| name | securing-api-gateway-with-aws-waf |
| description | Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security effectiveness. . Use when working with securing api gateway with aws waf. |
| domain | cybersecurity |
| tags | ["cloud-security","aws","waf","api-gateway","rate-limiting","bot-protection","owasp"] |
| subdomain | cloud-security |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"] |
Securing Api Gateway With Aws Waf
Overview
Cybersecurity skill for securing api gateway with aws waf. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"securing api gateway with aws waf"
-
"Securing API Gateway endpoints with AWS WAF by configuring managed rule groups f"
-
When deploying API Gateway endpoints that require protection against common web attacks
-
When implementing rate limiting and throttling to prevent API abuse and DDoS attacks
-
When building bot detection and mitigation for API endpoints exposed to the internet
-
When compliance requires WAF protection for all public-facing API endpoints
-
When customizing access controls based on IP reputation, geolocation, or request patterns
Do not use for network-level DDoS protection (use AWS Shield), for application logic vulnerabilities (use SAST/DAST tools), or for internal API security between microservices (use service mesh authentication and authorization).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS API Gateway (REST or HTTP API) deployed with public endpoints
- IAM permissions for
wafv2:* and apigateway:* operations
- CloudWatch and S3 or Kinesis Firehose configured for WAF logging
- Understanding of the API's expected traffic patterns for rate limiting configuration
- IP reputation lists or threat intelligence feeds for custom IP blocking
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}