<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Automated security assessment of Amazon Web Services accounts using CIS Benchmark and Python 3⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Oleksandr Volotovskyi</string-name>
          <email>oleksandr.volotovskyi.kb.2020@lpnu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Roman Banakh</string-name>
          <email>roman.i.banakh@lpnu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrian Piskozub</string-name>
          <email>andrian.z.piskozub@lpnu.ua</email>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Zoreslava Brzhevska</string-name>
          <email>z.brzhevska@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv Metropolitan University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudryavska str., 04053 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>CPITS-II 2024: Workshop on Cybersecurity Providing in Information and Telecommunication Systems II</institution>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Lviv Polytechnic National University</institution>
          ,
          <addr-line>12 Stepana Bandery str., 79013 Lviv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>363</fpage>
      <lpage>371</lpage>
      <abstract>
        <p>This paper focuses on the security assessment of Amazon Web Services (AWS) accounts using the Center for Internet Security (CIS) benchmarks. Considering the rapid growth of digital technologies and the increasing reliance on cloud services for business and personal use, ensuring the security of data and accounts is paramount. The study aims to analyze and assess the security posture of AWS accounts, emphasizing automating this process through Python 3 while also exploring the application of CIS benchmarks specific to the platform. A thorough examination of existing security evaluation methods and tools is conducted, including practical tests to ensure that AWS accounts comply with CIS benchmark security standards. The paper highlights the benefits of streamlining and enhancing the process to improve overall efficiency by automating the security assessment. The findings offer valuable insights for businesses and individual AWS users, providing practical recommendations to strengthen data security and ensure high confidentiality, integrity, and availability. These recommendations can be a foundation for developing and implementing effective security strategies in cloud environments.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;AWS</kwd>
        <kwd>CIS benchmarks</kwd>
        <kwd>cloud security</kwd>
        <kwd>automated security assessment</kwd>
        <kwd>compliance</kwd>
        <kwd>account security 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>In today’s digital world, where virtual infrastructure is
becoming integral to business and personal life, data and
account security is critical. This is especially true for cloud
platforms such as Amazon Web Services (AWS), which offer
a wide range of data storage, processing, and ans. In this
context, the issue of assessing the security of AWS accounts
becomes increasingly relevant. Although tools and methods
for security assessment, such as the CIS Benchmark for
AWS, play a crucial role in enhancing information security,
it is equally important to consider comprehensive
frameworks like ISO/IEC 27001:2022 and approaches such
as Secure as Code [1] to address configuration management
more effectively, as the lack of such comprehensive
approaches could lead to significant and potentially
irreversible losses.</p>
      <p>
        Assessing the security of Amazon Web Services
accounts using the Center for Internet Security (CIS)
benchmarks [2] and automating this process [
        <xref ref-type="bibr" rid="ref5">3</xref>
        ] allows for
effective monitoring and enhancement of security
measures. By utilizing existing methods and tools for
security evaluation, studying the CIS benchmark
recommendations for AWS, conducting practical tests, and
verifying account compliance with security standards, the
reliability of cloud environments can be significantly
improved [4].
      </p>
      <p>The CIS Benchmark recommendations cover the
configuration of various AWS services, such as Amazon S3
[5], Amazon EC2 [6], Amazon RDS [7], and others. These
guidelines help configure access permissions, ensure
effective monitoring and logging of events, and provide
automated tools to verify compliance with security
standards. Continuous updates in response to new threats
and changes in the AWS environment ensure the relevance
and effectiveness of security measures.</p>
      <p>Assessing AWS account security with CIS Benchmark is
a powerful tool for organizations looking to protect their
data and services in the cloud [8, 9]. Using such tools
mitigates risks and builds trust with customers and partners,
enhancing the organization’s reputation in the market.
Implementing the AWS CIS Benchmark is thus a strategic
step for any organization that aims to ensure the highest
level of security for its cloud resources.
2. Measures and tools to improve
security in AWS
The AWS CIS Benchmark is a set of recommendations and
guidelines for setting up security in an Amazon Web
0009-0003-3102-3694 (O. Volotovskyi);
0000-0001-6897-8206 (R. Banakh);
0000-0002-3582-2835 (A. Piskozub);
0000-0002-7029-9525 (Z. Brzhevska)
© 2024 Copyright for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).
