SlideShare a Scribd company logo
1 of 7
AWS WAF ADDS
SUPPORT FOR
CAPTCHA
SPEAKER
Dhaval Soni
A W S A P N A M B A S S A D O R A N D
S O L U T I O N S A R C H I T E C T
• India’s first Red Hat Certified Architect in 2009
• 10x AWS Certified Solutions Architect
• 10x Red Hat Certified Architect
• ISO/IEC 27001 Lead Auditor
• Certified Payment-Card Industry Security Implementer (CPISI)
• EU Registered European Data Protection Professional (GDPR)
• Certified Cyber Security Analyst from GFSU – Department of
Forensic Sciences, Gujarat State
Confidential Information - Infostretch Corporation - For intended recipients only. ©2021 Infostretch. All rights reserved. 3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
Confidential Information - Infostretch Corporation - For intended recipients only. ©2021 Infostretch. All rights reserved. 3
3
AGENDA
• What is AWS WAF?
• Latest announcement
• How will it help you?
WHAT IS AWS WAF?
• AWS WAF is a web application firewall that lets you monitor the HTTP
and HTTPS requests that are forwarded to an Amazon CloudFront
distribution, an Amazon API Gateway REST API, an Application Load
Balancer, or an AWS AppSync GraphQL API.
• AWS WAF also lets you control access to your content.
• Based on conditions that you specify, such as the IP addresses that
requests originate from or the values of query strings, Amazon
CloudFront, Amazon API Gateway, Application Load Balancer, or AWS
AppSync responds to requests either with the requested content or with
an HTTP 403 status code (Forbidden).
AWS WAF
ANNOUNCEMENT
• AWS has announced AWS WAF Captcha to help block unwanted bot
traffic by requiring users to successfully complete challenges before their
web request are allowed to reach AWS WAF protected resources.
• Captcha is an acronym for Completely Automated Public Turing test to
tell Computers and Humans Apart and is commonly used to distinguish
between robotic and human visitors to prevent activity like web scraping,
credential stuffing, and spam.
HOW WILL IT HELP YOU?
• You can configure AWS WAF rules to require WAF Captcha challenges
to be solved for specific resources that are frequently targeted by bots
such as login, search, and form submissions.
• You can also require WAF Captcha challenges for suspicious requests
based on the rate, attributes, or labels generated from AWS Managed
Rules, such as AWS WAF Bot Control or the Amazon IP Reputation list.
• WAF Captcha includes an audio version and is designed to meet
WCAG accessibility requirements.
THANK YOU!

More Related Content

Similar to AWS WAF adds support for Captcha

Similar to AWS WAF adds support for Captcha (20)

Getting Started with AWS IoT
Getting Started with AWS IoTGetting Started with AWS IoT
Getting Started with AWS IoT
 
AWS re:Invent 2016: Workshop: Secure Your Web Application with AWS WAF and Am...
AWS re:Invent 2016: Workshop: Secure Your Web Application with AWS WAF and Am...AWS re:Invent 2016: Workshop: Secure Your Web Application with AWS WAF and Am...
AWS re:Invent 2016: Workshop: Secure Your Web Application with AWS WAF and Am...
 
AWS Summit Barcelona 2015 - Introducing Amazon API Gateway
AWS Summit Barcelona 2015 - Introducing Amazon API GatewayAWS Summit Barcelona 2015 - Introducing Amazon API Gateway
AWS Summit Barcelona 2015 - Introducing Amazon API Gateway
 
Module 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APACModule 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APAC
 
Raleigh DevDay 2017: Distributed serverless stack tracing and monitoring
Raleigh DevDay 2017: Distributed serverless stack tracing and monitoringRaleigh DevDay 2017: Distributed serverless stack tracing and monitoring
Raleigh DevDay 2017: Distributed serverless stack tracing and monitoring
 
WSO2Con EU 2015: Securing, Monitoring and Monetizing APIs
WSO2Con EU  2015: Securing, Monitoring and Monetizing APIsWSO2Con EU  2015: Securing, Monitoring and Monetizing APIs
WSO2Con EU 2015: Securing, Monitoring and Monetizing APIs
 
AWSome Day Galway Intro
AWSome Day Galway IntroAWSome Day Galway Intro
AWSome Day Galway Intro
 
WPS301-Navigating HIPAA and HITRUST_QuickStart Guide to Account Gov Strat.pdf
WPS301-Navigating HIPAA and HITRUST_QuickStart Guide to Account Gov Strat.pdfWPS301-Navigating HIPAA and HITRUST_QuickStart Guide to Account Gov Strat.pdf
WPS301-Navigating HIPAA and HITRUST_QuickStart Guide to Account Gov Strat.pdf
 
AWS re:Invent 2016: Understanding IoT Data: How to Leverage Amazon Kinesis in...
AWS re:Invent 2016: Understanding IoT Data: How to Leverage Amazon Kinesis in...AWS re:Invent 2016: Understanding IoT Data: How to Leverage Amazon Kinesis in...
AWS re:Invent 2016: Understanding IoT Data: How to Leverage Amazon Kinesis in...
 
