Description
Allowing more outbound TCP or UDP ports than necessary increases opportunities to connect to unapproved services. If only one port is needed, set FromPort and ToPort to that port.
A range is valid for services that require multiple consecutive ports; not every rule must use a single port. For ICMP, these fields specify a type and code rather than a port range and must be interpreted separately.
Potential impact
- A compromised workload can communicate or transfer data over unnecessarily permitted ports.
- Narrowing a range without checking requirements can interrupt legitimate service connections.
Remediation
- Identify destination service ports and allow a single TCP or UDP port or the smallest required range.
- Also restrict destinations and permissions in other attached security groups.
- Test dependency connections. Security groups are stateful, so responses to permitted inbound connections do not require opening every outbound port.
Examples
These port-setting excerpts omit SourceSG and the required destination. Supply one destination CIDR, prefix list, or security group before using them.
Before
Resources:
OutboundRule:
Type: AWS::EC2::SecurityGroupEgress
Properties:
IpProtocol: tcp
FromPort: 0
ToPort: 65535
GroupId: !GetAtt SourceSG.GroupId
Once a destination is supplied, this permits every TCP port.
After
Resources:
OutboundRule:
Type: AWS::EC2::SecurityGroupEgress
Properties:
IpProtocol: tcp
FromPort: 443
ToPort: 443
GroupId: !GetAtt SourceSG.GroupId
The range is reduced to TCP 443. Confirm that the required service uses this port and configure TLS and authentication in the application as well.