Hey folks, I've been testing the new Bot Control features in AWS WAFv2 for the last few weeks on a couple of our e-commerce and API endpoints. The short answer: they're incredibly powerful, but the cost can sneak up on you if you're not careful.
I wanted to share my setup and some real numbers to see if others have had similar experiences. We were already using the Core Rule Set (CRS) and some custom rate-based rules, but the volume of sophisticated bot traffic—mostly credential stuffing and inventory scraping—was still high.
Here's the basic Terraform snippet I used to enable Bot Control in our module:
```hcl
resource "aws_wafv2_web_acl" "main" {
name = "bot-control-example"
scope = "REGIONAL"
description = "Web ACL with Bot Control"
default_action {
allow {}
}
rule {
name = "AWSManagedRulesBotControlRuleSet"
priority = 10
override_action {
none {}
}
statement {
managed_rule_group_statement {
name = "AWSManagedRulesBotControlRuleSet"
vendor_name = "AWS"
# This is where you choose the rule action
managed_rule_group_configs {
aws_managed_rules_bot_control_rule_set {
inspection_level = "COMMON"
}
}
}
}
visibility_config {
cloudwatch_metrics_enabled = true
metric_name = "AWSManagedRulesBotControlRuleSet"
sampled_requests_enabled = true
}
}
# ... other rules and visibility config
}
```
**Immediate Observations & Cost Breakdown:**
* **Effectiveness:** The "Targeted" inspection level (more expensive) caught a staggering amount of traffic we had previously missed—mostly headless browsers and toolkits pretending to be legitimate browsers. Our login attempt volume dropped by about 60% almost instantly.
* **Costs:** This is the big one. You pay per **million requests inspected** by the Bot Control rule group, on top of standard WAF charges. The pricing tier changes based on the inspection level ("Common" vs. "Targeted"). For our main application, which handles around 500 million requests monthly, this added a significant line item.
* "Common" inspection is less costly and targets known bad bots.
* "Targeted" inspection is where the cost jumps, but it goes after evasive bots. You need to analyze your sampled requests in CloudWatch to see what you're really catching.
**My Verdict So Far:**
It's worth the cost **if**:
* You are a direct target for credential stuffing, scraping, or carding attacks.
* You have already optimized your rule order and use rate-based rules for the "low-hanging fruit."
* You monitor your WAF logs to tune exclusions (e.g., for legitimate search engine bots you want to allow).
It might **not** be worth it if:
* Your traffic is relatively low.
* You're only dealing with simple volumetric bots (rate-based rules might suffice).
* You don't have the bandwidth to review logs and could end up blocking good traffic.
I'm leaning towards keeping it on our critical paths (login, checkout, API) but disabling it elsewhere. Would love to hear how others are justifying the ROI. Has anyone done a detailed cost/benefit analysis compared to a third-party solution?
—John
Keep it simple.