QuestionQ25

Infrastructure Security

A company operates an internet-facing open-source software platform. The legacy platform no longer receives security updates. It uses Amazon Route 53 weighted load balancing to route traffic to two Amazon EC2 instances that connect to an Amazon RDS cluster. A recent report indicates that the platform is vulnerable to SQL injection attacks and includes attack samples. The company’s security engineer must secure the system against SQL injection attacks within 24 hours. The solution must require the least effort and maintain normal operations throughout implementation.

What should the security engineer do to satisfy these requirements?

Explanation

AWS WAF SQL injection rules inspect web-request components for malicious SQL code and can block matching requests. A web ACL can be associated with an Application Load Balancer, so placing an ALB before the two existing EC2 instances provides immediate application-layer protection while continuing to distribute traffic to both instances. Restricting the EC2 security groups to traffic from the ALB prevents direct internet access that could bypass the web ACL.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!