads for software vulnerabilities and inadvertent network exposure with a single click. If you were thinking that it&#8217;s literally impossible, you&#8217;re very wrong. It&#8217;s called <a href=\"https:\/\/aws.amazon.com\/it\/inspector\/\"><br \/>\n  <strong>Amazon Inspector<\/strong><br \/>\n<\/a> , and it&#8217;s an <strong>AWS<\/strong> service that organizations of all sizes use <strong>to automate security assessment and management at scale<\/strong> to <strong>improve application security and compliance<\/strong>.<br \/>Originally introduced in 2015, <strong>Amazon Inspector<\/strong> has simplified the effort of implementing a detection mechanism for both operating systems and applications on <a href=\"https:\/\/aws.amazon.com\/it\/ec2\/instance-types\/\"><strong>EC2 instances<\/strong> <\/a>and container images that reside in<a href=\"https:\/\/aws.amazon.com\/it\/ecr\/\"><strong> Amazon Elastic Container Registry (Amazon ECR).<\/strong><\/p>\n<p><\/a> Amazon Inspector automatically evaluates vulnerabilities and deviations from best practices. It provides a detailed report that includes the steps for repair after each assessment is performed.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_image et_pb_image_420\">\n<p>\t\t\t\t<span class=\"et_pb_image_wrap \"><img decoding=\"async\" src=\"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/inspector-aws-2.jpg\" alt=\"\" title=\"AWS Inspector\"  sizes=\"(max-width: 740px) 100vw, 740px\" class=\"wp-image-34563\" \/><\/span>\n\t\t\t<\/div>\n<div class=\"et_pb_module et_pb_cta_343 et_pb_promo  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_promo_description et_multi_view_hidden\"><\/div>\n<div class=\"et_pb_button_wrapper\"><a class=\"et_pb_button et_pb_promo_button\" href=\"https:\/\/temp_new.vmenginelab.com\/2021\/08\/19\/network-e-security-best-practices-e-servizi-aws\/\" target=\"_blank\">Network and security. AWS Best Practices and Services<\/a><\/div>\n<\/p><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1597  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>We were recently introduced to a new <strong>Amazon Inspector<\/strong> that replaces what is now called <a href=\"https:\/\/docs.aws.amazon.com\/inspector\/v1\/userguide\/inspector_introduction.html\"><br \/>\n  <strong>Amazon Inspector Classic<\/strong><br \/>\n<\/a>. There are significant differences between the two, mainly related to <strong>automation<\/strong>, <strong>integration<\/strong> <strong>with other AWS services<\/strong> , and <strong>near real-time performance<\/strong>. Amazon Inspector is now<a href=\"https:\/\/aws.amazon.com\/it\/about-aws\/global-infrastructure\/regions_az\/\"><br \/>\n  <strong> available in 19 global regions<\/strong><br \/>\n<\/a>. You can scan your environment for vulnerabilities with a <a href=\"https:\/\/aws.amazon.com\/it\/inspector\/pricing\/\"><br \/>\n  <strong>15-day free trial<\/strong><br \/>\n<\/a>.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1598  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>But what does it do specifically? Let&#8217;s figure it out together.<\/p>\n<p>The first significant enhancement to Amazon Inspector is that it uses<a href=\"https:\/\/docs.aws.amazon.com\/it_it\/systems-manager\/latest\/userguide\/what-is-systems-manager.html\"><br \/>\n  <strong> the Systems Manager agent<\/strong><br \/>\n<\/a>. The previous version used its own dedicated agent. Merging agents <strong>simplifies provisioning<\/strong> and improves performance. The System Management Agent is automatically installed on most <strong>Amazon Linux and AWS Windows AMIs<\/strong>. This agent is available on <a href=\"https:\/\/github.com\/\"><br \/>\n  <strong>GitHub<\/strong><br \/>\n<\/a> and is <strong>open source<\/strong>.<br \/>What&#8217;s really important is that <strong>merging agents<\/strong> allows<strong> Amazon Inspector<\/strong> <strong>to integrate with other services and system managers<\/strong>, allowing you to <strong>monitor your network<\/strong>, <strong>file system<\/strong> , and<strong> process activity<\/strong>.