2021.01. ์ด์žฅ์žฌ ๐Ÿ“ง cine0831@gmail.com ๐Ÿ“‚ https://github.com/jangjaelee ๐Ÿ“’ http://www.awx.kr



Overview

AWS WAFv2(Web Application Firewall)์€ CloudFront distribution, Amazon API Gateway(REST API), Application Load Balancer ๋˜๋Š” AWS AppSync(GraphQL API)์— ์ „๋‹ฌ๋˜๋Š” HTTP ๋ฐ HTTPS requests๋ฅผ monitoringํ•˜์—ฌ ์š”์ฒญ์ด ํ—ˆ์šฉ๋˜๋Š” IP Address, Port, Query string value๋กœ๋ถ€ํ„ฐ ์ง€์ •ํ•˜๋Š” ์กฐ๊ฑด์— ๋”ฐ๋ผ HTTP 403 status code๋กœ ์š”์ฒญ์— ์‘๋‹ตํ•˜๋Š” ์›น๋ฐฉํ™”๋ฒฝ ์ž…๋‹ˆ๋‹ค.

์šฐ๋ฆฌ๊ฐ€ ํ”ํžˆ ์•Œ๊ณ  ์žˆ๋Š” F/W(Firewall)์ด L3/L4 Layer์˜ ๋ฐฉ์–ด(IP์™€ port ์ฐจ๋‹จ)์„ ์ œ๊ณต ํ•œ๋‹ค๋ฉด WAF(์›น๋ฐฉํ™”๋ฒฝ)์€ L7(HTTP header, HTTP body, URI strings, SQL Injection, Cross Site Scripting[XSS])์„ ์ด์šฉํ•œ ๊ณต๊ฒฉ์„ ๋ฐฉ์–ด ํ•ฉ๋‹ˆ๋‹ค.


๊ฐœ๋… ๋ฐ ๊ตฌ์„ฑ์š”์†Œ

Web ACL์„ ์ƒ์„ฑํ•˜๋ฉด ํ•˜๋‚˜ ์ด์ƒ์˜ AWS Resource์™€ ์—ฐ๊ฒฐํ•˜์—ฌ ์‚ฌ์šฉ ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๋ณดํ˜ธ๊ฐ€ ๊ฐ€๋Šฅํ•œ Resource type์€ Amazon CloudFront distribution, Amazon API Gateway(REST API), ALB(Application Load Balancer) ๊ทธ๋ฆฌ๊ณ  AWS AppSync GraphQL API ์ž…๋‹ˆ๋‹ค.

AWS WAF๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ์š”์†Œ๋Š” ํฌ๊ฒŒ ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค.


์žฅ์ 