METHODS OF CONNECTION TO AWS VIRTUAL SERVER LOCATED IN A PRIVATE SUBNET

M. S. Mamuta, I. V. Kravchenko, O. D. Mamuta
{"title":"METHODS OF CONNECTION TO AWS VIRTUAL SERVER LOCATED IN A PRIVATE SUBNET","authors":"M. S. Mamuta, I. V. Kravchenko, O. D. Mamuta","doi":"10.31649/1999-9941-2023-57-2-33-42","DOIUrl":null,"url":null,"abstract":"In today's world of total digitization cyber security and safe work with data in cyberspace are the most important questions. Especially this is actual for Ukraine, where the number and power of cyberattacks has increased several times over the last year. Businesses that work with private customer data become especially vulnerable. Of course, the ideal option is to place such data on servers that don’t have Internet access. But according to the global trend of moving to the cloud, it is inevitable for private data as well. And so, there is a question of protecting private data in the cloud. To this end, cloud service providers offer services to create private subnets without Internet access. Therefore, the question of how to securely access data in such subnets become actual. One of the leader’s vendors in cloud servicing is Amazon with its Web Services. Amazon offers a Virtual Private Cloud service for setting up a virtual network. The article deals with the analysis of configuration features at the stage of creation of subnets with and without Internet access. The method of connection to a virtual server, located in a private subnet, using the Secure Shell network protocol was analyzed. However, this method has a number of disadvantages. It requires to launch an additional server and its administration. The method also has quite complex settings of the network and requires managing keys. Therefore, another method of connection to private EC2 instance was proposed. The method requires Amazon Systems Manager service, which provides secure access to data without creating additional server, is cost-effective and convenient. At the same time, all connections take place over a secure channel between the Systems Manager agent and the Amazon data center. Main setting’s features for the proposed method were considered.","PeriodicalId":479698,"journal":{"name":"Ìnformacìjnì tehnologìï ta kompʼûterna ìnženerìâ","volume":"24 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Ìnformacìjnì tehnologìï ta kompʼûterna ìnženerìâ","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.31649/1999-9941-2023-57-2-33-42","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

In today's world of total digitization cyber security and safe work with data in cyberspace are the most important questions. Especially this is actual for Ukraine, where the number and power of cyberattacks has increased several times over the last year. Businesses that work with private customer data become especially vulnerable. Of course, the ideal option is to place such data on servers that don’t have Internet access. But according to the global trend of moving to the cloud, it is inevitable for private data as well. And so, there is a question of protecting private data in the cloud. To this end, cloud service providers offer services to create private subnets without Internet access. Therefore, the question of how to securely access data in such subnets become actual. One of the leader’s vendors in cloud servicing is Amazon with its Web Services. Amazon offers a Virtual Private Cloud service for setting up a virtual network. The article deals with the analysis of configuration features at the stage of creation of subnets with and without Internet access. The method of connection to a virtual server, located in a private subnet, using the Secure Shell network protocol was analyzed. However, this method has a number of disadvantages. It requires to launch an additional server and its administration. The method also has quite complex settings of the network and requires managing keys. Therefore, another method of connection to private EC2 instance was proposed. The method requires Amazon Systems Manager service, which provides secure access to data without creating additional server, is cost-effective and convenient. At the same time, all connections take place over a secure channel between the Systems Manager agent and the Amazon data center. Main setting’s features for the proposed method were considered.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
连接到位于私有子网中的aws虚拟服务器的方法
在全面数字化的今天,网络安全和网络空间数据安全工作是最重要的问题。尤其是在乌克兰,网络攻击的数量和力量在去年增加了几倍。处理私人客户数据的企业尤其容易受到攻击。当然,理想的选择是将这些数据放在不能访问Internet的服务器上。但随着全球云化趋势的发展,私有数据也将不可避免。因此,有一个保护云中的私人数据的问题。为此,云服务提供商提供了创建不接入Internet的私有子网的服务。因此,如何安全地访问这些子网中的数据成为现实问题。在云服务领域领先的供应商之一是亚马逊的网络服务。亚马逊提供了虚拟私有云服务来建立虚拟网络。本文分析了在有Internet接入和没有Internet接入的情况下创建子网时的配置特点。分析了利用Secure Shell网络协议连接到位于私有子网中的虚拟服务器的方法。然而,这种方法有一些缺点。它需要启动一个额外的服务器及其管理。该方法也有相当复杂的网络设置,需要管理密钥。因此,提出了另一种连接到私有EC2实例的方法。该方法需要Amazon Systems Manager服务,该服务提供对数据的安全访问,而无需创建额外的服务器,具有成本效益和便利性。同时,所有连接都通过system Manager代理和Amazon数据中心之间的安全通道进行。考虑了所提方法的主要设置特征。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
ANALYSIS OF THE ARCHITECTURE OF SUCCESSIVE APPROXIMATION REGISTER ADC AND APPROACHES TO ITS IMPROVEMENT IMPROVEMENT OF ASSIGNING TASKS METHOD FOR THE VEHICLE MAINTENANCE EMPLOYEES BASED ON GENETIC AND HUNGARIAN ALGORITHMS IMPLEMENTATION OF ARBITRARY BITNESS PERMUTATIONS BASED ON COMBINED CASCADES OF STRUCTURAL UNITS OBJECT-ORIENTED IMPLEMENTATION OF A WEB APPLICATION FOR TRAFFIC SIMULATION DECISION-MAKING SUPPORT SYSTEM FOR DETERMINING THE FITNESS OF SCIENTIFIC AND EDUCATIONAL ACTIVITY OBJECTS TO SCIENTIFIC AND EDUCATIONAL FIELDS AND SPECIALTIES
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1