Services (AWS) environment. CIS (Center for Internet
Security) is a non-profit organization specializing in
developing standards and methods for ensuring information
technology security.</p>
      <p>The AWS CIS Benchmark consists of recommendations
and guidelines to help organizations ensure a high level of
security for their accounts, resources, and services in the
AWS environment. This set includes recommendations for
configuring various AWS services, setting up access rights,
monitoring, logging, and other security aspects.</p>
      <p>Key features of the AWS CIS Benchmark:



</p>
      <p>Security Standards: The recommendations define
security standards for various AWS services,
including Amazon S3, Amazon EC2, Amazon RDS,
and others.</p>
      <p>Security Recommendations: The CIS Benchmark
provides detailed recommendations for securely
configuring AWS services and resources.</p>
      <p>Automated testing: The recommendations can be
used for automated security testing of an AWS
environment to detect security breaches and
compliance.</p>
      <p>Updates: CIS regularly updates its
recommendations to reflect changes in the AWS
environment and evolving security threats.</p>
      <p>Openness and community: CIS Benchmark is an open
standard, and all its recommendations are available for the
community and third-party developers.</p>
    </sec>
    <sec id="sec-2">
      <title>3. Compliance achievement with</title>
    </sec>
    <sec id="sec-3">
      <title>AWS Services</title>
      <p>Although AWS was created as a platform for providing
virtual machine services, today, this provider offers
hundreds of different services. Since there are many services
and the account owner can add many users to this account,
monitoring user activity is a natural need. Therefore, AWS
pays great attention to services for the security of user
accounts and their monitoring. In this discussion, we pay
attention to such services.</p>
      <sec id="sec-3-1">
        <title>3.1. Using AWS services to improve accounts’ security</title>
        <p>There are a couple of essential services that allow owners to
keep accounts safe. If you neglect them, you can lose access
to the account, which in turn can lead to reputational and
financial losses.</p>
        <sec id="sec-3-1-1">
          <title>3.1.1. Using the IAM service to improve accounts’ security</title>
          <p>There are several ways to provide unlimited and long-term
access to AWS S3 storage.</p>
          <p>The first way is to set access rules to the data in the
storage. Also, the number of people with access to S3
storage, even for senior management, should be limited if
there is no critical need for this.</p>
          <p>The second way is to use the least privilege rule. The
Identity and Access Management (IAM) service allows you
to restrict access to S3 storage with the proper settings.
Thus, users and programs are granted only the minimum
permissions necessary to perform their work. This approach
allows you to control permissions and reduces risks.</p>
          <p>The third way is temporary access through IAM roles.
The policy may be customized by adding conditions such as
IP addresses to define a secure process between the
application and S3 storage through IAM roles. This ensures
that access to data is temporary and limited.</p>
          <p>To prevent inappropriate permissions and privileges in
AWS, it is essential to proactively manage identity and
access rights by configuring user permissions according to
their roles and responsibilities.</p>
          <p>It is worth using an identity and access management
(IAM) provider that allows you to assign permissions to
each user or group of users. To increase the effectiveness of
permissions management, it is necessary to regularly review
all users with higher privileges and update their permissions
to match their current roles and responsibilities. This will
help avoid unauthorized use of permissions and ensure
compliance with the principle of least privilege.</p>
        </sec>
        <sec id="sec-3-1-2">
          <title>3.1.2. Using MFA and AWS secrets manager to improve accounts’ security</title>
          <p>
            To protect yourself from losing your AWS account, you
should use multi-factor authentication [
            <xref ref-type="bibr" rid="ref8">10</xref>
            ] to log in to your
account. This will provide an additional layer of security
and make it harder for an attacker to take over your
accounts, even if the data is compromised.
          </p>
          <p>It is also important to constantly monitor attempts to
log in to your accounts to detect possible intrusion attempts
in time.</p>
          <p>For more reliable control and security of credentials,
you can use AWS Secrets Manager, which provides the
ability to rotate credentials and store them in a stable
environment. This method will limit the risk of credential
theft and misuse of the infrastructure.</p>
        </sec>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Using AWS services for monitoring and logging</title>
        <p>
          In this section, we will use CloudTrail [
          <xref ref-type="bibr" rid="ref9">11</xref>
          ] to monitor and
audit account activity, AWS Config [
          <xref ref-type="bibr" rid="ref10">12</xref>
          ] for automated
configuration management and compliance, and AWS
GuardDuty to detect potential threats to the infrastructure.
Using these services allows you to maintain a high level of
security and respond to possible security threats on time.
        </p>
        <sec id="sec-3-2-1">
          <title>3.2.1. Using the CloudTrail service for monitoring and logging</title>
          <p>Enabling container access logging can prevent undetected
S3 storage request events. It is important to note that S3
storage does not create logs by default, so it is essential to
enable this feature. From then on, the S3 bucket will log all
types of requests they receive. In addition, they will log the
time of each request.</p>
          <p>Using access logs speeds up the process of detecting and
responding to unexpected activity.</p>
          <p>In addition, you should use Amazon CloudTrail. This
service allows you to track and log every API call to your
AWS account.</p>
          <p>Logs contain essential information such as IP addresses,
request execution time, and types of interactions.
