Adam Novotny's session on Optimizing Edge Security and Performance with CloudFront and WAF from AWS Cloud Day Prague 2025 is now live on our YouTube channel.
📹 youtu.be/Z7oCxHdCwuU
Check it out and let us know if you want to explore this topic further.
#Stormit #StormitCloud #AWS
          📹 youtu.be/Z7oCxHdCwuU
Check it out and let us know if you want to explore this topic further.
#Stormit #StormitCloud #AWS
            October 27, 2025 at 9:51 AM
            
              
              Everybody can reply
            
          
        
          
          
          1 likes
          
        
        
      
    Some kind of API and static asset serving will have maybe another $1-2k/mo of costs, maybe add another $1-2k for a Web-application-firewall via Cloudflare or AWS WAF since you'll likely deal with DDOSes. Chat would be a whole thing too, maybe another $500-$1,500/mo for hosting there.
          
            September 19, 2025 at 11:10 PM
            
              
              Everybody can reply
            
          
        
          
          
          12 likes
          
        
        
      
    Do they make it clear what changed in the docs? No.
What actually changed was that AWS WAF Bot Control now supports bot verification for some bots in the following categories:
- CategoryAI
- SignalAutomatedBrowser
- SignalKnownBotDataCenter
- SignalNonBrowserUserAgent
4/14
          What actually changed was that AWS WAF Bot Control now supports bot verification for some bots in the following categories:
- CategoryAI
- SignalAutomatedBrowser
- SignalKnownBotDataCenter
- SignalNonBrowserUserAgent
4/14
            September 14, 2024 at 5:20 PM
            
              
              Everybody can reply
            
          
        AWS WAF enhances integration with Service Quotas
AWS WAF enhances Service Quotas capabilities, enabling organizations to proactively monitor and manage quotas for their cloud deployments.
 
AWS WAF is a web application firewall that helps protect your web applic...
#AWS #AwsGovcloudUs #AwsWaf
        
          AWS WAF enhances Service Quotas capabilities, enabling organizations to proactively monitor and manage quotas for their cloud deployments.
AWS WAF is a web application firewall that helps protect your web applic...
#AWS #AwsGovcloudUs #AwsWaf
AWS WAF enhances integration with Service Quotas
            AWS WAF enhances Service Quotas capabilities, enabling organizations to proactively monitor and manage quotas for their cloud deployments.
 
 AWS WAF is a web application firewall that helps protect your web applications or APIs against common web exploits and bots that may affect availability, compromise security, or consume excessive resources. By leveraging AWS Service Quotas, you can quickly understand your applied service quota values for these WAF resources and request increases when needed. This enhanced integration brings three key benefits. First, you can now monitor the current utilization of your account-level quotas for WAF resources such as web ACLs, rule groups, and IP sets in the Service Quotas console. Second, certain service quota increase requests will now be auto-approved, enabling customers to access higher quotas faster. For example, smaller increases are usually automatically approved while larger requests are submitted to AWS Support. Lastly, you can now create https://aws.amazon.com/cloudwatch/ alarms to notify you when your utilization of a given quota exceeds a configurable threshold. This enables you to better adapt your utilization based on your applied quota values and automate your quota increase requests.
 
 You can access https://us-east-1.console.aws.amazon.com/servicequotas/home/services/s3/quotas through the AWS console, https://docs.aws.amazon.com/servicequotas/2019-06-24/apireference/Welcome.html, and CLI. Integration with AWS Service Quotas is available in all https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ where AWS WAF is offered. You can learn more about AWS WAF by visiting https://docs.aws.amazon.com/waf/latest/developerguide/waf-chapter.html.
  
          
            
            aws.amazon.com
          
        
          
            February 24, 2025 at 11:05 PM
            
              
              Everybody can reply
            
          
        ✍️ New blog post by Keyur Modi
Leveraging AWS WAF to Defend an Insecure Web App
#aws #cloud #security #terraform
        
            Leveraging AWS WAF to Defend an Insecure Web App
#aws #cloud #security #terraform
Leveraging AWS WAF to Defend an Insecure Web App
            This blog is based on the hands-on lab Leveraging AWS WAF to Defend an Insecure Web App from QA's...
          
