SlideShare una empresa de Scribd logo
1 de 35
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Sundar Jayashekar, Sr. Product Manager (AWS)
Jarrod Levitan, Chief Cloud Officer (TriNimbus)
Mike Fisher, Solutions Architect (TriNimbus)
January 30th, 2018
Managed Rules on AWS WAF
A Customer Story
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What to expect from this session
1. Service Introduction
2. Key Benefits
3. New Announcement!
4. Customer Story - TriNimbus
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is a WAF?
Web Application Firewall –
Monitors HTTP/S requests and protects
web applications from malicious
activities
Layer 7 inspection and mitigation tool
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What can we do with AWS WAF?
• Rate based rules
• IP Match & Geo-IP filters
• Regex & String Match
• Size constraints
• CloudWatch
Metrics/Alarms
• Sampled Logs
• Count Action mode
• SQLi
• XSS
• IP Blacklists
Malicious traffic
blocking
Web traffic filtering Active monitoring
& tuning
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Threats AWS WAF can help with
Application
Layer
Bad BotsDDoS OWASP type attacks
HTTP floods
Abusive users
Content scrapers
Scanners & probes
CrawlersSQL injection
XSS
Application exploits
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS WAF available on
Amazon CloudFront Application Load Balancer
(ALB)
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What do customers like about AWS WAF?
Fast Incidence
Response
Easy to deploy Affordable
Full API Support Managed platform
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
How are Customers using AWS WAF?
1. Custom Rules 3. Security Automation2. Managed Rules
You can combine all three!
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
New capabilities since June 2017
1. Rate Based Rules
2. OWASP Top 10 templates
3. Geo IP based restriction
4. RegEx Support
5. Managed Rules
6. Additional Regions for WAF/Shield
We listen to our customers and iterate quickly
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What customers asked?
“I don’t want expensive Pro-Serv engagements to
write and tune my rules”
“I want to focus on writing web applications and
not security rules”
“I don’t have the resources to write rules that keep
up with the bad guys”
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
So at re:Invent 2017 we announced…
Managed Rules on AWS WAF
with 5 Featured Sellers and 11 new Products!
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What are Seller Managed Rules?
• A set of WAF-Rules (sometimes in the 100’s) written
and managed by trusted security vendors
• Available on AWS Marketplace and the WAF Console
• Deployed on AWS WAF
• Pay-As-You-Go pricing
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
At Launch we said …
We will continue to add security vendors and
provide more Rule choices to customers ….
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
We are happy to Pre-Announce today!
Coming soon …
3 New Products!
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Featured Sellers
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
F5 Managed Rules for AWS WAF
SQLi, XSS, command
injection, No-SQLi
injection, path traversal,
and predictable resource
Apache, Apache Struts, Bash,
Elasticsearch, IIS, JBoss, JSP,
Java, Joomla, MySQL,
Node.js, PHP, PHPMyAdmin,
Perl, Ruby On Rails, and
WordPress.
Vulnerability scanners,
web scrapers, DDoS
tools, and forum spam
tools.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Key Benefits of Managed Rules
1. Rules managed by security experts
2. Choice of protections
3. Auto-updates
4. Pay as you go
5. Easy to Deploy
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Deploy in 3 easy steps
Find rules on AWS WAF
console or AWS
marketplace
Click and
subscribe
Associate rules in
AWS WAF
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
TriNimbus – Customer Story
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Born in the Cloud in 2013
• AWS Premier Consulting Partner
• Offices in Vancouver, Calgary, Toronto, Montreal and
Macedonia
• Top 50 fastest growing startups in Canada (Canadian
Business Magazine)
About TriNimbus
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Our Core Capabilities
• Expert team of Solution Architects
and DevOps Engineers
• Co-sourcing: Integrating with your
Agile teams
• 24/7 DevOps and DevSecOps
managed services
• Architecture, operations,
migrations, disaster recovery, cost
optimization, compliance
About TriNimbus
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Growing the AWS User Groups
Community Across Canada
• Organize AWS User Groups in 9
cities across Canada
• 4000+ members and growing
• Education focused presentations
by AWS customers, evangelists
and best-of-breed technology
partners
• Creating opportunities to
learn, interact, and share ideas
About TriNimbus
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
The ActiveDEMAND Story
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
About ActiveDEMAND
ActiveDEMAND is a marketing
technology company that provides
Marketing Automation to SMBs and
marketing agencies globally
• Call tracking
• Email marketing
• Social media marketing
• KPI dashboards
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
The Problem
• Suffering from intermittent DDoS attacks from a
small number of bad actors
• Attacks would quickly overwhelm their fixed
number of compute resources
• Web services would become completely
unavailable during attacks
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Original Architecture
• Amazon CloudFront in
front of static assets
only
• Elastic Load Balancer
in front of a fixed
number of Amazon
EC2 instances
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
VPC and EC2 Best Practices
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS WAF and Dynamic Content Delivery
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Why we Chose AWS WAF
• Very easy to add due to the
client already using Amazon
CloudFront
• DDoS were typically from a
small number of source IP
addresses; This made them
easy to block with IP match
conditions
• Very cost effective to
implement for a few rules
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
The Results
• ActiveDEMAND rolled out this
updated infrastructure
architecture for all new
customers
• There have been no detected
service interruptions for any
customers on this new
platform during the year it has
been in production
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Restrict ELB Access to
Amazon CloudFront IP Addresses
Going Forward
• AWS publishes IP ranges for
their services in JSON format
• Also publish updates to an
SNS topic they manage
• Subscribe to the SNS topic
with a Lambda function which
processes the JSON and
updates the ELB's security
group
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Take advantage of new AWS capabilities
• Use AWS WAF rate-based rules
instead of manually updating
blacklisted IP addresses
• Dedicated DDoS protection with AWS
Shield Advanced
• Subscribe to a managed rule group
instead of manually implementing SQL
injection and size constraint conditions
Going Forward
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Blog: Revisiting the AWS WAF
Take a look back at the all
improvements that have been
released for AWS WAF on its
journey from Minimal Viable
Product to Most Valuable Player
https://goo.gl/R37X6g
Further Reading
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
For more details on Managed Rules
https://aws.amazon.com/mp/security/WAFManagedRules/
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Thank you!