Monitoring logs allow for the detection of dangerous or
unusual activities in time.</p>
          <p>This detection process is essential for preventing cyber
threats and security breaches. CloudTrail makes it easy to
receive notifications of security events, such as root logins,
and receiving these notifications speeds up the response to
potential risks.</p>
        </sec>
        <sec id="sec-3-2-2">
          <title>3.2.2. Use AWS Config for configuration management and compliance</title>
          <p>
            AWS Config allows you to evaluate, verify, and control the
configuration of resources in the AWS infrastructure [
            <xref ref-type="bibr" rid="ref11">13</xref>
            ].
It also allows you to perform actions such as change
logging, compliance assessment, configuration tracking,
and change history.
          </p>
          <p>AWS Config logs every resource configuration change,
including access and security policies. This allows you to
respond to any changes quickly and helps identify possible
security issues.</p>
          <p>Moreover, AWS Config allows you to create rules that
automatically evaluate resource configurations against
defined security policies and standards. These rules can
include checking data encryption, configuration settings,
and more.</p>
          <p>Configuration history shows all the changes to
resources over a particular time. Thus, configuration history
allows you to analyze the causes of possible configuration
problems or failures.</p>
          <p>
            Also, notifications through Amazon SNS [
            <xref ref-type="bibr" rid="ref12">14</xref>
            ] allow you
to receive information about configuration changes and
inconsistencies in real-time, allowing you to respond
quickly to potential problems.
          </p>
        </sec>
        <sec id="sec-3-2-3">
          <title>3.2.3. Using AWS GuardDuty for continuous threat monitoring</title>
          <p>
            AWS GuardDuty is a service designed to analyze event logs,
network [
            <xref ref-type="bibr" rid="ref13">15</xref>
            ] traffic, and other data sources hosted by AWS
to detect unusual or suspicious activity. In addition,
GuardDuty uses machine learning and artificial intelligence
algorithms to identify potential security threats.
          </p>
          <p>The system can analyze numerous activities, such as
unusual external traffic, suspicious intrusion attempts,
changes in security system configuration, etc., to identify
potential threats. Once such threats are detected,
GuardDuty sends alerts and event reports, allowing security
operators to respond immediately to potential problems.</p>
        </sec>
      </sec>
      <sec id="sec-3-3">
        <title>3.3. Using AWS services to protect traffic and resources</title>
        <p>
          This section will cover the use of Web Application Firewall
(WAF [
          <xref ref-type="bibr" rid="ref14">16</xref>
          ]) and Network Access Control Lists (NACL) to
filter traffic, protect against distributed denial of service
(DDoS [
          <xref ref-type="bibr" rid="ref15">17</xref>
          ]) attacks with AWS Shield, and the role of AWS
Security Hub [
          <xref ref-type="bibr" rid="ref16">18</xref>
          ] in centralized security management.
        </p>
        <sec id="sec-3-3-1">
          <title>3.3.1. Use WAF and NACL to filter traffic and improve security</title>
          <p>It would help if users used a Web Application Firewall
(WAF) to protect AWS from unfiltered traffic from
untrusted resources. WAF effectively filters traffic,
preventing attacks and prohibited access to AWS resources.</p>
          <p>However, it’s important to remember that installing a
WAF alone doesn’t guarantee complete protection. To be
more effective, you should combine WAF with other
security measures, such as user identification and
authentication, network security measures, regular security
audits, and staff training on the latest threats and security
practices. You should also keep your WAF rules up to date
and analyze traffic to identify new threats and attacks.</p>
          <p>Additional security can be provided through network
access to control lists that manage the entry and exit of site
visitors from the subnet. For example, setting up security
rules in a NACL denies access to specific ports or IP
addresses. Thus, by frequently checking and updating the
rules, you can avoid threats and have a higher level of
protection.</p>
        </sec>
        <sec id="sec-3-3-2">
          <title>3.3.2. Using AWS Shield to protect against</title>
        </sec>
        <sec id="sec-3-3-3">
          <title>DDoS attacks</title>
          <p>
            AWS Shield is an integral part of the infrastructure for
protecting [
            <xref ref-type="bibr" rid="ref17">19</xref>
            ] against DDoS attacks. AWS Shield helps
ensure the stability of applications and websites in the AWS
environment. The main focus of AWS Shield is to protect
against various types of DDoS attacks, including parser
attacks at Layer 7 and attacks at Layers 3 and 4.