            
            dev.to
          
        
          
            April 2, 2025 at 5:24 AM
            
              
              Everybody can reply
            
          
        
          1 reposts
          
          1 likes
          
        
        
      
    AWS WAF is now available in AWS Asia Pacific (Malaysia) Region
        
            AWS WAF is now available in AWS Asia Pacific (Malaysia) Region
            Starting today, you can use AWS WAF in the AWS Asia Pacific (Malaysia) Region.
  AWS WAF is a web application firewall that helps you protect your web application resources against common web exploits and bots that can affect availability, compromise security, or consume excessive resources. You can protect the following resource types: Amazon CloudFront distributions, Amazon API Gateway REST APIs, Application Load Balancer, AWS AppSync GraphQL API, AWS App Runner, AWS Verified Access, and Amazon Cognito user pools.
  To see the full list of regions where AWS WAF is currently available, visit the AWS Region Table. Please note that only core AWS WAF features like AWS Managed Rules and rules are currently available in these new regions. For more information about the service, visit the AWS WAF page. AWS WAF pricing may vary between regions. For more information about pricing, visit the AWS WAF Pricing page.
          
            
            aws.amazon.com
          
        
          
            November 2, 2024 at 12:25 PM
            
              
              Everybody can reply
            
          
        medium.com/@allankp/bui...
The reality of hosting apps on the internet today is that you will start getting hammered by unexpected IP addresses right away. There are many approaches to handle this but one easy one to cover a lot of it on AWS is using their Web Application Firewall (WAF). (1️⃣/3️⃣)
🧵
        
            The reality of hosting apps on the internet today is that you will start getting hammered by unexpected IP addresses right away. There are many approaches to handle this but one easy one to cover a lot of it on AWS is using their Web Application Firewall (WAF). (1️⃣/3️⃣)
🧵
Building a Cost‑Effective AWS WAF Logging Pipeline with Terraform, CloudWatch, and S3
            Blocking malicious traffic with AWS WAF is only half the story — you also need clear, reliable logs so security and platform teams can…
          
            
            medium.com
          
        
          
            April 23, 2025 at 1:15 AM
            
              
              Everybody can reply
            
          
        Using AWS WAF Efficiently To Secure Your CDN, Load Balancers, and API Servers feeds.dzone.com/link...
        
            AWS WAF: Secure CDN, Load Balancers, API Servers - DZone
            When securing your cloud architecture, performance and efficiency are incredibly important. Learn more about how to strike a fine balance.
          
            
            feeds.dzone.com
          
        
          
            October 1, 2024 at 10:48 PM
            
              
              Everybody can reply
            
          
        "TerraStack: Build Bulletproof AWS Static Sites" by Victor Omolayo
#websitehosting #infrastructure-as-code #cloudfront #waf #route53
        
            #websitehosting #infrastructure-as-code #cloudfront #waf #route53
TerraStack: Build Bulletproof AWS Static Sites
            Deploy secure static websites on AWS with this Terraform toolkit. Automates S3, CloudFront, WAF, and DNS setup while optimizing costs and maintaining best practices.
          
            
            community.aws
          
        
          
            January 18, 2025 at 11:30 AM
            
              
              Everybody can reply
            
          
        Comprehensive Guide to AWS WAF — Protecting Web Applications
        
            Comprehensive Guide to AWS WAF — Protecting Web Applications
            The “Comprehensive Guide to AWS WAF” is course designed to provide participants with a thorough understanding of AWS Web Application…
          
            
            infosecwriteups.com
          
        
          
            April 5, 2024 at 2:29 AM
            
              
              Everybody can reply
            
          
        Enhancing Request Handling with Custom Headers in AWS WAF
https://socprime.com/blog/enhancing-request-handling-with-custom-headers-in-aws-waf/
#cybersecurity #infosec #security #hacker
          https://socprime.com/blog/enhancing-request-handling-with-custom-headers-in-aws-waf/
#cybersecurity #infosec #security #hacker
            December 6, 2024 at 12:21 PM
            
              
              Everybody can reply
            
          
        Nice! AWS Amplify (finally) got WAF support, allowing you to protect your websites against malicious actors or only for trusted actors.
        
            AWS Amplify Hosting Adds Web Application Firewall Protection – Public Preview
            AWS Amplify Hosting introduces Web Application Firewall protection in public preview, enabling developers to secure web applications with IP blocking, geo-...
          
            
            buff.ly
          
        
          
            December 18, 2024 at 5:55 PM
            
              
              Everybody can reply
            
          
        
          3 reposts
          
          7 likes
          
        
        
      
    ✍️ New blog post by nishikawaakira
Unlocking the Potential of Amazon CloudFront with VPC Origins: Overcoming WAF Bypass Challenges
#aws #security #waf
        
            Unlocking the Potential of Amazon CloudFront with VPC Origins: Overcoming WAF Bypass Challenges
#aws #security #waf
Unlocking the Potential of Amazon CloudFront with VPC Origins: Overcoming WAF Bypass Challenges
            Amazon CloudFront VPC Origins was announced on November 20, 2024. Have you had a chance to try it...
          
