Default security group retains traffic rules

Move required traffic to dedicated security groups so unintended permissions do not remain on the default group.

Description

A VPC’s default security group can be assigned to resources that omit a security group. Its default inbound rule permits traffic between resources in that group, while default outbound rules permit traffic to all destinations. The default inbound rule does not itself allow internet access.

Broad permissions added to this shared group also apply to resources attached later. Dedicated groups for specific workloads make access easier to control; remove rules from a default group that is no longer in use.

Potential impact

  • Unnecessary inbound rules can increase connection attempts against internal services or administrative ports.
  • Broad outbound permissions can give a compromised resource more external communication paths.

Remediation

  • Identify attached resources and required traffic, then configure and attach restricted dedicated groups first.
  • After verifying required connections, remove unnecessary inbound and outbound rules from the default group. The default group itself cannot be deleted.
  • Omitting egress rules when creating a security group adds allow-all outbound rules. Specify required destinations and protocols and inspect the resulting rules.

Examples

The first example adds broad SSH rules to an existing default group supplied by ID. The second creates a dedicated group limited to required SSH sources and destinations. Supply the actual VPC and approved CIDRs, and review other required traffic. Creating the dedicated group does not change existing attachments or default-group rules.

Before

yaml
Parameters:
  DefaultSecurityGroupId:
    Type: AWS::EC2::SecurityGroup::Id
Resources:
  SharedSSHIngress:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      GroupId: !Ref DefaultSecurityGroupId
      IpProtocol: tcp
      FromPort: 22
      ToPort: 22
      CidrIp: 0.0.0.0/0
  SharedSSHEgress:
    Type: AWS::EC2::SecurityGroupEgress
    Properties:
      GroupId: !Ref DefaultSecurityGroupId
      IpProtocol: tcp
      FromPort: 22
      ToPort: 22
      CidrIp: 0.0.0.0/0

These rules can affect every resource sharing the default group. External connectivity also depends on routing, addresses and other network controls.

After

yaml
Parameters:
  VpcId:
    Type: AWS::EC2::VPC::Id
  AdminCidr:
    Type: String
  SSHDestinationCidr:
    Type: String
Resources:
  DedicatedSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Restricted SSH connectivity
      VpcId: !Ref VpcId
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 22
          ToPort: 22
          CidrIp: !Ref AdminCidr
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 22
          ToPort: 22
          CidrIp: !Ref SSHDestinationCidr

Attach the dedicated group and test connectivity before removing the old default-group association and unnecessary rules. Security groups are stateful, so replies to allowed connections do not require separate reverse-direction rules.

References