to the instance and will be made available to your application via the Amazon EC2 Instance Metadata Service. The
Metadata Service will make new temporary security credentials available prior to the expiration of the current active
credentials, so that valid credentials are always available on the instance. In addition, the temporary security credentials
are automatically rotated multiple times per day, providing enhanced security. You can further control access to Auto
Scaling by creating users under your AWS Account using AWS IAM, and controlling what Auto Scaling APIs these users
have permission to call. More information about using roles when launching instances is available in the Amazon EC2
User Guide on the AWS website:

Amazon Web Services
–
Overview of Security Processes
November 2014
Page 25 of 77
Networking Services
Amazon Web Services provides a range of networking services that enable you to create a logically isolated network that
you define, establish a private network connection to the AWS cloud, use a highly available and scalable DNS service and
deliver content to your end users with low latency at high data transfer speeds with a content delivery web service.
Amazon Elastic Load Balancing Security
Amazon Elastic Load Balancing is used to manage traffic on a fleet of Amazon EC2 instances, distributing traffic to
instances across all availability zones within a region. Elastic Load Balancing has all the advantages of an on-premises
load balancer, plus several security benefits:
Takes over the encryption and decryption work from the Amazon EC2 instances and manages it centrally on the
load balancer
Offers clients a single point of contact, and can also serve as the first line of defense against attacks on your
network
When used in an Amazon VPC, supports creation and management of security groups associated with your
Elastic Load Balancing to provide additional networking and security options
Supports end-to-end traffic encryption using TLS (previously SSL) on those networks that use secure HTTP
(HTTPS) connections. When TLS is used, the TLS server certificate used to terminate client connections can be
managed centrally on the load balancer, rather than on every individual instance.
HTTPS/TLS uses a long-term secret key to generate a short-term session key to be used between the server and the
browser to create the ciphered (encrypted) message. Amazon Elastic Load Balancing configures your load balancer with
a pre-defined cipher set that is used for TLS negotiation when a connection is established between a client and your load
balancer. The pre-defined cipher set provides compatibility with a broad range of clients and uses strong cryptographic
algorithms. However, some customers may have requirements for allowing only specific ciphers and protocols (such as
PCI, SOX, etc.) from clients to ensure that standards are met. In these cases, Amazon Elastic Load Balancing provides
options for selecting different configurations for TLS protocols and ciphers. You can choose to enable or disable the
ciphers depending on your specific requirements.


You've reached the end of your free preview.
Want to read all 77 pages?
- Fall '19
- Amazon Web Services, AWS, Amazon Elastic Compute Cloud