揭开 IAM 权限的面纱:API Gateway 访问日志
bishopfox.com | 博客 | #cloud | #cloud-security | #aws | #data-protection | #iam | #api-gateway | #access-logging
摘要
Bishop Fox 指出 AWS API Gateway 访问日志默认不加密、持有相应 IAM 权限即可查看;文章演示如何通过数据保护策略掩蔽日志中的敏感信息(如 AWS 密钥),并建议生产环境不要开启完整请求/响应日志。
- 发布时间
- 收录时间
Skip to content