How Retail Insights, LLC Used Alert Logic to Meet Compliance Mandates and Enh...
How Retail Insights, LLC Used Alert Logic to Meet Compliance Mandates and Enh...How Retail Insights, LLC Used Alert Logic to Meet Compliance Mandates and Enh...
How Retail Insights, LLC Used Alert Logic to Meet Compliance Mandates and Enh...
 
Networking Best Practices for Your Serverless Applications
Networking Best Practices for Your Serverless ApplicationsNetworking Best Practices for Your Serverless Applications
Networking Best Practices for Your Serverless Applications
 
Getting Started on AWS
Getting Started on AWS Getting Started on AWS
Getting Started on AWS
 
AWS SSA Webinar 11 - Getting started on AWS: Security
AWS SSA Webinar 11 - Getting started on AWS: SecurityAWS SSA Webinar 11 - Getting started on AWS: Security
AWS SSA Webinar 11 - Getting started on AWS: Security
 
AWS物聯網基礎架構及連線概覽
AWS物聯網基礎架構及連線概覽AWS物聯網基礎架構及連線概覽
AWS物聯網基礎架構及連線概覽
 
Simplify & Standardise Your Migration to AWS with a Migration Landing Zone
Simplify & Standardise Your Migration to AWS with a Migration Landing ZoneSimplify & Standardise Your Migration to AWS with a Migration Landing Zone
Simplify & Standardise Your Migration to AWS with a Migration Landing Zone
 
AWS Webcast - Splunk and Autodesk
AWS Webcast - Splunk and AutodeskAWS Webcast - Splunk and Autodesk
AWS Webcast - Splunk and Autodesk
 
Simplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing ZoneSimplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing Zone
 
Fox pong mvp architectual overview
Fox pong mvp architectual overviewFox pong mvp architectual overview
Fox pong mvp architectual overview
 
PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...
PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...
PaaS – From Code to Running Application using AWS Elastic Beanstalk (DEV323) ...
 
The Lifecycle of an AWS IoT Thing
The Lifecycle of an AWS IoT ThingThe Lifecycle of an AWS IoT Thing
The Lifecycle of an AWS IoT Thing
 

More from Dhaval Soni

More from Dhaval Soni (20)

Introducing AWS Amplify Studio
Introducing AWS Amplify StudioIntroducing AWS Amplify Studio
Introducing AWS Amplify Studio
 
AWS Shield Advanced introduces automatic application-layer DDoS mitigation
AWS Shield Advanced introduces automatic application-layer DDoS mitigationAWS Shield Advanced introduces automatic application-layer DDoS mitigation
AWS Shield Advanced introduces automatic application-layer DDoS mitigation
 
AWS announces Construct Hub general availability
AWS announces Construct Hub general availabilityAWS announces Construct Hub general availability
AWS announces Construct Hub general availability
 
Amazon Virtual Private Cloud (VPC) customers can now create IPv6-only subnets...
Amazon Virtual Private Cloud (VPC) customers can now create IPv6-only subnets...Amazon Virtual Private Cloud (VPC) customers can now create IPv6-only subnets...
Amazon Virtual Private Cloud (VPC) customers can now create IPv6-only subnets...
 
Application Load Balancer and Network Load Balancer end-to-end IPv6 support
Application Load Balancer and Network Load Balancer end-to-end IPv6 supportApplication Load Balancer and Network Load Balancer end-to-end IPv6 support
Application Load Balancer and Network Load Balancer end-to-end IPv6 support
 
Amazon SQS Announces Server-Side Encryption with Amazon SQS-managed encryptio...
Amazon SQS Announces Server-Side Encryption with Amazon SQS-managed encryptio...Amazon SQS Announces Server-Side Encryption with Amazon SQS-managed encryptio...
Amazon SQS Announces Server-Side Encryption with Amazon SQS-managed encryptio...
 
EC2 Image Builder enables sharing Amazon Machine Images (AMIs) with AWS Organ...
EC2 Image Builder enables sharing Amazon Machine Images (AMIs) with AWS Organ...EC2 Image Builder enables sharing Amazon Machine Images (AMIs) with AWS Organ...
EC2 Image Builder enables sharing Amazon Machine Images (AMIs) with AWS Organ...
 