          </p>
          <p>This service automatically detects attacks, responds
quickly, and mitigates their impact on systems. In addition,
AWS Shield integrates with other AWS security services,
including AWS WAF or Web Application Firewall, to
provide an advanced level of protection.</p>
          <p>In addition to the standard level of protection, there is
an extended version: AWS Shield Advanced. This paid plan
provides additional features, such as protection against
sophisticated and large-scale attacks.</p>
        </sec>
        <sec id="sec-3-3-4">
          <title>3.3.3. Use AWS Security Hub for centralized security management</title>
          <p>AWS Security Hub is a centralized service for security
control and monitoring of a customer’s AWS infrastructure.
It offers security incident detection, automated notification
processing, and integration with other security tools.</p>
          <p>AWS Security Hub processes data from many sources,
including AWS CloudTrail, AWS Config, Amazon
GuardDuty, and many others, and then provides a single
view of an AWS user account's security status.</p>
          <p>Using the AWS Security Hub, you can notice potential
security threats, such as unusual or suspicious activity,
noncompliance with security requirements, and many other
vulnerabilities. When such incidents are detected, Security
Hub can send alerts and provide recommendations on how
to resolve them.</p>
          <p>AWS Security Hub centralizes and automates AWS
security management, enabling you to identify and respond
to potential security threats quickly. This service helps
ensure high security for infrastructure and data in the AWS
cloud environment.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Security issues in Amazon Web</title>
    </sec>
    <sec id="sec-5">
      <title>Services</title>
      <p>Poor security in Amazon Web Services (AWS) is a
widespread problem that exposes companies and
enterprises to high risks. Issues that undermine the
integrity, confidentiality, and availability of data and
resources hosted in an AWS environment can mainly result
in this. Incorrect configurations are often the cause of AWS
security breaches. Configuration errors related to various
AWS services, such as security groups or Simple Storage
Service (S3) storage, can easily lead to the leakage of
confidential information or unauthorized access that was
not intended in any way. These mistakes can result from
oversight, incompetence, or failure to follow the security
rules set by AWS.</p>
      <p>Another reason is that we need more visibility into
security in the AWS environment. Monitoring all assets in
large infrastructures around the clock to capture such
incidents is difficult. Hackers can only go undetected with
adequate monitoring and logging systems once they cause
damage.</p>
    </sec>
    <sec id="sec-6">
      <title>5. Threats to AWS services</title>
      <p>This section describes the security threats associated with
using Amazon S3 and AWS. Particularly, it discusses the
issues of unlimited and long-term access to S3 buckets,
which can lead to data leakage. Undetected request events
to S3 buckets make it challenging to detect unauthorized
access.</p>
      <sec id="sec-6-1">
        <title>5.1. Unlimited and long-lasting access to S3 buckets</title>
        <p>Unlimited and prolonged access to S3 buckets can create
vulnerabilities. S3 (Simple Storage Service) allows you to
store data that is easy and secure to access. The data is
uploaded to several data centers in a selected region and
stored with backups. C3 buckets can be vulnerable if they
provide uncontrolled access to all users. Attackers can use
read/write accounts to encrypt essential documents, change
settings, or install malware. Therefore, it is crucial to
manage permissions for access to buckets. Permissions can
include editing, viewing, uploading/deleting, and list
viewing. Reviewing permissions helps reduce AWS security
risks. Using temporary access through IAM Roles is
recommended by creating particular policies with
conditions, such as IP addresses. This allows you to ensure
a secure interaction process between your application and
S3 buckets.</p>
      </sec>
      <sec id="sec-6-2">
        <title>5.2. Unprotected request events to S3</title>
      </sec>
      <sec id="sec-6-3">
        <title>Buckets</title>
        <p>S3 Buckets can be a target for data theft because they
process objects and store application files. Cyberattacks that
lead to data breaches consist of countless requests to access
the data in these buckets. Without logs of these requests,
they go undetected until it’s too late.</p>
        <p>S3 Buckets do not generate logs by default, so this
feature must be enabled manually. Once enabled, S3 Buckets
will create access logs for any request made to them, with
details such as the type of request, the resource used for the
request, and date and time stamps. Having access logs helps
you assess AWS security risks by tracking requests and
recognizing the type of requests made. Access logs enable
you to assess AWS security risks by monitoring requests
and recognizing the type of requests made.</p>
        <p>An AWS security audit would be a great approach to
identify such misconfigurations.</p>
      </sec>
      <sec id="sec-6-4">
        <title>5.3. Unfiltered traffic from unreliable sources</title>
        <p>When traffic to the AWS instances or load balancers is
unrestricted, attackers can obtain information about the
application to attack. To avoid this, you must restrict access
to instances and control traffic.</p>
        <p>DDoS attacks are possible without proper network
configuration and can quickly overwhelm the system.
