SlideShare a Scribd company logo
1 of 36
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
MANAGED RULES
on AWS WAF
A N D R E W T H O M A S ( G M , P e r i m e t e r P r o t e c t i o n )
S U N D A R J A Y A S H E K A R ( S r . P r o d u c t M a n a g e r , A W S W A F )
SID217
November 29, 2017
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What to expect from this session
1. AWS WAF intro
2. What are we launching today?
3. Key benefits
4. Product details
5. Demo: How to get started?
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is a WAF?
Web Application Firewall
Monitors HTTP/S requests and
protects web applications from
malicious activities
Layer 7 inspection and mitigation tool
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is AWS WAF?
Web traffic filtering with
custom rules
• Rate based rules
• IP Match & Geo-IP filters
• Regex & String Match
• Size constraints
• Action: Allow/Block
Malicious request blocking
• SQLi
• XSS
Active monitoring & tuning
• CloudWatch
Metrics/Alarms
• Sampled Logs
• Count Action mode
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Where AWS WAF can help
Application
layer
Bad botsDDoS Application attacks
HTTP floods
Content scrapers
Scanners & probes
CrawlersSQL injection
Application exploits
Social engineering
AWS WAF
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Why we launched AWS WAF
“We don’t want to manage servers”
“We don’t want to pay thousands of $$”
“We want full API support for
DevOps”
Easy to deploy
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS WAF available on
Amazon CloudFront Application Load Balancer
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What do customers like about AWS WAF?
Fast incidence
response
Powerful, flexible rule
language
AffordableSecurity automation Preconfigured
templates
Easy to deploy
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
But we are not done. Challenges exist.
“I don’t want expensive Pro-Serv engagements to
write and tune my rules”
“I want to focus on writing web applications and
not security rules”
“I don’t have the resources to write rules that keep
up with the bad guys”
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Earlier today we announced…
Managed Rules on AWS WAF
with five featured sellers!
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
We are excited to present to you …
Five trusted names in security
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Featured sellers
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What are Seller Managed Rules?
• Rule sets written and managed by trusted security
sellers on the AWS Marketplace
• Deployed on AWS WAF
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Benefits
D e e p D i v e - M a n a g e d R u l e s o n A W S W A F
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Rules managed by security experts (1/5)
 Rules from trusted names
 No need for your own Threat Research teams
 Reduces the need to write your own Rules
 Focus on building solutions for your customers
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Choice of protections (2/5)
 Five sellers  Eleven products
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Auto-updates (3/5)
 Ensure protection against new and emerging threats
 Security research teams monitor, tune, and
update Rules on a regular basis
 Rule updates happen within minutes
 No extra cost for updates
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pay as you go (4/5)
 Affordable and pay as you go
 No contracts needed
 No need for ProServ engagements
 Unsubscribe anytime
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Easy to deploy (5/5)
 Easy subscription process
 Deployed on AWS WAF service
 Low maintenance
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Summarizing – Key benefits
1. Rules managed by security experts
2. Choice of protections
3. Auto-updates
4. Pay as you go
5. Easy to deploy
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Easy to get started
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Deploy in three easy steps
Find rules on AWS WAF
console or AWS
Marketplace
Click and
subscribe
Associate rules in
AWS WAF
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Demo
L e t ’ s s e e h o w t h i s i s d o n e
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Pricing
P a y a s y o u g o
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
How are Managed Rules priced?
 Two pricing dimensions:
Rule Group monthly fee ($/month)
Request fee per Million Requests ($/Million Request)
 Sellers set their own prices in AWS Marketplace
 Seller prices are in addition to normal AWS WAF charges
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Eleven new products!
A v a i l a b l e l a t e r t o d a y
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Fortinet: Product details
3. GEN+KNOWN
•Advanced ruleset
•General Attacks
•Known Exploits
•FortiGuard proprietary
protections
•Injection attacks
•URL redirects
•HTTP response
splitting
2. BAD BOTS
•Malicious Bots
•Content Scrapers
•Vulnerability
Scanners
•Specialized
protections
•Protects from known
unwanted
automated clients
1. SQLI+XSS
•Basic protection
rules
•SQL Injection
•Cross Site Scripting
•Additive to AWS
XSS and SQLi
protections
4. OWASP Rules
•SQLi/XSS +
•General Attacks +
•Known Exploits
•Discount over
purchasing separately
•FortiGuard proprietary
protections
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Imperva: Product details
• Reputation-based security
• Comment spam elimination
• Ensure search engine access
1. Managed Rules for IP
Reputation
2. Managed Rules for WordPress
Protection
• Protect your web applications built using
WordPress
• Detect and block requests targeting
WordPress vulnerabilities
• Decades of security experience and best practices – leveraging Imperva’s market-leading WAF
technology
• Ensure protection against new and emerging threats – security research team monitors, tunes,
and updates rulesets on a regular basis
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Trend Micro: Product details
2. Content Management
Servers (CMS) Rules
Protects common CMS and EMS
including WordPress, Joomla,
and Drupal from known
vulnerabilities, and to help
meet PCI DSS requirements.
Trend Micro delivers proactive
global threat intelligence
against zero-hour threats to
ensure that you are always
protected.
1. Rules for Nginx and
Apache servers
Protects web servers, including
the Apache Suite (Apache
Httpd, Apache Struts, Apache
Tomcat) and Nginx, from
known vulnerabilities and
helps meet PCI DSS
requirements.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Trustwave: Product details
2. CMS Virtual Patches1. ModSecurity Virtual
Patching
Protection against common
CMS and EMS including
WordPress, Joomla, and
Drupal from known
vulnerabilities and to help
meet PCI DSS requirements.
Select Trustwave SpiderLabs
ModSecurity. As the threat
landscape evolves,
Trustwave SpiderLabs will
continue to provide new
patches.rity virtual patches.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Alert Logic: Product details
Security expert-crafted
protection
Protect while you patch.
No tuning required.
Cover last six months of
known WordPress
exploits
1. Virtual Patches for WordPress
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Revisiting AWS WAF benefits
Fast incidence
response
Powerful rule
languageEasy to deploy
AffordableSecurity automation Preconfigured
templates
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS WAF benefits
Fast incidence
response
Powerful rule
languageEasy to deploy
AffordableSecurity automation Managed
rules
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Managed rules from security leaders
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
To learn more, visit …
https://aws.amazon.com/mp/security/WAFManagedRules/
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
THANK YOU!
Q u e s t i o n s ?