<\/p>\n<p>It also<strong> checks the operating system<\/strong> and all <strong>installed applications<\/strong>. It includes a knowledge base with hundreds of rules on <strong>security<\/strong> compliance standards and<strong> vulnerability definitions<\/strong>. It provides <strong>severity score<\/strong> control with the <strong>security metrics<\/strong> that make up the <a href=\"https:\/\/nvd.nist.gov\/\"><br \/>\n  <strong>National Vulnerability Database (ed. NVD<\/strong><br \/>\n<\/a>) and adapts them to your environment. The score is in <strong>CVSS<\/strong> format and is compatible with the <strong>Common Vulnerability Scoring System<\/strong> score provided by the National Vulnerability Database. You can always check if your fleet has <strong>vulnerable software<\/strong> versions installed and take the required <strong>mitigation<\/strong> measures. If you dim a result, <strong>the Inspector<\/strong> detects the correction and closes the result.<\/p>\n<\/div><\/div>\n<div class=\"et_pb_module et_pb_cta_344 et_pb_promo  et_pb_text_align_center et_pb_bg_layout_light\">\n<div class=\"et_pb_promo_description et_multi_view_hidden\"><\/div>\n<div class=\"et_pb_button_wrapper\"><a class=\"et_pb_button et_pb_promo_button\" href=\"https:\/\/temp_new.vmenginelab.com\/2021\/09\/30\/secrets-manager-il-servizio-keyholder-di-aws\/\" target=\"_blank\">See also Secrets Manager<\/a><\/div>\n<\/p><\/div>\n<div class=\"et_pb_module et_pb_image et_pb_image_421\">\n<p>\t\t\t\t<span class=\"et_pb_image_wrap \"><img decoding=\"async\" src=\"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/nvd-immagine-2.png\" alt=\"\" title=\"NVD image\"  sizes=\"(max-width: 740px) 100vw, 740px\" class=\"wp-image-34567\" \/><\/span>\n\t\t\t<\/div>\n<div class=\"et_pb_module et_pb_text et_pb_text_1599  et_pb_text_align_left et_pb_bg_layout_light\">\n<div class=\"et_pb_text_inner\">\n<p>There are many web giants that rely on this feature. Starting with <a href=\"https:\/\/www.uber.com\/it\/en\/\"><br \/>\n  <strong>Uber<\/strong><br \/>\n<\/a>, the San Francisco-based company that provides the smartest private car transport service there is. &#8220;<em>The new Amazon Inspector <\/em>,&#8221; said Oliver Szimmetat, Security Engineering Manager  <em>&#8211; Simplified the adoption of a <strong>cloud vulnerability<\/strong> management solution for our different AWS instances. Leveraging our existing Systems Manager agents with Inspector, <strong>we&#8217;ve automated ongoing remediation and<\/strong> streamlined operations with one-click <strong>onboarding, centralized controls<\/strong> , and <strong>operational visibility<\/strong>. In addition, Inspector&#8217;s <strong>auto-trigger<\/strong> capability identifies recommended patches in near real-time. After patching, Inspector automatically re-examines the instances, verifying that no new vulnerabilities have been introduced. The use of Inspector has dramatically reduced the mean time to repair for Uber<\/em>\u201d.<\/p>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Here are the web giants that have chosen Amazon Inspector.<\/p>\n","protected":false},"author":3,"featured_media":34562,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[97,2297,1374],"tags":[4798,3304,4799,133,4800,4801],"class_list":["post-36476","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en","category-news-en","category-the-analysis","tag-amazon-inspector-en","tag-amazon-web-service-en","tag-automation-en","tag-aws-en","tag-cloud-vulnerabilities","tag-vulnerability-en"],"aioseo_notices":[],"jetpack_featured_media_url":"http:\/\/temp_new.vmenginelab.com\/wp-content\/uploads\/2022\/02\/automations-1.gif","amp_enabled":true,"_links":{"self":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/comments?post=36476"}],"version-history":[{"count":1,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36476\/revisions"}],"predecessor-version":[{"id":41688,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/posts\/36476\/revisions\/41688"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/media\/34562"}],"wp:attachment":[{"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/media?parent=36476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/categories?post=36476"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/temp_new.vmenginelab.com\/en\/wp-json\/wp\/v2\/tags?post=36476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}