Amazon DynamoDB now helps you meet regulatory compliance and business continu...
Amazon DynamoDB now helps you meet regulatory compliance and business continu...Amazon DynamoDB now helps you meet regulatory compliance and business continu...
Amazon DynamoDB now helps you meet regulatory compliance and business continu...
 
AWS Database Migration Service now supports Azure SQL Managed Instance as a s...
AWS Database Migration Service now supports Azure SQL Managed Instance as a s...AWS Database Migration Service now supports Azure SQL Managed Instance as a s...
AWS Database Migration Service now supports Azure SQL Managed Instance as a s...
 
Amazon EC2 Auto Scaling Now Supports Predictive Scaling with Custom Metrics
Amazon EC2 Auto Scaling Now Supports Predictive Scaling with Custom MetricsAmazon EC2 Auto Scaling Now Supports Predictive Scaling with Custom Metrics
Amazon EC2 Auto Scaling Now Supports Predictive Scaling with Custom Metrics
 
Amazon s3 storage lens metrics now available in amazon cloud watch
Amazon s3 storage lens metrics now available in amazon cloud watchAmazon s3 storage lens metrics now available in amazon cloud watch
Amazon s3 storage lens metrics now available in amazon cloud watch
 
Amazon s3 event notifications with amazon event bridge help you build advance...
Amazon s3 event notifications with amazon event bridge help you build advance...Amazon s3 event notifications with amazon event bridge help you build advance...
Amazon s3 event notifications with amazon event bridge help you build advance...
 
Introducing the aws migration and modernization competency
Introducing the aws migration and modernization competencyIntroducing the aws migration and modernization competency
Introducing the aws migration and modernization competency
 
Amazon s3 adds new s3 event notifications for s3 lifecycle, s3 intelligent ti...
Amazon s3 adds new s3 event notifications for s3 lifecycle, s3 intelligent ti...Amazon s3 adds new s3 event notifications for s3 lifecycle, s3 intelligent ti...
Amazon s3 adds new s3 event notifications for s3 lifecycle, s3 intelligent ti...
 
Amazon FSx for Lustre can now automatically update file system contents as da...
Amazon FSx for Lustre can now automatically update file system contents as da...Amazon FSx for Lustre can now automatically update file system contents as da...
Amazon FSx for Lustre can now automatically update file system contents as da...
 
Amazon S3 console now reports security warnings, errors, and suggestions from...
Amazon S3 console now reports security warnings, errors, and suggestions from...Amazon S3 console now reports security warnings, errors, and suggestions from...
Amazon S3 console now reports security warnings, errors, and suggestions from...
 
Amazon FSx for Lustre now supports automatically exporting file updates to Am...
Amazon FSx for Lustre now supports automatically exporting file updates to Am...Amazon FSx for Lustre now supports automatically exporting file updates to Am...
Amazon FSx for Lustre now supports automatically exporting file updates to Am...
 
Announcing the next generation of amazon f sx for lustre file systems
Announcing the next generation of amazon f sx for lustre file systemsAnnouncing the next generation of amazon f sx for lustre file systems
Announcing the next generation of amazon f sx for lustre file systems
 
Amazon Pinpoint launches in-app messaging as a new communications channel
Amazon Pinpoint launches in-app messaging as a new communications channelAmazon Pinpoint launches in-app messaging as a new communications channel
Amazon Pinpoint launches in-app messaging as a new communications channel
 
Amazon FSx for Lustre now supports linking multiple Amazon S3 buckets to a fi...
Amazon FSx for Lustre now supports linking multiple Amazon S3 buckets to a fi...Amazon FSx for Lustre now supports linking multiple Amazon S3 buckets to a fi...
Amazon FSx for Lustre now supports linking multiple Amazon S3 buckets to a fi...
 

Recently uploaded

Recently uploaded (20)

Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 

AWS WAF adds support for Captcha

  • 1. AWS WAF ADDS SUPPORT FOR CAPTCHA
  • 2. SPEAKER Dhaval Soni A W S A P N A M B A S S A D O R A N D S O L U T I O N S A R C H I T E C T • India’s first Red Hat Certified Architect in 2009 • 10x AWS Certified Solutions Architect • 10x Red Hat Certified Architect • ISO/IEC 27001 Lead Auditor • Certified Payment-Card Industry Security Implementer (CPISI) • EU Registered European Data Protection Professional (GDPR) • Certified Cyber Security Analyst from GFSU – Department of Forensic Sciences, Gujarat State
  • 3. Confidential Information - Infostretch Corporation - For intended recipients only. ©2021 Infostretch. All rights reserved. 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 Confidential Information - Infostretch Corporation - For intended recipients only. ©2021 Infostretch. All rights reserved. 3 3 AGENDA • What is AWS WAF? • Latest announcement • How will it help you?
  • 4. WHAT IS AWS WAF? • AWS WAF is a web application firewall that lets you monitor the HTTP and HTTPS requests that are forwarded to an Amazon CloudFront distribution, an Amazon API Gateway REST API, an Application Load Balancer, or an AWS AppSync GraphQL API. • AWS WAF also lets you control access to your content. • Based on conditions that you specify, such as the IP addresses that requests originate from or the values of query strings, Amazon CloudFront, Amazon API Gateway, Application Load Balancer, or AWS AppSync responds to requests either with the requested content or with an HTTP 403 status code (Forbidden). AWS WAF
  • 5. ANNOUNCEMENT • AWS has announced AWS WAF Captcha to help block unwanted bot traffic by requiring users to successfully complete challenges before their web request are allowed to reach AWS WAF protected resources. • Captcha is an acronym for Completely Automated Public Turing test to tell Computers and Humans Apart and is commonly used to distinguish between robotic and human visitors to prevent activity like web scraping, credential stuffing, and spam.
  • 6. HOW WILL IT HELP YOU? • You can configure AWS WAF rules to require WAF Captcha challenges to be solved for specific resources that are frequently targeted by bots such as login, search, and form submissions. • You can also require WAF Captcha challenges for suspicious requests based on the rate, attributes, or labels generated from AWS Managed Rules, such as AWS WAF Bot Control or the Amazon IP Reputation list. • WAF Captcha includes an audio version and is designed to meet WCAG accessibility requirements.

Editor's Notes

  1. RYM SLIDE​​ ​​ *Hello and good morning, everyone. We will begin the webinar here in a few minutes, still seeing some people signing on at this time. In the meantime, I would like to ensure we could hear our speakers, Shabir, Kinjan, Chintan, can you say a quick hello? --- Perfect, thank you. Okay, stay tuned, we’ll begin here shortly.  ​​  ​​ *Hi all, we’ll begin the presentation in about a minute. Thank you.  ​​ ​​ *Hello and welcome to our webinar, ”Secure Real Time Monitoring & Analysis for IoT Product Engineering". ​​ My name is Rym Badri and I will be your host today. ​​
  2. RYM SLIDE​ ​ Today’s presenter are: ​ ​ Shabir ​​Rupani, Sr. Partner Solutions Architect at AWS, Kinjan Shah, Director of IoT and MedTech Practice at Infostretch and Chintan Prajapati, Solutions Architect focused on IoT and MedTech at Infostretch. Shabir is a Senior Partner Solutions Architect at AWS. He has a background in Application Infrastructure Architecture with a core focus on migrating and modernizing applications for the cloud. Currently, at AWS he is focused on helping AWS Partner Network (APN) partners build and develop their AWS Practice, and innovate on the AWS platform to deliver the best possible outcomes for their customers. Kinjan is our Director of the IoT and MedTech Engineering Practice here at Infostretch, He has led the creation of various frameworks that enable MedTech companies to shorten their product development cycle. He has more than 22 years of experience in IoT solutions and MedTech Engineering along with enterprise mobile applications, embedded systems, and enterprise solutions. He has worked with both startups and Fortune 500 companies across different industries including Healthcare, Medical Devices, Financial (Mobile and Digital Payments) and Industrial Automation (M2M and IoT solutions). Finally, As Solutions Architect part of the IoT and MedTech Practice at Infostretch, Chintan is involved in building Accelerators & Frameworks to expedite delivery of IoT & Mobility Solutions. Chintan is involved in Project seeding activities and Solution Development for customer on their Consumer IoT, Industrial IoT, Internet of Medical Things (IOMT), Mobility & Cloud initiatives.
  3. KINJAN SLIDE
  4. RYM SLIDE I believe that’s all the questions we are able to answer at this time. ​ Many thanks to our speakers, Ketan, Shabir and Deven and Thank you everyone for joining us today! ​ Be sure to check out and subscribe to DTV – A digital transformation channel that brings in industry experts including Intermiles! ​ You will receive an email in the next 24 hours with the slide presentation and link to the webcast replay. ​ ​ If you have any questions, please contact us at info@infostretch.com or you can reach out to the presenters directly. ​ ​ Thank you, all. Enjoy the rest of your day!​ ​ <END PRESENTATION>​ ​