Restricting traffic from suspicious sources will reduce risks
and reduce the attack surface.</p>
        <p>Security groups that function as a firewall allow only
authorized traffic. They only allow access from specific IP
addresses or ranges. A Network Access Control List (NACL)
provides an additional layer of security for subnets. Users
must ensure that the NACL does not allow access from all
IP addresses or ports and creates new restrictive rules.</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>6. Automated assessment of</title>
      <p>compliance with CIS Benchmark
controls</p>
      <sec id="sec-7-1">
        <title>6.1. Identity and access management section</title>
        <p>
          The code is implemented in Python to check and collect
information about the security of accounts in AWS Identity
and Access Management (IAM). It uses the boto3 [
          <xref ref-type="bibr" rid="ref18">20</xref>
          ] and
pytz libraries to interact with AWS services and work with
data. It checks various aspects by the CIS benchmark
controls of the Identity and Access Management section.
The results of the checks are saved in a JSON file.
        </p>
        <p>First, we need to import a few important libraries that
will be used in our script:




boto3: This is the core AWS SDK library for
Python that allows you to interact with AWS
services, specifically S3.
json: Used to work with JSON data, in which we
will store the results of the check.
subprocess: Allows you to execute system
commands through the shell, which is necessary
for some specific queries.
xml.etree.ElementTree: A standard library for
processing XML. (In our case, it is not used
directly, but may be needed for future
integrations.)
The first check we will perform is to evaluate the encryption
of data in the S3 bucket. According to the CIS Benchmark,
all buckets must be encrypted using the AES-256 algorithm.
To do this, we use the check_s3_bucket_encryption()
function. It calls the S3 API and checks whether encryption
is enabled and whether AES-256 is used.
def check_s3_bucket_encryption(bucket_name):
s3_client = boto3.client('s3')
try:</p>
        <p>encryption_response =
s3_client.get_bucket_encryption(Bucket=bucket_name)
encryption_configuration =
encryption_response.get('ServerSideEncryptionConfigurati
on', {})</p>
        <p>sse_algorithm = encryption_configuration.get('Rules',
[{}])[0]\
.get('ApplyServerSideEncryptionByDefault', {})\
.get('SSEAlgorithm', '')
return sse_algorithm in ['AES256', 'aws:kms']
except s3_client.exceptions.NoSuchBucketEncryption:
print(f"Bucket '{bucket_name}' does not have
encryption configured.")</p>
        <p>return False
except ClientError as e:</p>
        <p>print(f"Error checking S3 bucket encryption for
{bucket_name}: {e}")</p>
        <p>return False
The function makes a request to the S3 API to get the
encryption configuration of the bucket. If the bucket is
encrypted with AES-256, the function returns True.
Otherwise, it returns False. In case of an error (for example,
if encryption is not configured or the batch does not exist),
a corresponding message is displayed.</p>
        <p>
          The next step is to make sure that all traffic to the S3
bucket is transmitted over a secure connection
(SecureTransport) [
          <xref ref-type="bibr" rid="ref19">21</xref>
          ]. To do this, we use a system
command through the subprocess library that searches the
bucket policy [
          <xref ref-type="bibr" rid="ref20">22</xref>
          ] for the requirement to use HTTPS.
import boto3
import json
from botocore.exceptions import ClientError
def check_secure_transport(bucket_name):
s3 = boto3.client('s3')
try:
        </p>
        <p>response =
s3.get_bucket_policy(Bucket=bucket_name)</p>
        <p>policy = json.loads(response['Policy'])
'aws:SecureTransport'
for statement in policy.get("Statement", []):</p>
        <p>if "Condition" in statement and "Bool" in
statement["Condition"]:</p>
        <p>if "aws:SecureTransport" in
statement["Condition"]["Bool"]:</p>
        <p>if
statement["Condition"]["Bool"]["aws:SecureTransport"] ==
"true":
The aws s3api get-bucket-policy command is used to
retrieve an S3 bucket policy that is checked for the presence
of a SecureTransport key. If the policy contains a
requirement to use only a secure connection, the function
returns True, otherwise, it returns False.</p>
        <p>
          Another important recommendation is to enable
versioning of the batch and additional protection with MFA
(Multi-Factor Authentication) [
          <xref ref-type="bibr" rid="ref21">23</xref>
          ]. Versioning helps to save
all changes made to files, and MFA protects against
accidental or malicious deletions.
def check_bucket_versioning_mfa(bucket_name):
s3_client = boto3.client('s3')
try:
        </p>
        <p>versioning_response =
s3_client.get_bucket_versioning(Bucket=bucket_name)
versioning_status = versioning_response.get('Status',
'Disabled')
if versioning_status == 'Enabled':</p>
        <p>mfa_delete_status =
versioning_response.get('MFADelete', 'Disabled')</p>
        <p>return mfa_delete_status == 'Enabled'
else:</p>
        <p>return False
except ClientError as e:</p>
        <p>print(f"Error checking S3 bucket versioning and
MFADelete: {e}")</p>
        <p>return False
The function checks whether versioning is enabled for a
particular batch. If versioning is enabled, it also checks
whether MFA Delete is enabled. Returns True if both
features are enabled, or False otherwise.</p>
        <p>The last check concerns the public access blocking
settings. It is important to ensure that S3 buckets are not
publicly accessible unless it is a conscious choice. To do this,
we use the check_public_access_block() function.