            
            dev.to
          
        
          
            December 28, 2024 at 3:49 AM
            
              
              Everybody can reply
            
          
        
          
          
          1 likes
          
        
        
      
    AWS WAF announces general availability of Resource-level DDoS protection for Application Load Balancers (ALB) #cloud
        
          AWS WAF announces general availability of Resource-level DDoS protection for Application Load Balancers (ALB)
            
AWS WAF announces general availability of Resource-level DDoS protection for Application Load Balancers (ALB)
0 views
Eyal Estrin
unread,
10:46 PM (27 minutes ago)
to
https://aws.amazon.com/about-aws/whats-new/2025/06/aws-waf-general-availability-resource-level-ddos-protection-alb/
https://docs.aws.amazon.com/waf/latest/developerguide/waf-anti-ddos-alb.html
https://docs.aws.amazon.com/waf/latest/developerguide/aws-managed-rule-groups-anti-ddos.html
https://docs.aws.amazon.com/waf/latest/developerguide/aws-managed-rule-groups-ip-rep.html
Eyal Estrin
CISSP, CCSP, CISM, CISA, CDPSE, CCSK
Blog: https://security-24-7.com | Books: https://amzn.to/42Xai9A | https://amzn.to/3Sggbtv
Twitter: @eyalestrin | Bluesky: @eyalestrin.bsky.social
Reply all
Reply to author
Forward
          
            
            groups.google.com
          
        
          
            June 27, 2025 at 6:12 AM
            
              
              Everybody can reply
            
          
        Amazon Q Business enables secure, unauthenticated AI-powered web experiences for public sector agencies by leveraging AWS Amplify, AWS WAF, and comprehensive security controls.
        
            Securing Amazon Q Business Web Experiences with AWS Amplify and AWS WAF
            Amazon Q Business enables secure, unauthenticated AI-powered web experiences for public sector agencies by leveraging AWS Amplify, AWS WAF, and comprehensive security controls.
          
            
            aws-news.com
          
        
          
            September 15, 2025 at 4:08 PM
            
              
              Everybody can reply
            
          
        AWS WAF for DevOps Engineers: Guide to Web Application Security in AWS
As a DevOps engineer, you’re constantly looking for ways to balance rapid software delivery with rock-solid security. One crucial tool at your disposal is a Web Application Firewall (WAF). In the AWS ecosystem, that solution is…
        
          As a DevOps engineer, you’re constantly looking for ways to balance rapid software delivery with rock-solid security. One crucial tool at your disposal is a Web Application Firewall (WAF). In the AWS ecosystem, that solution is…
AWS WAF for DevOps Engineers: Guide to Web Application Security in AWS
            As a DevOps engineer, you’re constantly looking for ways to balance rapid software delivery with rock-solid security. One crucial tool at your disposal is a Web Application Firewall (WAF). In the AWS ecosystem, that solution is AWS WAF—a service designed to protect your applications from common web exploits while giving you the flexibility and integrations essential to a modern DevOps workflow.
          
            
            www.fdaytalk.com
          
        
          
            January 6, 2025 at 5:15 AM
            
              
              Everybody can reply
            
          
        
          1 reposts
          
          2 likes
          
        
        
      
    AWS WAF enhances Data Protection and logging experience
https://aws.amazon.com/about-aws/whats-new/2025/02/aws-waf-data-protection-logging-experience
          https://aws.amazon.com/about-aws/whats-new/2025/02/aws-waf-data-protection-logging-experience
            February 18, 2025 at 8:12 PM
            
              
              Everybody can reply
            
          
        ✍️ New blog post by Fady Nabil
Discovering the Latest Features of AWS CloudFront: Enhancing Performance and Security
#aws #cloudfront #waf #security
        
            Discovering the Latest Features of AWS CloudFront: Enhancing Performance and Security
#aws #cloudfront #waf #security
Discovering the Latest Features of AWS CloudFront: Enhancing Performance and Security
            🚀 Amazon CloudFront now supports VPC Origins, allowing private network resources in your AWS account...
          