More Related Content

What's hot

AWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage GatewayAWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage GatewayAmazon Web Services Japan
 
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用Amazon Web Services Japan
 
Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...
Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...
Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...Amazon Web Services
 
AWS Control Tower
AWS Control TowerAWS Control Tower
AWS Control TowerCloudHesive
 
AWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@Edge
AWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@EdgeAWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@Edge
AWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@EdgeAmazon Web Services Japan
 
20191001 AWS Black Belt Online Seminar AWS Lake Formation
20191001 AWS Black Belt Online Seminar AWS Lake Formation 20191001 AWS Black Belt Online Seminar AWS Lake Formation
20191001 AWS Black Belt Online Seminar AWS Lake Formation Amazon Web Services Japan
 
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...Amazon Web Services
 
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要Amazon Web Services Japan
 
Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...
Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...
Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...Amazon Web Services
 
20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrail20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrailAmazon Web Services Japan
 
20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)
20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)
20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)Amazon Web Services Japan
 
20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)
20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)
20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)Amazon Web Services Japan
 
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018Amazon Web Services
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAmazon Web Services
 
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집Amazon Web Services Korea
 
20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...
20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...
20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...Amazon Web Services Japan
 
Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...
Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...
Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...Amazon Web Services
 
20190319 AWS Black Belt Online Seminar Amazon FSx for Windows Server
20190319 AWS Black Belt Online Seminar Amazon FSx for Windows Server20190319 AWS Black Belt Online Seminar Amazon FSx for Windows Server
20190319 AWS Black Belt Online Seminar Amazon FSx for Windows ServerAmazon Web Services Japan
 

What's hot (20)

AWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage GatewayAWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage Gateway
 
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
 
Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...
Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...
Introducing Managed Rules for AWS WAF (with a Customer Story) - AWS Online Te...
 