import boto3
from botocore.exceptions import ClientError
def check_s3_public_access_block(bucket_name):
s3_client = boto3.client('s3')
try:</p>
        <p>access_block_response =
s3_client.get_public_access_block(Bucket=bucket_name)
config =
access_block_response.get('PublicAccessBlockConfiguratio
n', {})</p>
        <p>block_public_acls = config.get('BlockPublicAcls',
False)</p>
        <p>ignore_public_acls = config.get('IgnorePublicAcls',
False)</p>
        <p>block_public_policy = config.get('BlockPublicPolicy',
False)</p>
        <p>restrict_public_buckets =
config.get('RestrictPublicBuckets', False)</p>
        <p>return block_public_acls and ignore_public_acls and
block_public_policy and restrict_public_buckets
except ClientError as e:</p>
        <p>print(f"Error checking public access block for bucket
{bucket_name}: {e}")
return False
The function checks the Public Access Block configuration
to ensure that all policies that block public access are
enabled. Returns True if all these options are enabled.</p>
      </sec>
      <sec id="sec-7-2">
        <title>6.2. Elastic Compute Cloud (EC2) section</title>
        <p>
          This code snippet implements checking the default
encryption settings for EBS (Elastic Block Store) [
          <xref ref-type="bibr" rid="ref22">24</xref>
          ] objects
in different AWS regions.
        </p>
        <p>Using the AWS API for each EC2 region, it checks
whether the default encryption for EBS is set in each of
them. This allows you to ensure that security settings are
consistent across all regions where AWS infrastructure is
used.</p>
        <p>
          This function checks whether EBS encryption is enabled
by default in the specified region.
This code snippet implements the verification of some
security [
          <xref ref-type="bibr" rid="ref23">25</xref>
          ] aspects of the RDS (Relational Database
Service) database in AWS in different regions. It checks
whether the data storage is encrypted, whether automatic
updates of minor versions of RDS are enabled, and whether
the databases are available for public access.
        </p>
        <p>The function checks whether encryption is enabled for
each database across all AWS regions.
The following function checks whether the database is
publicly available.
import boto3
from botocore.exceptions import ClientError
def check_rds_publicly_accessible():
results = {}
try:
ec2_client = boto3.client('ec2')
regions = [region['RegionName'] for region in
ec2_client.describe_regions()['Regions']]
for region_name in regions:</p>
        <p>rds_client = boto3.client('rds',
region_name=region_name)
try:</p>
        <p>db_instances =
rds_client.describe_db_instances()['DBInstances']
for db_instance in db_instances:</p>
        <p>db_instance_identifier =
db_instance['DBInstanceIdentifier']
publicly_accessible =
db_instance.get('PubliclyAccessible', False)
if region_name not in results:</p>
        <p>results[region_name] = {}
results[region_name][db_instance_identifier]
= {"PubliclyAccessible": publicly_accessible}
except ClientError as e:</p>
        <p>print(f"Error describing DB instances in region
{region_name}: {e}")</p>
      </sec>
      <sec id="sec-7-3">
        <title>6.4. Logging section</title>
        <p>
          This code snippet implements the verification of compliance
with various security requirements and settings in the
CloudTrail service, which provides event logging in AWS.
It checks the presence and status of various components,
such as event logging, the inclusion of various types of
events, the time of the last log delivery to CloudWatch, the
status of the configuration logger, encryption and KMS [
          <xref ref-type="bibr" rid="ref24">26</xref>
          ]
key settings, KMS key rotation, and others.
