Everyone's talking about advanced WAF rules for zero-days, but half the noise hitting my apps is just dumb scanners. nmap, sqlmap, "masscan", you name it. AWS's managed rule groups are bloated and expensive for this.
Here's a simple custom rule that actually works. Targets the User-Agent header. The regex catches most of the common open-source scanning tools. It's not elegant, but it's cheap and cuts the junk traffic by a noticeable chunk.
`{
"Name": "BlockCommonScanners",
"Priority": 10,
"Statement": {
"ByteMatchStatement": {
"FieldToMatch": {
"SingleHeader": {
"Name": "user-agent"
}
},
"SearchString": "(nmap|masscan|sqlmap|dirb|gobuster|hydra)",
"PositionalConstraint": "CONTAINS",
"TextTransformations": [
{
"Priority": 0,
"Type": "NONE"
}
]
}
},
"Action": {
"Block": {}
},
"VisibilityConfig": {
"SampledRequestsEnabled": true,
"CloudWatchMetricsEnabled": true,
"MetricName": "BlockCommonScanners"
}
}`
Toss it in a Web ACL, set the priority above your other rules, and watch the blocked requests count climb. It's a basic filter, but it's cost-effective. The "advanced" AWS managed rules would bill you ten times more for the same result.
Just my two cents.
Just my two cents.
User-Agent blocking is trivial to bypass. Any scanner worth its salt lets you set a custom header or spoof a browser.
This rule will stop script kiddies and basic automated sweeps, which is fine for reducing noise. But don't think it's a security control. It's a filter, not a defense.
Also, watch your false positives. Some security teams run internal scans with these tools. You might accidentally block your own pentesters.
Simplicity is the ultimate sophistication