-
Notifications
You must be signed in to change notification settings - Fork 16
/
service_support.html
94 lines (73 loc) · 6.27 KB
/
service_support.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="description" content="Table of the services that have SLAs, CloudTrail support, encryption at rest by default, and some other features.">
<meta name="keywords" content="aws,security,amazon,enterprise,defense,infosec,cyber">
<title>AWS Service Support table</title>
<link rel="icon" href="https://summitroute.com/favicon.ico" sizes="16x16 32x32 64x64" type="image/vnd.microsoft.icon">
<link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/3.4.0/css/bootstrap.min.css" integrity="sha384-PmY9l28YgO4JwMKbTvgaS7XNZJ30MK9FAZjjzXtlqyZCqBY6X6bXIkM++IkyinN+" crossorigin="anonymous">
<link href="https://fonts.googleapis.com/css?family=Roboto:regular" rel="stylesheet">
<style>
body {
font-family: 'Roboto', sans-serif;
font-weight: 300;
font-style: normal;
}
</style>
<link href="https://unpkg.com/[email protected]/dist/css/tabulator.min.css" rel="stylesheet">
<script type="text/javascript" src="https://unpkg.com/[email protected]/dist/js/tabulator.min.js"></script>
</head>
<body>
<div class="container">
<a href="https://github.com/SummitRoute/aws_research"><img style="position: absolute; top: 0; right: 0; border: 0;" src="https://s3.amazonaws.com/github/ribbons/forkme_right_red_aa0000.png" alt="Fork me on GitHub"></a>
<center>
<h1>AWS Service Support</h1>
<a href="https://summitroute.com"><img src="https://summitroute.com/img/logo.png" width="200px"></a><br>
Created by Scott Piper of Summit Route, an independent AWS security consultant.
</center>
<br><br>
<p>The goal of this page is to high-light the lack of coverage AWS provides for its services across different security factors. These limitations are not well-understood by many. Further, the "Y" fields are meant to indicate that this service has any capability for the relevant factor. In many cases, this is not full coverage for the service, or there are exceptions or special cases.
<p>Last Update: 2019.01.06
<p><a href="./">Other research</a>
<p><b><u>Columns</u></b><br>
<ul>
<li><b>SLA</b>: This column indicates if there is a Service Level Agreement. These are documented <a href="https://aws.amazon.com/legal/service-level-agreements/">here</a>. These aren't as great as you'd hope. They only guarantee some cost savings in the event of an outage if the service is down for more than a period of time (ie. you still pay when the service is down, just less if it is really bad). These do not cover every part of a service. For example, the SLA for RDS does not cover any of the Aurora flavors.
<li><b>CloudFormation</b>: Indicates whether any CloudFormation support at all is provided for this service.
<li><b>CloudTrail</b>: AWS is supposed to log all API calls to CloudTrail. This column indicates if the service logs at all to CloudTrail, as documented <a href="https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-unsupported-aws-services.html">here</a>. Note that new features of existing services often do not log to CloudTrail, for example, the boundary related APIs of IAM do not. Also, data level calls sometimes do not. In the case of S3 objects and Lambda invokes, you can specially configure CloudTrail to record these, but in some cases, such as the CloudWatch PutMetricData call, these are never recorded.
<li><b>Config</b>: The AWS Config service is meant to give you a snapshot of how an account looks. The resources it records are documented <a href="https://docs.aws.amazon.com/config/latest/developerguide/resource-config-reference.html">here</a>. Some services, such as EC2, contain a lot of resource types, and not all resources are recorded by AWS Config.
<li><b>Encryption at rest by default</b>: In 2019, or really since maybe 2015 or earlier, you'd expect all data to be stored encrypted at rest by default. This is not the case with AWS. This column was researched manually by reviewing the docs. Some fields here need to be changed to "N/A" to account for the fact that they don't store any data.
<li><b>Runs in all regions</b>: As new services are announced, they normally only run in a few regions initially. As new regions are announced, they normally don't support all services. Some services are likely to remain in only one specific region forever, such as Device Farm, which only runs in us-west-2. This column is only for the AWS partition regions and not China or GovCloud. This data was found <a href="https://github.com/boto/botocore/blob/develop/botocore/data/endpoints.json">here</a> and running <tt>cat botocore/data/endpoints.json | jq -cr '.partitions[0].services | keys[] as $k | (.[$k] | .endpoints | keys[] as $e | [$k, $e])' | grep -v local | grep -v fips | grep -v sandbox | grep -v s3-external-1 | grep -v aws-global | sed 's/,.*//' | sort | uniq -c | grep 15</tt>.
</ul>
<div id="table"></div>
</div>
<script>
formatcolor = function(cell, formatterParams){
style ="";
if (cell.getValue() == "Y") {
cell.getElement().style = "background-color:#b7e1cd";
};
if (cell.getValue() == "N") {
cell.getElement().style = "background-color:#f4c7c3";
};
return cell.getValue();
};
var table = new Tabulator("#table", {
layout:"fitColumns",
layoutColumnsOnNewData:true,
placeholder:"No Data Set",
columns:[
{title:"Service", field:"service", sorter:"string", width:200},
{title:"SLA", field:"sla", formatter:formatcolor, sorter:"string"},
{title:"CloudFormation", field:"cloudformation", formatter:formatcolor, sorter:"string"},
{title:"CloudTrail", field:"cloudtrail", formatter:formatcolor, sorter:"string"},
{title:"Config", field:"config", formatter:formatcolor, sorter:"string"},
{title:"Encryption at rest by default", field:"encryption_at_rest", formatter:formatcolor, sorter:"string"},
{title:"Tagging", field:"tagging", formatter:formatcolor, sorter:"string"},
{title:"All regions", field:"all_regions", formatter:formatcolor, sorter:"string"},
],
});
table.setData("./service_support.json");
</script>