Description
A VPC’s default security group can be assigned to resources that omit a security group. Its default inbound rule permits traffic between resources in that group, while default outbound rules permit traffic to all destinations. The default inbound rule does not itself allow internet access.
Broad permissions added to this shared group also apply to resources attached later. Dedicated groups for specific workloads make access easier to control; remove rules from a default group that is no longer in use.
Potential impact
- Unnecessary inbound rules can increase connection attempts against internal services or administrative ports.
- Broad outbound permissions can give a compromised resource more external communication paths.
Remediation
- Identify attached resources and required traffic, then configure and attach restricted dedicated groups first.
- After verifying required connections, remove unnecessary inbound and outbound rules from the default group. The default group itself cannot be deleted.
- Omitting egress rules when creating a security group adds allow-all outbound rules. Specify required destinations and protocols and inspect the resulting rules.
Examples
The first example adds broad SSH rules to an existing default group supplied by ID. The second creates a dedicated group limited to required SSH sources and destinations. Supply the actual VPC and approved CIDRs, and review other required traffic. Creating the dedicated group does not change existing attachments or default-group rules.
Before
Parameters:
DefaultSecurityGroupId:
Type: AWS::EC2::SecurityGroup::Id
Resources:
SharedSSHIngress:
Type: AWS::EC2::SecurityGroupIngress
Properties:
GroupId: !Ref DefaultSecurityGroupId
IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: 0.0.0.0/0
SharedSSHEgress:
Type: AWS::EC2::SecurityGroupEgress
Properties:
GroupId: !Ref DefaultSecurityGroupId
IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: 0.0.0.0/0
These rules can affect every resource sharing the default group. External connectivity also depends on routing, addresses and other network controls.
After
Parameters:
VpcId:
Type: AWS::EC2::VPC::Id
AdminCidr:
Type: String
SSHDestinationCidr:
Type: String
Resources:
DedicatedSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Restricted SSH connectivity
VpcId: !Ref VpcId
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: !Ref AdminCidr
SecurityGroupEgress:
- IpProtocol: tcp
FromPort: 22
ToPort: 22
CidrIp: !Ref SSHDestinationCidr
Attach the dedicated group and test connectivity before removing the old default-group association and unnecessary rules. Security groups are stateful, so replies to allowed connections do not require separate reverse-direction rules.