[AWS Architecture Patterns] Security
Need to enable custom domain name and encryption in transit for an application running behind an Application Load Balancer?
Use AWS Route 53 to create an Alias record to the ALB's DNS name and attach an SSL/TLS certificate issued by Amazon Certificate Manager (ACM).
Company records customer information in CSV in an S3 bucket and must ont store PII data?
Use Macie to scan the S3 bucket for any PII data.
For compliance reasons all S3 buckets must have encryption enabled and any non-compliant buckets must be auto remediated?
Use AWS Config to check the encryption status of the buckets and use auto remediation to enable encyprtion as requried.
EC2 instances must be checked against CIS benchmarks every 7 days?
Install Amazon Inspector agent and configure a host assessment every 7 days.
Webiste running on EC2 instances behind and ALB must be protected against well known web exploits?
Create a Web ACL in AWS WAF to protect against web exploits against web exploits and attach to the ALB.
Need to block access to an application running on an ALB from connections originating in a specific list of countries?
Create a Web ACL in AWS WAF with a geographic match and block traffic that matches the list of countries.
Partten matching for 100 requests per 5 mins, block it
分类:
AWS
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 阿里最新开源QwQ-32B,效果媲美deepseek-r1满血版,部署成本又又又降低了!
· Manus重磅发布:全球首款通用AI代理技术深度解析与实战指南
· 开源Multi-agent AI智能体框架aevatar.ai,欢迎大家贡献代码
· 被坑几百块钱后,我竟然真的恢复了删除的微信聊天记录!
· AI技术革命,工作效率10个最佳AI工具
2021-03-28 [Node.js] Apply image filter on Express
2019-03-28 [Node.js] process.nextTick for converting sync to async
2019-03-28 [Algorithm] Print 2-D array in spiral order
2017-03-28 [Grid Layout] Use auto-fill and auto-fit if the number of repeated grid tracks is not to be def
2017-03-28 [Grid Layout] Use the repeat function to efficiently write grid-template values
2017-03-28 [Grid Layout] Use the minmax function to specify dynamically-sized tracks
2017-03-28 [Jest] Snapshot