AWS Control Tower
AWS Control TowerAWS Control Tower
AWS Control Tower
 
AWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@Edge
AWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@EdgeAWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@Edge
AWS BlackBelt Online Seminar 2017 Amazon CloudFront + AWS Lambda@Edge
 
20191001 AWS Black Belt Online Seminar AWS Lake Formation
20191001 AWS Black Belt Online Seminar AWS Lake Formation 20191001 AWS Black Belt Online Seminar AWS Lake Formation
20191001 AWS Black Belt Online Seminar AWS Lake Formation
 
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
 
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
 
20170621 aws-black belt-ads-sms
20170621 aws-black belt-ads-sms20170621 aws-black belt-ads-sms
20170621 aws-black belt-ads-sms
 
Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...
Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...
Threat detection on AWS: An introduction to Amazon GuardDuty - FND216 - AWS r...
 
20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrail20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrail
 
20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)
20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)
20190521 AWS Black Belt Online Seminar Amazon Simple Email Service (Amazon SES)
 
20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)
20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)
20191029 AWS Black Belt Online Seminar Elastic Load Balancing (ELB)
 
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best Practices
 
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집
AWS 네트워크 보안을 위한 계층별 보안 구성 모범 사례 – 조이정, AWS 솔루션즈 아키텍트:: AWS 온라인 이벤트 – 클라우드 보안 특집
 
20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...
20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...
20191002 AWS Black Belt Online Seminar Amazon EC2 Auto Scaling and AWS Auto S...
 
Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...
Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...
Secure your Web Applications with AWS Web Application Firewall (WAF) and AWS ...
 
20190319 AWS Black Belt Online Seminar Amazon FSx for Windows Server
20190319 AWS Black Belt Online Seminar Amazon FSx for Windows Server20190319 AWS Black Belt Online Seminar Amazon FSx for Windows Server
20190319 AWS Black Belt Online Seminar Amazon FSx for Windows Server
 
AWS WAF - A Web App Firewall
AWS WAF - A Web App FirewallAWS WAF - A Web App Firewall
AWS WAF - A Web App Firewall
 

Similar to AWS WAF Managed Rules Launch

AWS reInvent 2017 recap - Managed Rules on AWS WAF
AWS reInvent 2017 recap - Managed Rules on AWS WAFAWS reInvent 2017 recap - Managed Rules on AWS WAF
AWS reInvent 2017 recap - Managed Rules on AWS WAFAmazon Web Services
 
Introduction to the Security Perspective of the Cloud Adoption Framework
Introduction to the Security Perspective of the Cloud Adoption FrameworkIntroduction to the Security Perspective of the Cloud Adoption Framework
Introduction to the Security Perspective of the Cloud Adoption FrameworkAmazon Web Services
 
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...Amazon Web Services
 
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloadsMSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloadsAmazon Web Services
 
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS clouduAWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS clouduVladimir Simek
 
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018Amazon Web Services
 
Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...
Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...
Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...Amazon Web Services
 
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...Amazon Web Services
 
Security & Compliance in the cloud
Security & Compliance in the cloudSecurity & Compliance in the cloud
Security & Compliance in the cloudAmazon Web Services
 
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...Amazon Web Services
 
How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWS
 How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWS How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWS
How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWSAmazon Web Services
 
Achieving Compliance and Selling to Regulated Markets on AWS
Achieving Compliance and Selling to Regulated Markets on AWSAchieving Compliance and Selling to Regulated Markets on AWS
Achieving Compliance and Selling to Regulated Markets on AWSAmazon Web Services
 
Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
 Secure Your Cloud Deployment. Learn how with AWS and Barracuda. Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
Secure Your Cloud Deployment. Learn how with AWS and Barracuda.Amazon Web Services
 
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...Amazon Web Services
 
Adding the Sec to Your DevOps Pipelines
Adding the Sec to Your DevOps PipelinesAdding the Sec to Your DevOps Pipelines
Adding the Sec to Your DevOps PipelinesAmazon Web Services
 
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...Amazon Web Services
 
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)Amazon Web Services
 
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech TalksAWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech TalksAmazon Web Services
 
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...Amazon Web Services
 

Similar to AWS WAF Managed Rules Launch (20)

AWS reInvent 2017 recap - Managed Rules on AWS WAF
AWS reInvent 2017 recap - Managed Rules on AWS WAFAWS reInvent 2017 recap - Managed Rules on AWS WAF
AWS reInvent 2017 recap - Managed Rules on AWS WAF
 
Introduction to the Security Perspective of the Cloud Adoption Framework
Introduction to the Security Perspective of the Cloud Adoption FrameworkIntroduction to the Security Perspective of the Cloud Adoption Framework
Introduction to the Security Perspective of the Cloud Adoption Framework
 
AWS Security Fundamentals
AWS Security FundamentalsAWS Security Fundamentals
AWS Security Fundamentals
 
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
Leverage AWS Marketplace to Accelerate Production-Ready Workloads - MSC204 - ...
 