            
            dev.to
          
        
          
            November 23, 2024 at 7:09 PM
            
              
              Everybody can reply
            
          
        
          
          
          2 likes
          
        
        
      
    AWS WAF adds JA4 fingerprinting and aggregation on JA3 and JA4 fingerprints for rate-based rules
AWS WAF adds JA4 fingerprinting to allow/block clients. JA4 and JA3 can be used as aggregation keys in rate-based rules. Enhances threat detection and mitigation. Available in most regions.
          AWS WAF adds JA4 fingerprinting to allow/block clients. JA4 and JA3 can be used as aggregation keys in rate-based rules. Enhances threat detection and mitigation. Available in most regions.
            March 6, 2025 at 9:09 PM
            
              
              Everybody can reply
            
          
        AWS introduces AntiDDoS AMR, a new AWS WAF feature that provides advanced Layer 7 DDoS protection with automatic traffic profiling, rapid detection, and customizable mitigation actions for web applications.
        
            Introducing new application layer (L7) DDoS protections for AWS WAF and AWS Shield Advanced customers
            AWS introduces AntiDDoS AMR, a new AWS WAF feature that provides advanced Layer 7 DDoS protection with automatic traffic profiling, rapid detection, and customizable mitigation actions for web applications.
          
            
            aws-news.com
          
        
          
            June 12, 2025 at 7:01 PM
            
              
              Everybody can reply
            
          
        インターネットからの野良リクエストがどれぐらい AWS WAF のマネージドルールに一致するのか確かめてみた - 電通総研 テックブログ
        
            インターネットからの野良リクエストがどれぐらい AWS WAF のマネージドルールに一致するのか確かめてみた - 電通総研 テックブログ
            https://tech.dentsusoken.com/entry/waf_managed_rules_match_experiment
          
            
            tech.dentsusoken.com
          
        
          
            May 14, 2024 at 1:00 AM
            
              
              Everybody can reply
            
          
        Amazon Cognito introduces AWS WAF support for Managed Login
Amazon Cognito introduces AWS Web Application Firewall (AWS WAF) support in Cognito Managed Login. This new capability allows customers to protect their Managed Login endpoints configured in Cognito...
#AWS #AmazonCognito #AwsGovcloudUs
        
          Amazon Cognito introduces AWS Web Application Firewall (AWS WAF) support in Cognito Managed Login. This new capability allows customers to protect their Managed Login endpoints configured in Cognito...
#AWS #AmazonCognito #AwsGovcloudUs
Amazon Cognito introduces AWS WAF support for Managed Login
            Amazon Cognito introduces AWS Web Application Firewall (AWS WAF) support in Cognito Managed Login. This new capability allows customers to protect their Managed Login endpoints configured in Cognito user pools from unwanted or malicious requests and web-based attacks. Managed Login, a fully-managed, hosted sign-in and sign-up experience that customers can personalize to align with their company or application branding, now offers an additional layer of protection against threat vectors through integration with AWS WAF web access control lists (web ACLs).
 
 This integration provides customers with powerful new capabilities to safeguard their applications against malicious attacks. With AWS WAF support, you can now define rules that enforce rate limits, gain visibility into web traffic to your applications, and allow or block traffic to Cognito Managed Login based on your specific business or security requirements. Additionally, the AWS WAF integration enables you to optimize costs by controlling bot traffic to your Cognito user pools.
 
 Managed Login and WAF support in Managed Login are offered as part of the Cognito Essentials and Plus tiers and are available in all AWS Regions where Amazon Cognito is available. Please note that AWS WAF charges apply for the inspection of user pool requests. For more information, see https://aws.amazon.com/waf/pricing/. To learn more, see Using https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-waf.html, and to get started, visit the https://console.aws.amazon.com/cognito/home.
  
          
            
            aws.amazon.com
          
        
          
            June 26, 2025 at 11:05 PM
            
              
              Everybody can reply
            
          
        
          
          
          1 likes
          
        
        
      
    AWS WAF now offers resource-level DDoS protection for Application Load Balancers, enabling rapid detection and mitigation of attacks through an integrated on-host agent with IP reputation rules.
        
            AWS WAF announces general availability of Resource-level DDoS protection for Application Load Balancers (ALB)
            AWS WAF now offers resource-level DDoS protection for Application Load Balancers, enabling rapid detection and mitigation of attacks through an integrated on-host agent with IP reputation rules.
          
            
            aws-news.com
          
        
          
            June 26, 2025 at 9:34 PM
            
              
              Everybody can reply
            
          
        
          
          
          1 likes
          
        
        
      
     
        