< ciso
brief />
Tag Banner

All news with #aws waf tag

29 articles

AWS Network Firewall adds rule hit count visibility

🔒 This post announces a new AWS Network Firewall capability—rule hit count—that provides visibility into how often stateful rules match network traffic across custom and managed rule groups. Rule hit counts increment when matches produce alert logs (alert, drop, reject), and pass rules can be tracked by adding the alert keyword. Alert logs include aws_metadata with resource ARN and signature ID, are delivered to CloudWatch Logs or S3, and drive the Top Rule Hits dashboard for monitoring and compliance validation.
read more →

AWS WAF Adds Salt Security Managed Rule Group

🔒 AWS WAF now offers the Salt Security managed rule group, available via AWS Marketplace as Salt Managed Rules for AWS WAF - AI Agent & API Security. The group provides detection and mitigation for API-focused attacks and traffic from AI agents and Model Context Protocol (MCP) endpoints without requiring customers to write custom rules. It addresses threats such as credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT anomalies while labeling MCP traffic and sensitive request attributes. Customers can subscribe and add the rule group to a web ACL directly in the AWS WAF console; pricing and versioning are managed by Salt Security through AWS Marketplace.
read more →

AWS WAF adds Miggo managed rule groups

🛡️ AWS WAF now supports two new partner-managed rule groups from Miggo Security available via AWS Marketplace: Miggo Rules for AWS WAF – High Emerging Application Threats and Miggo Rules for AWS WAF – AI/ML Application Protection. These rule groups provide continuously updated protection against actively exploited vulnerabilities, public proof-of-concept exploits, and items listed in the CISA KEV catalog without custom rule maintenance. Subscriptions can be added directly to a web ACL in the AWS WAF console with no extra configuration; Miggo manages versioning and pricing in AWS Marketplace.
read more →

AWS WAF adds pre-parse and new text transforms

🔒 Today, AWS WAF adds pre-parse text transformations for query arguments and ten new text transformations for use in any rule statement. These capabilities help normalize request content so that AWS WAF inspects requests the same way your application interprets them. New pre-parse options close HTTP parameter pollution and parser-differential evasion gaps, while new transforms include Uppercase, Trim, SHA256, and OS- and JavaScript-aware decoders.
read more →

AWS Shield Advanced adopts Anti‑DDoS WAF rule group

🛡️ In June 2025 AWS introduced the AWS WAF Anti‑DDoS managed rule group to protect application‑layer (L7) traffic. Starting July 27, 2026, Shield Advanced will add this rule group to eligible web ACLs in Count mode and eventually replace Shield’s existing L7 automatic mitigation by January 1, 2027. The rollout includes a free evaluation period, configurable sensitivities, new Challenge actions, reduced WCU usage, and a dedicated dashboard and metrics for observability.
read more →

AWS WAF dynamic label interpolation for bot signals

🛡️ AWS WAF now supports dynamic label interpolation, allowing labels applied to requests (including managed Bot Control and ATP labels) to be referenced by namespace instead of enumerating individual values. Use the ${namespace:} syntax in custom request/response headers and response bodies to forward matched labels and synthetic values (client IP, request ID, JA3/JA4) to your origin or embed them in challenge and block pages. This reduces rule maintenance, supports hundreds of evolving bot categories, enables per-device signals, and lets applications make nuanced decisions—such as challenges, redirects, or routing—based on WAF classifications.
read more →

Authenticate Legitimate AI Agent Traffic with WAF

🔒 This post introduces Web Bot Authentication (WBA) in AWS WAF Bot Control, a cryptographic, standards-based method for verifying automated agent identities using HTTP Message Signatures. It explains how asymmetric signatures and IETF drafts enable tamper-proof verification, the new WAF labels (verified, invalid, expired, unknown_bot, vendor, name, account), and how verified traffic is handled by default. The article also outlines deployment steps, supported rule group versions, monitoring guidance, and future registration APIs.
read more →

AWS WAF Protects Amazon Bedrock AgentCore Gateway

🔒 AWS announces general availability of AWS WAF protection for Amazon Bedrock AgentCore Gateway, enabling protection of agentic AI workloads from common web exploits and abuse. You can associate an AWS WAF protection pack with your AgentCore Gateway to enforce IP-based access controls, rate-based throttling, and AWS Managed Rule Groups including Bot Control. Configure protections once at the Gateway and have them applied consistently to all targets behind it.
read more →

AWS WAF launches AI traffic monetization for bots

🛡️ Today AWS WAF introduced AI traffic monetization, a Bot Control feature that enables content owners to price, meter, and accept payments from AI bots and agents accessing content and APIs. Using the x402 protocol, AWS WAF returns a machine-readable HTTP 402 response with pricing, accepted methods, and license terms; upon proof of payment it verifies at the edge and issues scoped access tokens. Publishers can set differentiated pricing by agent identity and intent, view revenue analytics in the console, and receive payouts via third-party providers such as Coinbase’s x402 Facilitator, with Stripe and MPP support coming soon.
read more →

AWS Network Firewall: URL and Domain Category Filtering

🔒 AWS Network Firewall adds URL and domain category filtering to simplify policy management by using AWS-managed categories instead of manual allowlists and blocklists. This reduces administrative overhead and keeps policies current as new domains appear. The feature supports domain category filtering via SNI without decryption and URL filtering with TLS inspection, and includes options for exceptions, Suricata rule support, and integrated logging for monitoring and compliance.
read more →