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloadsMSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
 
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS clouduAWS Webinar CZSK 02 Bezpecnost v AWS cloudu
AWS Webinar CZSK 02 Bezpecnost v AWS cloudu
 
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
Security, Risk and Compliance of Your Cloud Journey - Tel Aviv Summit 2018
 
Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...
Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...
Building the Largest Repo for Serverless Compliance-as-Code - SID205 - re:Inv...
 
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
DEV325_Application Deployment Techniques for Amazon EC2 Workloads with AWS Co...
 
Security & Compliance in the cloud
Security & Compliance in the cloudSecurity & Compliance in the cloud
Security & Compliance in the cloud
 
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
 
How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWS
 How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWS How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWS
How BrightEdge Achieves End-to-End Security Visibility with Splunk and AWS
 
Achieving Compliance and Selling to Regulated Markets on AWS
Achieving Compliance and Selling to Regulated Markets on AWSAchieving Compliance and Selling to Regulated Markets on AWS
Achieving Compliance and Selling to Regulated Markets on AWS
 
Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
 Secure Your Cloud Deployment. Learn how with AWS and Barracuda. Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
Secure Your Cloud Deployment. Learn how with AWS and Barracuda.
 
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
Keys to Successfully Monitoring and Optimizing Innovative and Sophisticated C...
 
Adding the Sec to Your DevOps Pipelines
Adding the Sec to Your DevOps PipelinesAdding the Sec to Your DevOps Pipelines
Adding the Sec to Your DevOps Pipelines
 
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
Security at Scale: How Autodesk Leverages Native AWS Technologies to Provide ...
 
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
Introduction to the Security Perspective of the Cloud Adoption Framework (CAF)
 
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech TalksAWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
AWS X-Ray: Debugging Applications at Scale - AWS Online Tech Talks
 
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
Living on the Edge, It’s Safer Than You Think! Building Strong with Amazon Cl...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

