AWS makes it easier to spot firewall rules that have gone quiet
Overview
AWS has introduced a new feature for its Network Firewall that allows security teams to track the hit count of stateful firewall rules. This capability helps identify which rules are actively matching traffic, making it easier for teams to spot unused or redundant rules. By enabling this feature by default, AWS aims to assist users in ensuring their security controls are functioning as intended. However, it's important to note that this feature currently only applies to stateful rules and does not support stateless rules. This update has no additional costs beyond standard charges for storing firewall data, making it a beneficial tool for organizations looking to enhance their network security management.
Key Takeaways
- Affected Systems: AWS Network Firewall, stateful firewall rules
- Action Required: Enable the rule hit count feature in AWS Network Firewall settings to monitor stateful rules.
- Timeline: Newly disclosed
Original Article Summary
AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability covers stateful rules in both custom and managed rule groups, while stateless rules are not supported. The feature is enabled by default and comes at no additional Network Firewall cost, although standard charges still apply for storing and … More → The post AWS makes it easier to spot firewall rules that have gone quiet appeared first on Help Net Security.
Impact
AWS Network Firewall, stateful firewall rules
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Enable the rule hit count feature in AWS Network Firewall settings to monitor stateful rules.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Update, Amazon.