Review AWS WAF protection for API Gateway

Apply required web request filtering to REST API stages and check its effect on legitimate requests.

Description

An API Gateway REST API stage without an AWS WAF association does not receive the request inspection and blocking of that web ACL. Where controls against abusive web requests are needed, review WAF configuration against the API’s purpose and existing protections.

WAF processes requests according to its rules. It does not replace caller authentication, application permission checks or vulnerability fixes, and attaching a web ACL does not block every attack.

Potential impact

  • Without required request filtering, malicious inputs or repeated requests can reach the application.
  • Unsuitable blocking rules can reject legitimate customer requests.

Remediation

Associate a REGIONAL web ACL in the same Region with the REST API stage that needs protection. Select managed and custom rules appropriate for the API, assess their impact using options such as Count mode, then apply required blocking. Verify the actual association, request records and legitimate traffic, and retain authentication and application security controls.

Examples

The REST API, deployment and web ACL are separate inputs. Supply the ARN of a REGIONAL web ACL in the same Region through ApiWebAclArn. Rule definitions and logging configuration are omitted.

Before

yaml
Resources:
  ProdStage:
    Type: AWS::ApiGateway::Stage
    Properties:
      StageName: Prod
      RestApiId: !Ref MyRestApi
      DeploymentId: !Ref ApiDeployment

This excerpt contains no stage-to-web-ACL association. Check separately applied protections and the actual association state.

After

yaml
Resources:
  ProdStage:
    Type: AWS::ApiGateway::Stage
    Properties:
      StageName: Prod
      RestApiId: !Ref MyRestApi
      DeploymentId: !Ref ApiDeployment

  ProdStageWebAclAssociation:
    Type: AWS::WAFv2::WebACLAssociation
    Properties:
      WebACLArn: !Ref ApiWebAclArn
      ResourceArn: !Sub arn:${AWS::Partition}:apigateway:${AWS::Region}::/restapis/${MyRestApi}/stages/${ProdStage}

This associates the web ACL using MyRestApi and ProdStage in the current Region. Configure web ACL rules and actions, and verify results for legitimate and malicious requests.

References