AWS WAF Managed Rules Launch

  • 1. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. MANAGED RULES on AWS WAF A N D R E W T H O M A S ( G M , P e r i m e t e r P r o t e c t i o n ) S U N D A R J A Y A S H E K A R ( S r . P r o d u c t M a n a g e r , A W S W A F ) SID217 November 29, 2017
  • 2. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What to expect from this session 1. AWS WAF intro 2. What are we launching today? 3. Key benefits 4. Product details 5. Demo: How to get started?
  • 3. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is a WAF? Web Application Firewall Monitors HTTP/S requests and protects web applications from malicious activities Layer 7 inspection and mitigation tool
  • 4. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is AWS WAF? Web traffic filtering with custom rules • Rate based rules • IP Match & Geo-IP filters • Regex & String Match • Size constraints • Action: Allow/Block Malicious request blocking • SQLi • XSS Active monitoring & tuning • CloudWatch Metrics/Alarms • Sampled Logs • Count Action mode
  • 5. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Where AWS WAF can help Application layer Bad botsDDoS Application attacks HTTP floods Content scrapers Scanners & probes CrawlersSQL injection Application exploits Social engineering AWS WAF
  • 6. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Why we launched AWS WAF “We don’t want to manage servers” “We don’t want to pay thousands of $$” “We want full API support for DevOps” Easy to deploy
  • 7. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS WAF available on Amazon CloudFront Application Load Balancer
  • 8. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What do customers like about AWS WAF? Fast incidence response Powerful, flexible rule language AffordableSecurity automation Preconfigured templates Easy to deploy
  • 9. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. But we are not done. Challenges exist. “I don’t want expensive Pro-Serv engagements to write and tune my rules” “I want to focus on writing web applications and not security rules” “I don’t have the resources to write rules that keep up with the bad guys”
  • 10. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Earlier today we announced… Managed Rules on AWS WAF with five featured sellers!
  • 11. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. We are excited to present to you … Five trusted names in security
  • 12. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Featured sellers
  • 13. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What are Seller Managed Rules? • Rule sets written and managed by trusted security sellers on the AWS Marketplace • Deployed on AWS WAF
  • 14. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Benefits D e e p D i v e - M a n a g e d R u l e s o n A W S W A F
  • 15. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Rules managed by security experts (1/5)  Rules from trusted names  No need for your own Threat Research teams  Reduces the need to write your own Rules  Focus on building solutions for your customers
  • 16. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Choice of protections (2/5)  Five sellers  Eleven products
  • 17. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Auto-updates (3/5)  Ensure protection against new and emerging threats  Security research teams monitor, tune, and update Rules on a regular basis  Rule updates happen within minutes  No extra cost for updates
  • 18. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pay as you go (4/5)  Affordable and pay as you go  No contracts needed  No need for ProServ engagements  Unsubscribe anytime
  • 19. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Easy to deploy (5/5)  Easy subscription process  Deployed on AWS WAF service  Low maintenance
  • 20. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Summarizing – Key benefits 1. Rules managed by security experts 2. Choice of protections 3. Auto-updates 4. Pay as you go 5. Easy to deploy
  • 21. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Easy to get started
  • 22. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Deploy in three easy steps Find rules on AWS WAF console or AWS Marketplace Click and subscribe Associate rules in AWS WAF
  • 23. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Demo L e t ’ s s e e h o w t h i s i s d o n e
  • 24. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Pricing P a y a s y o u g o
  • 25. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. How are Managed Rules priced?  Two pricing dimensions: Rule Group monthly fee ($/month) Request fee per Million Requests ($/Million Request)  Sellers set their own prices in AWS Marketplace  Seller prices are in addition to normal AWS WAF charges
  • 26. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Eleven new products! A v a i l a b l e l a t e r t o d a y
  • 27. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Fortinet: Product details 3. GEN+KNOWN •Advanced ruleset •General Attacks •Known Exploits •FortiGuard proprietary protections •Injection attacks •URL redirects •HTTP response splitting 2. BAD BOTS •Malicious Bots •Content Scrapers •Vulnerability Scanners •Specialized protections •Protects from known unwanted automated clients 1. SQLI+XSS •Basic protection rules •SQL Injection •Cross Site Scripting •Additive to AWS XSS and SQLi protections 4. OWASP Rules •SQLi/XSS + •General Attacks + •Known Exploits •Discount over purchasing separately •FortiGuard proprietary protections
  • 28. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Imperva: Product details • Reputation-based security • Comment spam elimination • Ensure search engine access 1. Managed Rules for IP Reputation 2. Managed Rules for WordPress Protection • Protect your web applications built using WordPress • Detect and block requests targeting WordPress vulnerabilities • Decades of security experience and best practices – leveraging Imperva’s market-leading WAF technology • Ensure protection against new and emerging threats – security research team monitors, tunes, and updates rulesets on a regular basis
  • 29. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Trend Micro: Product details 2. Content Management Servers (CMS) Rules Protects common CMS and EMS including WordPress, Joomla, and Drupal from known vulnerabilities, and to help meet PCI DSS requirements. Trend Micro delivers proactive global threat intelligence against zero-hour threats to ensure that you are always protected. 1. Rules for Nginx and Apache servers Protects web servers, including the Apache Suite (Apache Httpd, Apache Struts, Apache Tomcat) and Nginx, from known vulnerabilities and helps meet PCI DSS requirements.
  • 30. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Trustwave: Product details 2. CMS Virtual Patches1. ModSecurity Virtual Patching Protection against common CMS and EMS including WordPress, Joomla, and Drupal from known vulnerabilities and to help meet PCI DSS requirements. Select Trustwave SpiderLabs ModSecurity. As the threat landscape evolves, Trustwave SpiderLabs will continue to provide new patches.rity virtual patches.
  • 31. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Alert Logic: Product details Security expert-crafted protection Protect while you patch. No tuning required. Cover last six months of known WordPress exploits 1. Virtual Patches for WordPress
  • 32. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Revisiting AWS WAF benefits Fast incidence response Powerful rule languageEasy to deploy AffordableSecurity automation Preconfigured templates
  • 33. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS WAF benefits Fast incidence response Powerful rule languageEasy to deploy AffordableSecurity automation Managed rules
  • 34. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Managed rules from security leaders
  • 35. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. To learn more, visit … https://aws.amazon.com/mp/security/WAFManagedRules/
  • 36. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. THANK YOU! Q u e s t i o n s ?