WAF "AWS Managed Rules" for "Windows Operating System" block SNS requests sent by AWS Textract

0

I've noticed that if you enable the "Windows Operating System" rule group from the "AWS Managed Rules" rule group against your Web ACL in WAF that SNS notifications generated by AWS Textract are blocked due to matching the rule:

AWS#AWSManagedRulesWindowsRuleSet#WindowsShellCommands_BODY

Whilst that rule can be edited and "count" switched on instead to mitigate the issue the problem then is that you loose that rules protection against legitimate attacks. My questions therefore is how can do we add the AWS services to an allow list so that they do not trigger the block themselves whilst leaving the rule in place for all other requests? Do we have to allow all AWS IPs by creating a IP set covering the all IP ranges within expected regions or is there another way to simply say "allow AWS based services"?

已提问 2 年前109 查看次数
没有答案

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则