Más contenido relacionado

La actualidad más candente

Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Amazon Web Services
 

La actualidad más candente (20)

AWS solution Architect Associate study material
AWS solution Architect Associate study materialAWS solution Architect Associate study material
AWS solution Architect Associate study material
 
AWS WAF - A Web App Firewall
AWS WAF - A Web App FirewallAWS WAF - A Web App Firewall
AWS WAF - A Web App Firewall
 
AWS 클라우드 핵심 서비스로 클라우드 기반 아키텍처 빠르게 구성하기 - 문종민 솔루션즈 아키텍트, AWS :: AWS Summit Seo...
AWS 클라우드 핵심 서비스로 클라우드 기반 아키텍처 빠르게 구성하기 - 문종민 솔루션즈 아키텍트, AWS :: AWS Summit Seo...AWS 클라우드 핵심 서비스로 클라우드 기반 아키텍처 빠르게 구성하기 - 문종민 솔루션즈 아키텍트, AWS :: AWS Summit Seo...
AWS 클라우드 핵심 서비스로 클라우드 기반 아키텍처 빠르게 구성하기 - 문종민 솔루션즈 아키텍트, AWS :: AWS Summit Seo...
 
How to use AWS WAF to Mitigate OWASP Top 10 attacks - AWS Online Tech Talks
How to use AWS WAF to Mitigate OWASP Top 10 attacks - AWS Online Tech TalksHow to use AWS WAF to Mitigate OWASP Top 10 attacks - AWS Online Tech Talks
How to use AWS WAF to Mitigate OWASP Top 10 attacks - AWS Online Tech Talks
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
 
Fundamentals of AWS Security
Fundamentals of AWS SecurityFundamentals of AWS Security
Fundamentals of AWS Security
 
AWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design PatternsAWS Security Best Practices and Design Patterns
AWS Security Best Practices and Design Patterns
 
AWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro TipsAWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro Tips
 
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
 
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
AWS Landing Zone Deep Dive (ENT350-R2) - AWS re:Invent 2018
AWS Landing Zone Deep Dive (ENT350-R2) - AWS re:Invent 2018AWS Landing Zone Deep Dive (ENT350-R2) - AWS re:Invent 2018
AWS Landing Zone Deep Dive (ENT350-R2) - AWS re:Invent 2018
 
AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인
AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인
AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인
 
Access Control for the Cloud: AWS Identity and Access Management (IAM) (SEC20...
Access Control for the Cloud: AWS Identity and Access Management (IAM) (SEC20...Access Control for the Cloud: AWS Identity and Access Management (IAM) (SEC20...
Access Control for the Cloud: AWS Identity and Access Management (IAM) (SEC20...
 
