Introducing AWS WAF
aws.amazon.com
aws.amazon.com
The AWS WAF is, presumably, going to give application developers and owners significantly more insight into whether their apps are getting attacked. Congratulations to the Amazon team for shipping something that has the potential to make a really big difference.
At this point, my only question is why Amazon didn't give it a strange name (like most of the other AWS products)!
Maybe they decided that "WAF" was sufficiently ambiguous. My first guess was s/firewall/framework/.
But I entirely agree; it's a good time for Amazon to look at the suite of products and make them a tad more cohesive. It can be a bit disjointed at times, especially when trying to tie multiple services together.
I wonder if the drivers are:
* Culture of always having to be seen to innovate
* (Percieved) Competition to keep launching new features to stay ahead
With that said there have been improvements; for example EFS building on top of EBS.
This, combined with the dearth of reasonably priced instances with large on-instance storage, artificially inflates our bills to the point that we're seriously considering abandoning AWS. just EBS snapshots are a full percent of our revenue.
We have essentially no idea how much many of our backups actually cost.
The price didn't triple, what happened was they dropped S3 pricing substantially but never dropped snapshot pricing, even though it's based on S3.
So, yeah, it's a CLoudfront feature.
Polishing up stuff like EC2 to make DevOps easier is great. Creating things like Lambda to make NoOps possible is better, and the two activities should not be mutually exclusive.
I think its hilarious that there's an idea of NoOps. That's like thinking you can automate software development to machine learning.
It is basically the ability to create filtering rules at a high $ per rule.
Real WAF/IDS products come with a large set of rules that are well tested and have a research team behind it.
One area I can see this being used for my purposes right now is to limit URL patterns down to IP restrictions for /admin type area's on a web app. This means this can be done A) Outside of app source code and B) without having to do any fancy reverse proxy work and setup of subdomains.
If you host your servers internally and you are big organization you have WAF's/Application Firewalls, IPS/IDS, and possibility a DB FW like imperva as well.
Does this lead to issues with deployments? yes, but it doesn't affect your code, if the WAF breaks you application 9/10 unless you use something silly like SQL queries in the URL (yes this has been seen before...) it's up to your security team to adjust the rule set during the pre-prod testing.
Being able to create rules is interesting, but doesn't make it a WAF that can compete with ModSecurity, Sucuri, Barracuda and others.
These products have serious research and testing behind their WAF products to cover a large variety of attacks (SQLi, XSS, virtual patching, etc, etc).
But it is kind nice to be able to filter traffic based on the HTTP payloads, instead of just the IPs/tcp ports like before.
CloudFront (or any CDN) is great for serving static/cached content, but for the kind of services WAF is designed to help protect, it wouldn't make a lot of sense to use CloudFront (apart from WAF) as it would just be passing the requests through to another load balancer/server.
There are probably a dozen orgs who can legitimately claim to absolutely need to support pre-SNI clients, but those shouldn't be on AWS.
Does that apply to wildcard SSL certs, too?
Does this mean the amount would increase exponentially during a DDOS attack? Could I sink my theoretical competitor into bankruptcy if I know they are an AWS WAF client simply by DDOSing them?
One call to Amazon and they'll forgive the bill. More attempts at DDOS Amazon services would likely trigger FBI investigation.
Really?
> Limits:
> Web ACLs per AWS account: 10
> Rules per AWS account: 50
> Conditions per AWS account: 50
> IP address ranges (in CIDR notation) per IP match condition: 1000
Huh? Is this really intended for production, with such low arbitrary limits?
[1] only a handful of countries use it, and they don't have English as their primary language: https://en.wikipedia.org/wiki/Decimal_mark#Examples_of_use (row 5)
edit: regarding the disagreement over "only a handful" in a reply: that map is showing the separator between units and fractional part I think, not the thousands/millions/etc grouping separator.
I don't even need to count to figure out that 80+ countries use that system :)
The convention for digit group separators varies but usually seeks to distinguish the delimiter from the decimal mark. Typically, English-speaking countries employ commas as the delimiter—10,000—and other European countries employ periods or spaces: 10.000 or 10 000. Because of the confusion that can result in international documents, the superseded SI/ISO 31-0 standard advocates the use of spaces and the International Bureau of Weights and Measures and International Union of Pure and Applied Chemistry advocate the use of a "thin space" in "groups of three".
Each Web ACL is basically a group that can contain multiple rules.
As noted, limits are easily raised with a quick email to Amazon.
Who needs WAF with basic, static rules in 2015 when applications are deployed several times a day? Mod_security in a cloud? Well. Be ready to get a dedicated person to support it to avoid false positives. And I guess it's still easy to by-pass.
Give a try to Wallarm, NAXSI, Signal Sciences.
But yep. If you're looking for WAF for NGINX, these are good options.
BTW, mod_security is now compatible with NGINX too.
Not that I'd ever want this, because CloudFront is dog slow compared to other CDNs, but yeah..
CloudFlare, Sucuri and Incapsula all come with pre-package, well-tested rules.
; )
I basically stopped having enough mental capacity for that after S3, EBS, Glacier, EC2 (which I just looked up, I spelled it E2), and maybe SES.
How on earth do people survive in that ecosystem without a glossary right by their side?
At least with this one they kept it to a name that is already reasonably well used?
You can have your tool accessible by some piece of shit CGN and web proxy. or direct over ipv6
Edit: spelling correction