超詳細的解說AWS各個服務用到的安全技術,
如果沒有時間一一試驗AWS的服務,
可以從這份white paper當中快速了解各服務的目的以及底層仰賴的技術。
| Security Group | Network ACL |
|---|---|
|
Operates at the instance level (first layer of defense) |
Operates at the subnet level (second layer of defense) |
|
Supports allow rules only |
Supports allow rules and deny rules |
|
Is stateful: Return traffic is auwtomatically allowed, regardless of any rules |
Is stateless: Return traffic must be explicitly allowed by rules |
|
We evaluate all rules before deciding whether to allow traffic |
We process rules in number order when deciding whether to allow traffic |
|
Applies to an instance only if someone specifies the security group when launching the instance, or associates the security group with the instance later on |
Automatically applies to all instances in the subnets it's associated with (backup layer of defense, so you don't have to rely on someone specifying the security group) |