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
Automating AWS security and compliance
Automating AWS security and compliance Automating AWS security and compliance
Automating AWS security and compliance
 
Introduction to AWS WAF and AWS Firewall Manager
Introduction to AWS WAF and AWS Firewall ManagerIntroduction to AWS WAF and AWS Firewall Manager
Introduction to AWS WAF and AWS Firewall Manager
 
AWS Monitoring & Logging
AWS Monitoring & LoggingAWS Monitoring & Logging
AWS Monitoring & Logging
 
VPC Design and New Capabilities for Amazon VPC
VPC Design and New Capabilities for Amazon VPCVPC Design and New Capabilities for Amazon VPC
VPC Design and New Capabilities for Amazon VPC
 

Similar a Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Tech Talks

Similar a Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Tech Talks (20)

NEW LAUNCH! Introduction to Managed Rules for AWS WAF - SID217 - re:Invent 2017
NEW LAUNCH! Introduction to Managed Rules for AWS WAF - SID217 - re:Invent 2017NEW LAUNCH! Introduction to Managed Rules for AWS WAF - SID217 - re:Invent 2017
NEW LAUNCH! Introduction to Managed Rules for AWS WAF - SID217 - re:Invent 2017
 
AWS reInvent 2017 recap - Managed Rules on AWS WAF
AWS reInvent 2017 recap - Managed Rules on AWS WAFAWS reInvent 2017 recap - Managed Rules on AWS WAF
AWS reInvent 2017 recap - Managed Rules on AWS WAF
 
Introduction to the Security Perspective of the Cloud Adoption Framework
Introduction to the Security Perspective of the Cloud Adoption FrameworkIntroduction to the Security Perspective of the Cloud Adoption Framework
Introduction to the Security Perspective of the Cloud Adoption Framework
 
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
 
Introduction to Threat Detection and Remediation on AWS
Introduction to Threat Detection and Remediation on AWSIntroduction to Threat Detection and Remediation on AWS
Introduction to Threat Detection and Remediation on AWS
 
Introduction to Threat Detection and Remediation
Introduction to Threat Detection and RemediationIntroduction to Threat Detection and Remediation
Introduction to Threat Detection and Remediation
 
GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...
GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...
GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...
 
AWS Marketplace on Reaching Enterprises
AWS Marketplace on Reaching EnterprisesAWS Marketplace on Reaching Enterprises
AWS Marketplace on Reaching Enterprises
 
Intro to Threat Detection and Remediation on AWS
Intro to Threat Detection and Remediation on AWSIntro to Threat Detection and Remediation on AWS
Intro to Threat Detection and Remediation on AWS
 
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloadsMSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
 
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
 
Managing Microsoft Workloads on AWS.pdf
Managing Microsoft Workloads on AWS.pdfManaging Microsoft Workloads on AWS.pdf
Managing Microsoft Workloads on AWS.pdf
 
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
 
AWS Security Fundamentals
AWS Security FundamentalsAWS Security Fundamentals
AWS Security Fundamentals
 
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS clouduAWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
 
GPSTEC314-GPS From Monolithic to Serverless - Why and How to Move
GPSTEC314-GPS From Monolithic to Serverless - Why and How to MoveGPSTEC314-GPS From Monolithic to Serverless - Why and How to Move
GPSTEC314-GPS From Monolithic to Serverless - Why and How to Move
 
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
 
Introduction to the Serverless Cloud
Introduction to the Serverless CloudIntroduction to the Serverless Cloud
Introduction to the Serverless Cloud
 
Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
 Secure Your Cloud Deployment. Learn how with AWS and Barracuda. Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
 
Advanced Techniques for Federation of the AWS Management Console and Command ...
Advanced Techniques for Federation of the AWS Management Console and Command ...Advanced Techniques for Federation of the AWS Management Console and Command ...
Advanced Techniques for Federation of the AWS Management Console and Command ...
 

Más de Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Más de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Tech Talks