        </p>
        <p>The function determines whether logging is enabled for
each CloudTrail route.</p>
        <p>import boto3
from botocore.exceptions import ClientError
def describe_trails():
cloudtrail_client = boto3.client('cloudtrail')
try:
response = cloudtrail_client.describe_trails()
return response.get('trailList', [])
except ClientError as e:
print(f"Error describing trails: {e}")
return []
if __name__ == "__main__":
trails = describe_trails()
if trails:
for trail in trails:</p>
        <p>print(trail)
else:</p>
        <p>print("No trails found.")</p>
        <p>The script checks whether CloudTrail uses event
logging on S3, which allows event auditing.</p>
        <p>import boto3
from botocore.exceptions import ClientError
def check_cloudtrail_s3_logging():
cloudtrail_client = boto3.client('cloudtrail')
try:
response = cloudtrail_client.describe_trails()
trails = response.get('trailList', [])
for trail in trails:</p>
        <p>logging_s3_enabled = trail.get('S3BucketName') is
not None
if logging_s3_enabled:</p>
        <p>return True
return False
except ClientError as e:
print(f"Error describing trails: {e}")
return False</p>
        <p>The function checks if event log encryption is enabled using
AWS KMS.</p>
      </sec>
      <sec id="sec-7-4">
        <title>6.5. Networking section</title>
        <p>
          This code snippet implements checking compliance with
various security aspects in the AWS environment. It checks
access to the network access control lists (ACLs) [
          <xref ref-type="bibr" rid="ref25">27</xref>
          ] and
security groups (SGs) [
          <xref ref-type="bibr" rid="ref26">28</xref>
          ] for the corresponding ports (22,
3389) from any IP address, checks access to security groups
for IPv6, checks for restrictions in the default offline
security group, and checks the routing tables for routing
rules for the special subnet.
        </p>
        <p>
          This feature checks whether the network ACLs in the
specified region allow unrestricted access to ports 22 (SSH)
and 3389 (RDP).
def check_network_acl_access(region):
ec2 = boto3.client('ec2', region_name=region)
try:
response = ec2.describe_network_acls()
for acl in response.get('NetworkAcls', []):
for entry in acl.get('Entries', []):
if ('PortRange' in entry and
entry.get('CidrBlock') == '0.0.0.0/0' and
entry.get('PortRange', {}).get('From') in [
          <xref ref-type="bibr" rid="ref20">22,
3389</xref>
          ] and
entry.get('RuleAction') == 'allow'):
return False
return True
except ClientError as e:
        </p>
        <p>print(f"Error describing network ACLs in region
{region}: {e}")</p>
        <p>
          return False
This feature checks to see if the default security group for a
VPC [
          <xref ref-type="bibr" rid="ref27">29</xref>
          ] in the region has open rules.
        </p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>7. Conclusions</title>
      <p>The following conclusions and results were reached from
analyzing and assessing the security of Amazon Web
Services (AWS) accounts using the CIS (Center for Internet
Security) benchmark standards.</p>
      <p>First, we reviewed the existing methods and tools for
assessing AWS account security in detail. Studying tools
such as AWS Config, AWS Security Hub, and specialized
solutions from third-party vendors allowed us to form a
holistic view of the capabilities and limitations of different
approaches to ensuring security in cloud environments.</p>
      <p>Secondly, an in-depth study of the CIS Benchmark
recommendations for AWS revealed critical security
settings for various AWS services, including Amazon S3,
Amazon EC2, Amazon RDS, and others. The
recommendations cover a wide range of settings, such as
access control, event monitoring, and logging of user
actions, allowing for comprehensive cloud resource
security.</p>
      <p>Practical tests and an assessment of AWS accounts’
compliance with CIS Benchmark security standards have
confirmed the effectiveness of implementing these
recommendations. In particular, automating the security
assessment process using tools that integrate with AWS has
significantly increased the efficiency and speed of
identifying and fixing potential vulnerabilities.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>O.</given-names>
            <surname>Vakhula</surname>
          </string-name>
          , et al.,
          <source>Security as Code Concept for Fulfilling ISO/IEC 27001: 2022 Requirements, in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>59</fpage>
          -
          <lpage>72</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <source>CIS AWS Benchmark v1.5</source>
          .0. URL: https://www.scribd.com/document/624550364/CISAmazon-Web-
          <article-title>Services-Foundations-Benchmark-v1- 5-0</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <article-title>Automated Approach to Evaluation and Security of AWS Services using Python and “CIS Benchmark”</article-title>
          , in: 2nd International Scientific Conference (
          <year>2024</year>
          )
          <fpage>141</fpage>
          -
          <lpage>142</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Shapoval</surname>
          </string-name>
          , et al.,
          <article-title>Automation of Data Management Processes in Cloud Storage</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems, CPITS</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>410</fpage>
          -
          <lpage>418</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <article-title>Amazon S3</article-title>
          . URL: https://aws.amazon.com/s3/ Amazon EC2. URL: https://aws.amazon.com/ec2/ Amazon Relational Database Service. URL: https://aws.amazon.com/rds/ Practical Aspects of Using Fully Homomorphic Encryption Systems to Protect Cloud Computing | P.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Evaluation Method of the Physical Compatibility of Equipment in a Hybrid Information Transmission Network</article-title>
          ,
          <source>Journal of Theoretical and Applied Information Technology</source>
          <volume>100</volume>
          (
          <issue>22</issue>
          ) (
          <year>2022</year>
          )
          <fpage>6635</fpage>
          -
          <lpage>6644</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Zhebka</surname>
          </string-name>
