Files
nexus/wiki/concepts/WAF-Web-Application-Firewall.md
2026-04-28 20:03:11 +08:00

1.7 KiB
Raw Blame History

title, type, tags, sources, last_updated
title type tags sources last_updated
WAF (Web Application Firewall) concept
AWS
Security
Networking
ctp-topic-7-saas-landing-zone-design
2026-05-06

WAF (Web Application Firewall)

AWS Web Application Firewall — Web 应用防火墙服务,监控和过滤进入 Web 应用的 HTTP/HTTPS 流量。

Definition

WAF 是产品账户入站安全层的核心组件:

  • 功能通过规则Rules过滤恶意流量保护 Web 应用免受 OWASP Top 10 等常见攻击
  • 部署位置:产品账户,位于 CloudFront 和 Load Balancer 之后
  • 流量监控WAF 监控入站流量,可阻断 SQL 注入、XSS、CSRF 等攻击

Role in SAS Landing Zone

ctp-topic-7-saas-landing-zone-design 定义的 Product Account 入站架构中:

  • 位置CloudFront → WAF → Load Balancer公有子网→ 工作负载(私有子网)
  • 功能:实时监控入站流量,阻断异常请求
  • 可选 CloudFrontCDN 层可选,但 WAF 是必须的安全层

Key Properties

  • Type: Security Service
  • Layer: Application Layer (L7)
  • Position in stack: After CDN/Before Application
  • In SAS LZ: 产品账户入站安全层

AWS WAF Capabilities

  • Managed rule groups (AWS managed, vendor managed)
  • IP blocking/rate limiting
  • Geographic restrictions
  • SQL injection and XSS protection
  • Bot control

Relationship to AWS Firewall Manager

Connections