Skip to content
Notifications
Clear all

Thoughts on the new ATP (Advanced Threat Protection) rules? Hype or real?

3 Posts
3 Users
0 Reactions
32 Views
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
Topic starter   [#21559]

Hey folks, been wrestling with some webhook ingestion pipelines that keep getting hit with sketchy traffic. Saw AWS rolled out new ATP rules for WAF and figured I'd give them a spin on our staging API.

My initial take? They're definitely a step up from the old managed rule groups, especially for API protection. The "Business Logic" rule to detect abnormal request rates per session is something I've had to build custom rules for before. Having it out-of-the-box is nice.

But here's my thing: the real test is tuning. Out of the gate, the "Generic RFI" rule (for remote file inclusion) threw a few false positives on our legitimate query parameters that pass file paths. Had to dive into the logs and set up some exclusions. The configuration feels more granular, which is good, but it's not a "set and forget" magic bullet.

```json
{
"Name": "exclude-legit-path-param",
"Action": "EXCLUDE_AS_COUNT",
"Statement": {
"ByteMatchStatement": {
"FieldToMatch": {
"UriPath": {}
},
"SearchString": "/api/valid_upload",
"TextTransformations": [
{
"Type": "NORMALIZE_PATH",
"Priority": 1
}
]
}
}
}
```

Has anyone else integrated these yet, especially for data pipeline ingress points? I'm curious if the "Server-Side Request Forgery" rule is catching things the old SQLi rules missed, or if it's just more hype. The pricing is still based on web requests processed, so cranking up all the ATP groups could get spendy on a high-traffic endpoint.

ship it


ship it


   
Quote
(@cost_observer_42)
Honorable Member
Joined: 4 months ago
Posts: 407
 

Nice to hear the granular controls are working for you. But that "Business Logic" rule for abnormal request rates? I'd keep a very close eye on your WAF bill. Every one of those session evaluations and counts is a web ACL request unit. If your traffic is high-volume, "out-of-the-box" can quickly become "out-of-budget."

Have you actually compared the cost per million requests for ATP rules versus your old custom rules? The promise is great until the invoice arrives.


cost_observer_42


   
ReplyQuote
(@henryp)
Reputable Member
Joined: 3 months ago
Posts: 294
 

So what if the old custom rules were cheaper? They missed things. ATP costs more because it's doing more.

But your cost point is real. The question isn't just the invoice. It's what you'd pay for a breach. The hypetrain is about 'advanced' threats. The exit strategy is always in your WAF logs: if the ATP is mostly catching stuff your old rules did, turn it off and pocket the difference.


Doubt everything


   
ReplyQuote