          , et al.,
          <article-title>Optimization of Machine Learning Method to Improve the Management Efficiency of Heterogeneous Telecommunication Network</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3288</volume>
          (
          <year>2022</year>
          )
          <fpage>149</fpage>
          -
          <lpage>155</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>D.</given-names>
            <surname>Shevchuk</surname>
          </string-name>
          , et al.,
          <source>Designing Secured Services for Authentication</source>
          , Authorization, and
          <article-title>Accounting of Users, in: Cybersecurity Providing in Information and Telecommunication Systems II</article-title>
          , vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>217</fpage>
          -
          <lpage>225</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [11]
          <article-title>CloudTrail</article-title>
          . URL: https://aws.amazon.com/cloudtrail/
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>AWS</given-names>
            <surname>Config</surname>
          </string-name>
          . URL: https://aws.amazon.com/config/
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>V.</given-names>
            <surname>Khoma</surname>
          </string-name>
          , et al.,
          <article-title>Comprehensive Approach for Developing an Enterprise Cloud Infrastructure</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>201</fpage>
          -
          <lpage>215</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [14]
          <article-title>Amazon Simple Notification Service</article-title>
          . URL: https://aws.amazon.com/sns/
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>R.</given-names>
            <surname>Banakh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Piskozub</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Stefinko</surname>
          </string-name>
          ,
          <article-title>External Elements of Honeypot for Wireless Network</article-title>
          , in: 13th International Conference on Modern Problems of Radio Engineering, Telecommunications and Computer Science (TCSET) (
          <year>2016</year>
          )
          <fpage>480</fpage>
          -
          <lpage>482</lpage>
          . doi:
          <volume>10</volume>
          .1109/TCSET.
          <year>2016</year>
          .
          <volume>7452093</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>AWS</given-names>
            <surname>WAF. URL</surname>
          </string-name>
          : https://aws.amazon.com/waf/
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>DDoS</given-names>
            <surname>Attack</surname>
          </string-name>
          . URL: https://aws.amazon.com/ shield/ddos-attack-protection/
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>AWS</given-names>
            <surname>Security</surname>
          </string-name>
          <article-title>Hub</article-title>
          . URL: https://aws.amazon.com/ security-hub/
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Protecting Objects of Critical Information Infrastructure from Wartime Cyber Attacks by Decentralizing the Telecommunications Network</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
          <fpage>240</fpage>
          -
          <lpage>245</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>Python</given-names>
            <surname>Bibliotheca</surname>
          </string-name>
          <article-title>Boto3</article-title>
          . URL: https://aws.amazon.com/sdk-for-python/
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>SecureTransport</given-names>
            <surname>End-User</surname>
          </string-name>
          <string-name>
            <surname>API</surname>
          </string-name>
          v1.
          <article-title>4 Documentation</article-title>
          . URL: https://www.postman.com/api-evangelist/ axway/documentation/x04b0lo/securetransport
          <article-title>-enduser-api-v1-4</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>O.</given-names>
            <surname>Deineka</surname>
          </string-name>
          , et al.,
          <article-title>Designing Data Classification and Secure Store Policy According to SOC 2 Type II</article-title>
          ,
          <source>in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>398</fpage>
          -
          <lpage>409</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Multi-Factor Authentication</surname>
          </string-name>
          (MFA). URL: https://aws.amazon.com/iam/features/mfa/
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Amazon</surname>
            <given-names>EBS</given-names>
          </string-name>
          <string-name>
            <surname>Documentation</surname>
          </string-name>
          . URL: https://docs.aws.amazon.com/ebs/
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Martseniuk</surname>
          </string-name>
          , et al.,
          <source>Automated Conformity Verification Concept for Cloud Security, in: Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>25</fpage>
          -
          <lpage>37</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [26]
          <article-title>Getting Started with AWS Key Management Service</article-title>
          . URL: https://aws.amazon.com/kms/getting-started/
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>Access</given-names>
            <surname>Control</surname>
          </string-name>
          <article-title>List (ACL) Overview</article-title>
          . URL: https://docs.aws.amazon.com/AmazonS3/latest/userg uide/acl-overview.html
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>Find</given-names>
            <surname>Security</surname>
          </string-name>
          <article-title>Group (SG) IDs, AMS</article-title>
          . URL: https://docs.aws.amazon.com/managedservices/latest /userguide/find-SGs.html
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>Amazon</given-names>
            <surname>Virtual Private</surname>
          </string-name>
          <article-title>Cloud (VPC)</article-title>
          . https://docs.aws.amazon.
          <article-title>com/toolkit-for-visualstudio/latest/user-guide/vpc-tkv</article-title>
          .html
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>