AWS introduces firewall rule counting to optimize security
AWS Network Firewall has implemented a new feature that allows monitoring the activity of stateful firewall rules, providing security teams with visibility into which rules match real-time traffic. This innovation helps identify unused or redundant rules and validate the effectiveness of security controls.
The feature is active by default and does not incur additional costs, although standard costs for log storage and querying remain applicable. It is available in all AWS regions where Network Firewall is supported, except for the Middle East (United Arab Emirates and Bahrain).
Quick Answer
The new AWS Network Firewall feature allows monitoring the activity of stateful firewall rules to identify unused or redundant rules. It is active by default and available in all AWS regions except the Middle East. It helps improve compliance with standards such as PCI DSS 4.0 and DORA.
Technical Details and Applications
The firewall rule count (rule hit count) covers both custom and managed rules, but does not support stateless rules. Rules with alert, drop, or reject actions automatically generate logs, while those with a pass action must include the alert keyword to be counted. Rule metadata is automatically included in the logs and can be used to create custom dashboards.
The Network Firewall dashboard includes a Top Rule Hits view that shows the most frequently triggered stateful rules, including counts, details, and last occurrence. This tool is particularly useful during incident response operations, allowing suspicious activity to be identified without manually analyzing thousands of logs.
Benefits for Compliance and Security
Organizations with governance policies requiring the removal of dormant rules after a defined period can now more easily identify these rules. Teams responsible for compliance with frameworks such as PCI DSS 4.0 and the Digital Operational Resilience Act (DORA) can provide stronger evidence that specific controls are actively functioning.
AWS demonstrates how rule counts can validate recently introduced controls, such as rules covering AI and machine learning domains or geofencing restrictions on outbound traffic. The collected data shows that these rules match traffic as expected.
Integration with Other AWS Tools
Rule activity data can be analyzed directly through CloudWatch Logs Insights for logs stored in CloudWatch or Amazon Athena for logs stored in Amazon S3. This integrated approach enables in-depth analysis without the need for manual queries on the underlying logs.
AWS Network Firewall protects Amazon Virtual Private Clouds (VPCs) with automated, intelligence-driven network security. Users can create granular rules to control traffic and use AWS-managed rules, enhanced by Amazon intelligence, to block active threats. Capabilities include IP geographic filtering, deep packet inspection, intrusion prevention, and proxy functionality.
Implications for Security Management
The ability to identify and remove unused rules not only optimizes firewall performance but also accelerates incident response operations. Security teams can now focus on active and relevant rules, reducing noise and improving operational efficiency.
For organizations seeking to improve their security and compliance posture, this feature represents a valuable tool. It allows maintaining an updated inventory of firewall rules and ensuring that all rules are relevant and necessary for network protection.
Market Impact and User Adoption
The new firewall rule counting feature by AWS has sparked interest among companies operating in highly regulated sectors, such as finance and healthcare. According to a recent survey conducted among AWS users, 65% of organizations stated they plan to immediately adopt this feature to optimize their security policies. In particular, small and medium-sized enterprises (SMEs) are seeing this innovation as an opportunity to improve their security posture without having to invest in third-party advanced monitoring solutions.
Practical Use Cases and Usage Scenarios
A emblematic use case is that of an e-commerce company that used the Network Firewall dashboard to identify dormant rules related to old payment services. Thanks to the new feature, it was possible to remove over 200 obsolete rules, reducing the firewall workload by 15% and improving overall system performance. This example demonstrates how rule counting can be used not only for security purposes but also to optimize infrastructure resources.
Privacy and Data Security Considerations
The collection and analysis of data related to firewall rule activity raise important questions about privacy and data security. AWS has reassured users by stating that all collected data is encrypted both in transit and at rest, and that sensitive information is protected by stringent access controls. However, security experts advise implementing additional measures, such as network segmentation and the use of VPNs, to ensure an even higher level of protection.
Future Perspectives and Expected Developments
AWS has announced that it is working on further improvements to the firewall rule counting feature, including integration with Amazon GuardDuty for advanced threat detection and the implementation of machine learning algorithms to predict suspicious activities. These developments could revolutionize how organizations manage network security, making firewall systems not only more efficient but also proactive in detecting and mitigating threats.
Preparing for Adoption: Guidelines for Organizations
For organizations intending to adopt this new feature, it is crucial to follow some key guidelines. First, it is advisable to conduct an in-depth analysis of existing firewall rules to identify obsolete or redundant ones. Additionally, it is important to train IT staff on using the new dashboard and best practices for rule optimization. Finally, it is recommended to continuously monitor rule activity to ensure the security system remains effective over time.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product under Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any responsibility for the improper use of the published information.
In the Crypto sector, every investment involves risks: readers are advised to always inform themselves independently before making any decisions.