AWS security-group port exposure needs review

Identify the actual service and intended clients for public ports.

Description

A port open to all source addresses needs a clear service purpose and intended audience. An uncommon port number does not by itself prove that a service is unsafe or its purpose unknown. Identify the actual listener, its owner and the need for public access.

Potential impact

  • Unused or temporary services may be exposed to unnecessary external connections.
  • Rules without a clear purpose or owner make access scope and change impact harder to manage.

Remediation

  • Identify the service, owner and required clients, and remove unnecessary public rules.
  • Where public access is needed, restrict actual sources, protocols and ports to the required scope, documenting the reason and review deadline.
  • Review IPv4, IPv6 and all attached security groups, verifying that required connections succeed and unwanted connections are blocked.

Examples

These excerpts compare ingress scope for a TCP 5001 service. Identify the actual service, VPC and attachments separately, and replace the private example range with approved client addresses.

Before

hcl
resource "aws_security_group" "custom_service" {
  name        = "allow-custom-port"
  description = "Unknown port exposed"

  ingress {
    from_port   = 5001
    to_port     = 5001
    protocol    = "tcp"
    cidr_blocks = ["0.0.0.0/0"]
  }
}

This allows TCP 5001 from all IPv4 sources. The port number alone does not determine the service or whether public access is needed.

After

hcl
resource "aws_security_group" "custom_service" {
  name        = "allow-custom-port"
  description = "Unknown port restricted"

  ingress {
    from_port   = 5001
    to_port     = 5001
    protocol    = "tcp"
    cidr_blocks = ["10.20.0.0/24"]
  }
}

This restricts sources to 10.20.0.0/24. Check whether the entire range is needed and whether another security group allows broader access.

References