CloudFront Premium Now Offers Configurable Flat-Rate Plans

🚀Amazon CloudFront's Premium flat-rate plan now offers multiple self-service monthly usage tiers ranging from 500 million to 6 billion requests and 50 TB to 600 TB. Customers can select and change their tier in the CloudFront console with instant pricing and no commitment. All Premium features — including AWS WAF, DDoS protection, bot management, Amazon Route 53 DNS, Amazon CloudWatch Logs ingestion, serverless edge compute, and Amazon S3 storage credits — are included with no overage charges.
read more →

AWS WAF Adds Dynamic Label Interpolation for Signals

🛡️AWS WAF now supports dynamic label interpolation, letting you forward WAF classification signals to your origin and embed contextual data in responses using a single rule. Using the ${namespace:} syntax in custom request headers, response headers, and response bodies, you can pass entire label namespaces (including AWS Managed Rules, marketplace groups, or custom labels) without separate rules. Interpolation adds synthetic labels like client IP, WAF request ID, and JA3/JA4 fingerprints, adapts headers automatically, and is available in all AWS Regions at no extra cost and with no new API fields or configuration steps.
read more →

AI Traffic Analysis Dashboards for AWS WAF and Bot Control

🔍 The AWS blog announces AI Traffic Analysis dashboards for AWS WAF, adding AI-specific visibility into bot and agent activity across web ACLs. The dashboards extend WAF Bot Control detection to more than 650 named bots and provide identity, intent classification, organization breakdowns, top paths, and 14‑day temporal trends. Data is emitted to Amazon CloudWatch and is queryable via the GetTopPathStatisticsByTraffic API for custom dashboards, alerting, and automation. A reference sample demonstrates per-path monetization with CloudFront and Lambda@Edge, with usage guidance and cost warnings.
read more →

AWS Marketplace Expands Network Firewall Managed Rules

🔒 AWS Network Firewall supports expanded managed rule groups from AWS Marketplace partners, allowing rule groups to include up to 10 million domain indicators and 1 million IP addresses. Partners including Infoblox, Lumen, and ThreatSTOP are adding protections for high-risk domains, command-and-control blocking, and sanctions compliance. Managed rules from sellers like Check Point, Fortinet, Rapid7, and Trend Micro provide ready-to-deploy, continuously updated protections and are now available in additional regions.
read more →

AWS Firewall Manager Now Available in Asia Pacific (NZ)

🛡️ AWS Firewall Manager is now available in the AWS Asia Pacific (New Zealand) Region. The service centralizes policy management so cloud security administrators and site reliability engineers can protect applications while reducing the operational overhead of manually configuring and maintaining rules. With AWS Firewall Manager, customers can enforce defense-in-depth policies across AWS security services and create and manage AWS WAF security policies at scale. See the product documentation and region table for detailed availability and setup guidance.
read more →

AWS Firewall Manager Available in Asia Pacific NZ Region

🔒 AWS Firewall Manager is now available in the AWS Asia Pacific (New Zealand) Region. The service helps cloud security administrators and site reliability engineers protect applications while reducing the operational overhead of manual rule configuration and management. Customers can use Firewall Manager to create and maintain AWS WAF security policies and apply defense-in-depth controls across AWS security services and accounts.
read more →

AWS WAF AI Activity Dashboard and Expanded Bot Detection

🔍 AWS announced a new AWS WAF AI activity dashboard that centralizes visibility into AI-driven bot and agent traffic reaching applications. The update expands AWS WAF Bot Control detection to track more than 650 unique bots and agents and provides trend visualizations, most-active bot listings, path analysis, and request volumes by category and verification status. Administrators can act directly using Bot Control rules to allow verified crawlers while rate-limiting or blocking unverified agents. The dashboard is available in all AWS Regions and is included on flat-rate plans or provided at no extra cost for other WAF customers.
read more →

AWS WAF Now Available in Asia Pacific (New Zealand)

🛡️ AWS announced that AWS WAF is now available in the AWS Asia Pacific (New Zealand) Region. AWS WAF is a web application firewall that helps protect web applications from common exploits and bots by letting you block, allow, or return custom responses based on conditions such as source IP, query strings, and other request attributes. This regional expansion supports lower latency and regional data handling for New Zealand customers.
read more →

CloudWatch: Org-wide Auto-Telemetry for Six Services

🔔 Amazon CloudWatch now supports organization-wide automatic telemetry configuration for six critical AWS services: AWS CloudTrail Management Events, AWS CloudTrail Data Events, Amazon Route 53 Resource Query Logs, Amazon EKS Control Plane logs, Network Load Balancer access logs, and AWS WAF WebACL logs. Administrators can create enablement rules that automatically apply logging for both existing and new resources using AWS Config service-linked recorders. This simplifies enforcement of consistent monitoring and audit practices at scale while adhering to CloudWatch and AWS Config billing models.
read more →

Customizing AWS WAF Anti-DDoS AMR Responses for L7

🛡️This post explains how to customize AWS WAF Anti-DDoS AMR responses to Layer 7 DDoS events using labels and additional rules. It summarizes the AMR’s baseline‑and‑anomaly approach, default mitigations (a mix of Block and JavaScript Challenge), and the importance of excluding non‑challengeable paths. Three practical examples show geo‑based blocking, tightened rate limits, and adaptive capacity‑aware defenses, with JSON/IaC configuration guidance.
read more →