AwsNetworkFirewall - Amazon Security Hub
Amazon Web Services 文档中描述的 Amazon Web Services 服务或功能可能因区域而异。要查看适用于中国区域的差异,请参阅 中国的 Amazon Web Services 服务入门 (PDF)

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

AwsNetworkFirewall

以下是AwsNetworkFirewall资源Amazon的安全查找格式的示例。

AwsNetworkFirewallFirewall

AwsNetworkFirewallFirewall对象包含有关Amazon Network Firewall防火墙的详细信息。

以下示例显示AwsNetworkFirewallFirewall对象Amazon的安全结果格式 (ASFF)。要查看AwsNetworkFirewallFirewall属性的描述,请参阅 Amazon Security HubAPI 参考AwsNetworkFirewallFirewallDetails中的。

示例

"AwsNetworkFirewallFirewall": { "DeleteProtection": false, "FirewallArn": "arn:aws:network-firewall:us-east-1:024665936331:firewall/testfirewall", "FirewallPolicyArn": "arn:aws:network-firewall:us-east-1:444455556666:firewall-policy/InitialFirewall", "FirewallId": "dea7d8e9-ae38-4a8a-b022-672a830a99fa", "FirewallName": "testfirewall", "FirewallPolicyChangeProtection": false, "SubnetChangeProtection": false, "SubnetMappings": [ { "SubnetId": "subnet-0183481095e588cdc" }, { "SubnetId": "subnet-01f518fad1b1c90b0" } ], "VpcId": "vpc-40e83c38" }

AwsNetworkFirewallFirewallPolicy

AwsNetworkFirewallFirewallPolicy对象提供有关防火墙策略的详细信息。防火墙策略定义网络防火墙的行为。

以下示例显示AwsNetworkFirewallFirewallPolicy对象Amazon的安全结果格式 (ASFF)。要查看AwsNetworkFirewallFirewallPolicy属性的描述,请参阅 Amazon Security HubAPI 参考AwsNetworkFirewallFirewallPolicyDetails中的。

示例

"AwsNetworkFirewallFirewallPolicy": { "FirewallPolicy": { "StatefulRuleGroupReferences": [ { "ResourceArn": "arn:aws:network-firewall:us-east-1:444455556666:stateful-rulegroup/PatchesOnly" } ], "StatelessDefaultActions": [ "aws:forward_to_sfe" ], "StatelessFragmentDefaultActions": [ "aws:forward_to_sfe" ], "StatelessRuleGroupReferences": [ { "Priority": 1, "ResourceArn": "arn:aws:network-firewall:us-east-1:444455556666:stateless-rulegroup/Stateless-1" } ] }, "FirewallPolicyArn": "arn:aws:network-firewall:us-east-1:444455556666:firewall-policy/InitialFirewall", "FirewallPolicyId": "9ceeda22-6050-4048-a0ca-50ce47f0cc65", "FirewallPolicyName": "InitialFirewall", "Description": "Initial firewall" }

AwsNetworkFirewallRuleGroup

AwsNetworkFirewallRuleGroup对象提供有关Amazon Network Firewall规则组的详细信息。规则组用于检查和控制网络流量。无状态规则组适用于单个数据包。有状态规则组适用于数据包的流量上下文中的数据包。

防火墙策略中引用了规则组。

以下示例显示AwsNetworkFirewallRuleGroup对象Amazon的安全结果格式 (ASFF)。要查看AwsNetworkFirewallRuleGroup属性的描述,请参阅 Amazon Security HubAPI 参考AwsNetworkFirewallRuleGroupDetails中的。

示例-无状态规则组

"AwsNetworkFirewallRuleGroup": { "Capacity": 600, "RuleGroupArn": "arn:aws:network-firewall:us-east-1:444455556666:stateless-rulegroup/Stateless-1", "RuleGroupId": "fb13c4df-b6da-4c1e-91ec-84b7a5487493", "RuleGroupName": "Stateless-1" "Description": "Example of a stateless rule group", "Type": "STATELESS", "RuleGroup": { "RulesSource": { "StatelessRulesAndCustomActions": { "CustomActions": [], "StatelessRules": [ { "Priority": 1, "RuleDefinition": { "Actions": [ "aws:pass" ], "MatchAttributes": { "DestinationPorts": [ { "FromPort": 443, "ToPort": 443 } ], "Destinations": [ { "AddressDefinition": "192.0.2.0/24" } ], "Protocols": [ 6 ], "SourcePorts": [ { "FromPort": 0, "ToPort": 65535 } ], "Sources": [ { "AddressDefinition": "198.51.100.0/24" } ] } } } ] } } } }

示例-有状态规则组

"AwsNetworkFirewallRuleGroup": { "Capacity": 100, "RuleGroupArn": "arn:aws:network-firewall:us-east-1:444455556666:stateful-rulegroup/tupletest", "RuleGroupId": "38b71c12-da80-4643-a6c5-03337f8933e0", "RuleGroupName": "ExampleRuleGroup", "Description": "Example of a stateful rule group", "Type": "STATEFUL", "RuleGroup": { "RuleSource": { "StatefulRules": [ { "Action": "PASS", "Header": { "Destination": "Any", "DestinationPort": "443", "Direction": "ANY", "Protocol": "TCP", "Source": "Any", "SourcePort": "Any" }, "RuleOptions": [ { "Keyword": "sid:1" } ] } ] } } }

以下是AwsNetworkFirewallRuleGroup属性的有效值示例列表:

  • Action

    有效值:PASS |DROP |ALERT

  • Protocol

    有效值:IP|TCPUDP |ICMP |HTTP |FTP |TLS |SMB |DNS |DCERPC |SSH |SMTPIMAP |MSN |KRB5 |IKEV2 |TFTP |NTP |DHCP

  • Flags

    有效值:FIN | SYN | RST | PSH | ACK | URG | ECE | CWR

  • Masks

    有效值:FIN | SYN | RST | PSH | ACK | URG | ECE | CWR