Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

29
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Nate Dye - AWS Sr. Manager, Software Development Heitor Vital - AWS Solutions Architect Thomas Wick - eVitamins Manager Nov 2016 AWS WAF Preconfigured Protections

Transcript of Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Page 1: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.

Nate Dye - AWS Sr. Manager, Software DevelopmentHeitor Vital - AWS Solutions ArchitectThomas Wick - eVitamins Manager

Nov 2016

AWS WAFPreconfigured Protections

Page 2: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

What to Expect from the Session

Introduction to AWS WAF Key Benefits Ease of Use

AWS WAF 101

Page 3: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

What is AWS WAF

Page 4: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Why AWS WAF?Application vulnerabilities

Valid users

Attackers

Web server Database

Exploit code

Page 5: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

AWS WAF

Why AWS WAF?Application vulnerabilities

Valid users

Attackers

Web server Database

Exploit code

X

Page 6: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Why AWS WAF?Content Abuse: Bots & Scrapers

Web server DatabaseValid users

Attackers

Page 7: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

AWS WAF

Why AWS WAF?Content Abuse: Bots & Scrapers

Web server DatabaseValid users

Attackers

X

Page 8: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Why AWS WAF?Application DDoS

Web server DatabaseValid users

Attackers

Page 9: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

AWS WAF

Why AWS WAF?Application DDoS

Web server DatabaseValid users

Attackers

X

Page 10: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

AWS WAFVisibility and Dashboards

Monitor security events

Page 11: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Key BenefitsCustomers like …

Scale APIs for AutomationFast Incidence Response

PreconfiguredProtection

Page 12: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Security AutomationIntegration with DevOps

AWS WAF

Logs

Threatanalysi

s

Rule updater Notificatio

n

Security Engineer

Web serverValid users

Attackers

X

Page 13: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

HTTP floodsScanners and probes

SQL injection

Bots and scrapersIP reputation lists

Cross-site scripting

Preconfigured Protection

Page 14: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

SQL injection

Bots and scrapersIP reputation lists

Cross-site scripting

Preconfigured Protection

HTTP floodsScanners and probes

Page 15: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

IP reputation lists

Preconfigured Protection IP Reputation Lists

AWS WAF

Valid users

Bad NetworksLambda

Synchronizer

X Web server

Page 16: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Preconfigured ProtectionSQL and XSS Injection Protection

AWS WAF

Valid users

Bad Networks

XSQL injection

Cross-site scripting Web server

Page 17: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

HTTP floodsScanners and probes

SQL injection

Bots and scrapersIP reputation lists

Cross-site scripting

Preconfigured Protection

Page 18: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Easy Setup

Page 19: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

AWS WAFSecurity Automations - Demo

Page 20: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Customer Story

Page 21: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

IntroductionBackground of eVitamins.com

Founded in 1999

Award winning Health & Beauty eTailer

Ships thousands of orders daily to over 85 Countries Worldwide

Localized in 15 different languages

Trusted supplier for over 600 different manufacturers

Page 22: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Stop http floods attacks

Prevent attacks and malicious activity in off-hours

Prevent known bad IP addresses from access

“Slap the wrist” of anyone getting “frisky”

Make sure Robots respect us

Stop SQL Injects, XSS Attacks from network layer in addition to application layer.

Challenges & Tasks Specific eVitamins challenges

Page 23: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Up to date IP Offenders from Spam Haus

Stop Malicious activity around the clock

Automate temporary blacklisting

Force robots to follow - play by our rules

Double up on SQL Injects, XSS Attacks, etc = less load

Post AWS WAF Security Automations After implementation

Page 24: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

True Ability to Not Miss Anything

Mitigate Damage in 90% less time (from 3 hours to 20 minutes)

Reduce IT Overhead - Less dedicated resources equals more time on other projects. Reduced security overhead

Reduce Attacks on application layer by 90%

Increased sleep = Peace of mind for our IT Team.

Results & OutcomeMeasurable results in many ways

Page 25: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

“It is without a doubt that anyone running any type of web application needs to implement this stack.”

“We’d recommend giving AWS WAF a try as the resources, insight and control you have over the network layer for a web app is second to none. The ease of use and the resources needed to have such control over everything is highly appreciated.”

RecomendationA Must Implement Stack

Page 26: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

CostThe approximate cost for running this solution with default settings* is as follows:

•$13.00 per month in fixed AWS WAF charges ($5.00 for one web ACL and $1.00 for each of the eight rules)

•$0.65 ($0.60+$0.05) per million web requests in combined, variable charges (this includes AWS WAF request charges and AWS Lambda, Amazon S3, and Amazon API Gateway charges).

*Approximate cost as of the date of publication in us-east-1. This does not include costs incurred from Amazon CloudFront or other existing resources. Prices are subject to change.

Web Requests Total Cost/Month1 million $13.65

50 million $45.50

100 million $78.00

Page 27: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Get Started

Use the Setup Wizard: https://aws.amazon.com/waf/preconfiguredrules/

Page 28: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Register for Q&A session

Registration details for an upcoming AWS WAF Q&A session coming your way soon ..

Page 29: Setup Preconfigured Protections on AWS WAF - November 2016 Webinar Series

Thank you!

Nov 2016

https://aws.amazon.com/waf/preconfiguredrules/ https://github.com/awslabs/aws-waf-security-automations

AWS Team:Nate Dye - Sr. Manager, Software DevelopmentHeitor Vital - Solutions ArchitectSundar Jayashekar – Sr. Product Manager