AWS has rolled out a significant update for its Network Firewall service by introducing a rule hit count feature. This new addition is designed to offer security teams enhanced visibility into which stateful firewall rules are actively engaging with network traffic in real-time.
Improved Visibility for Security Teams
The introduction of the rule hit count is automatic, providing organizations with the ability to identify which firewall rules are in use and which may be misconfigured or redundant without the need for manual log reviews. As firewall policies expand, they often gather rules that may not trigger due to their placement or because they are no longer relevant.
Previously, security teams faced challenges in determining the usage of specific rules, often leading to time-consuming manual log searches. This new feature streamlines the process of firewall management, incident response, and compliance verification.
Dashboard Features and Functionality
The Top Rule Hits dashboard within the AWS console provides a detailed overview of rule activity. It displays critical information such as the signature ID, rule description, resource ARN, total hit count, and a percentage of overall hits, along with the last activation time. This allows security teams to quickly assess rule activity and determine the relevance of each rule.
Rules that create alert logs are counted, including those with actions like alert, drop, or reject. However, pass rules do not generate alerts by default and are excluded unless modified to include the alert keyword, allowing organizations to monitor allowed traffic patterns.
Applications and Benefits
The rule hit count feature integrates AWS metadata into alert logs, which helps analysts pinpoint the specific rule generating an alert using tools like Amazon CloudWatch Logs or Amazon S3. The enhanced monitoring capabilities assist security operations in efficiently investigating alerts with CloudWatch Logs Insights or Amazon Athena.
This feature also supports compliance operations by providing data for standards such as PCI DSS 4.0 and DORA. By using rule hit counts, organizations can ensure firewall rules are effective and remove unnecessary ones that consume resources without enhancing security.
Available at no extra cost for AWS Network Firewall users, except in certain Middle Eastern regions, this update underscores AWS’s commitment to improving cloud security management.