  • 1. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Sundar Jayashekar, Sr. Product Manager (AWS) Jarrod Levitan, Chief Cloud Officer (TriNimbus) Mike Fisher, Solutions Architect (TriNimbus) January 30th, 2018 Managed Rules on AWS WAF A Customer Story
  • 2. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What to expect from this session 1. Service Introduction 2. Key Benefits 3. New Announcement! 4. Customer Story - TriNimbus
  • 3. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is a WAF? Web Application Firewall – Monitors HTTP/S requests and protects web applications from malicious activities Layer 7 inspection and mitigation tool
  • 4. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What can we do with AWS WAF? • Rate based rules • IP Match & Geo-IP filters • Regex & String Match • Size constraints • CloudWatch Metrics/Alarms • Sampled Logs • Count Action mode • SQLi • XSS • IP Blacklists Malicious traffic blocking Web traffic filtering Active monitoring & tuning
  • 5. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Threats AWS WAF can help with Application Layer Bad BotsDDoS OWASP type attacks HTTP floods Abusive users Content scrapers Scanners & probes CrawlersSQL injection XSS Application exploits
  • 6. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS WAF available on Amazon CloudFront Application Load Balancer (ALB)
  • 7. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What do customers like about AWS WAF? Fast Incidence Response Easy to deploy Affordable Full API Support Managed platform
  • 8. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. How are Customers using AWS WAF? 1. Custom Rules 3. Security Automation2. Managed Rules You can combine all three!
  • 9. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. New capabilities since June 2017 1. Rate Based Rules 2. OWASP Top 10 templates 3. Geo IP based restriction 4. RegEx Support 5. Managed Rules 6. Additional Regions for WAF/Shield We listen to our customers and iterate quickly
  • 10. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What customers asked? “I don’t want expensive Pro-Serv engagements to write and tune my rules” “I want to focus on writing web applications and not security rules” “I don’t have the resources to write rules that keep up with the bad guys”
  • 11. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. So at re:Invent 2017 we announced… Managed Rules on AWS WAF with 5 Featured Sellers and 11 new Products!
  • 12. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What are Seller Managed Rules? • A set of WAF-Rules (sometimes in the 100’s) written and managed by trusted security vendors • Available on AWS Marketplace and the WAF Console • Deployed on AWS WAF • Pay-As-You-Go pricing
  • 13. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. At Launch we said … We will continue to add security vendors and provide more Rule choices to customers ….
  • 14. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. We are happy to Pre-Announce today! Coming soon … 3 New Products!
  • 15. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Featured Sellers
  • 16. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. F5 Managed Rules for AWS WAF SQLi, XSS, command injection, No-SQLi injection, path traversal, and predictable resource Apache, Apache Struts, Bash, Elasticsearch, IIS, JBoss, JSP, Java, Joomla, MySQL, Node.js, PHP, PHPMyAdmin, Perl, Ruby On Rails, and WordPress. Vulnerability scanners, web scrapers, DDoS tools, and forum spam tools.
  • 17. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Key Benefits of Managed Rules 1. Rules managed by security experts 2. Choice of protections 3. Auto-updates 4. Pay as you go 5. Easy to Deploy
  • 18. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Deploy in 3 easy steps Find rules on AWS WAF console or AWS marketplace Click and subscribe Associate rules in AWS WAF
  • 19. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. TriNimbus – Customer Story
  • 20. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Born in the Cloud in 2013 • AWS Premier Consulting Partner • Offices in Vancouver, Calgary, Toronto, Montreal and Macedonia • Top 50 fastest growing startups in Canada (Canadian Business Magazine) About TriNimbus
  • 21. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Our Core Capabilities • Expert team of Solution Architects and DevOps Engineers • Co-sourcing: Integrating with your Agile teams • 24/7 DevOps and DevSecOps managed services • Architecture, operations, migrations, disaster recovery, cost optimization, compliance About TriNimbus
  • 22. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Growing the AWS User Groups Community Across Canada • Organize AWS User Groups in 9 cities across Canada • 4000+ members and growing • Education focused presentations by AWS customers, evangelists and best-of-breed technology partners • Creating opportunities to learn, interact, and share ideas About TriNimbus
  • 23. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. The ActiveDEMAND Story
  • 24. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. About ActiveDEMAND ActiveDEMAND is a marketing technology company that provides Marketing Automation to SMBs and marketing agencies globally • Call tracking • Email marketing • Social media marketing • KPI dashboards
  • 25. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. The Problem • Suffering from intermittent DDoS attacks from a small number of bad actors • Attacks would quickly overwhelm their fixed number of compute resources • Web services would become completely unavailable during attacks
  • 26. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Original Architecture • Amazon CloudFront in front of static assets only • Elastic Load Balancer in front of a fixed number of Amazon EC2 instances
  • 27. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VPC and EC2 Best Practices
  • 28. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS WAF and Dynamic Content Delivery
  • 29. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Why we Chose AWS WAF • Very easy to add due to the client already using Amazon CloudFront • DDoS were typically from a small number of source IP addresses; This made them easy to block with IP match conditions • Very cost effective to implement for a few rules
  • 30. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. The Results • ActiveDEMAND rolled out this updated infrastructure architecture for all new customers • There have been no detected service interruptions for any customers on this new platform during the year it has been in production
  • 31. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Restrict ELB Access to Amazon CloudFront IP Addresses Going Forward • AWS publishes IP ranges for their services in JSON format • Also publish updates to an SNS topic they manage • Subscribe to the SNS topic with a Lambda function which processes the JSON and updates the ELB's security group
  • 32. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Take advantage of new AWS capabilities • Use AWS WAF rate-based rules instead of manually updating blacklisted IP addresses • Dedicated DDoS protection with AWS Shield Advanced • Subscribe to a managed rule group instead of manually implementing SQL injection and size constraint conditions Going Forward
  • 33. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Blog: Revisiting the AWS WAF Take a look back at the all improvements that have been released for AWS WAF on its journey from Minimal Viable Product to Most Valuable Player https://goo.gl/R37X6g Further Reading
  • 34. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. For more details on Managed Rules https://aws.amazon.com/mp/security/WAFManagedRules/
  • 35. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Thank you!