PRODUCT

SecureFlex

Why AWS WAF blocked a request, explained every morning.

SecureFlex reads your AWS WAF logs every day and checks whether legitimate operations were blocked by mistake. It delivers a report with the rule behind each block and suggested adjustments. It runs inside your own AWS account, so your logs stay there.

Trial adoption is open.We read the first two weeks of reports with you and sort out the false positives and how to handle them.

The reports and the product site are in Japanese.

Talk to us about a trial
PROBLEM

You turned on WAF. Operating it is the hard part.

Managed rules can be enabled in minutes. But when a CSV import or a rich-text post suddenly stops working, a person has to find out why. SecureFlex does that work for you every day.

  1. Find
  2. Explain
  3. Suggest

It aggregates blocked requests by rule and URL, and checks whether a blocked IP also sent legitimate requests. It explains in Japanese which rule reacted to which URL and why, and suggests how to exclude or narrow it. You decide whether to apply a change. SecureFlex never rewrites your rules.

FEATURES

Key features

Daily report

Every morning, it aggregates the logs and sends an interpretation and suggestions by email or Slack. The first half is the AI's interpretation; the second half is the numbers counted from the logs, so you can check one against the other.

False-positive hints

It marks combinations where every blocked IP also sent legitimate requests in the same period, because an attacker normally sends only requests that get blocked. This is a hint, not a verdict. A person makes the final call.

Comparison with past reports

It compares against the past seven days of reports and shows, as numbers, what newly appeared and what increased.

Instant IP blocking

It blocks, for a limited time, IPs that were blocked many times in a short period while probing several URLs. AI is not used for this decision. It is made mechanically from count thresholds.

Safeguards against blocking by mistake

An allowlist, a dry-run mode (record and notify only), automatic release and a cap, and exclusion of repeats on a single URL.

CloudWatch Logs and S3

In addition to CloudWatch Logs, it can analyze WAF logs delivered to S3. With S3 logs, only the daily report is available.

DATA

Your logs never leave your AWS

  • It is software you deploy into your own AWS account. The AI it uses is Amazon Bedrock in your own account, called in a Japanese region
  • It reads only the log group you specify, or the S3 location you specify
  • The daily report has no write permission to WAF. Even with instant blocking, it can write only two IP sets dedicated to SecureFlex, and cannot change the Web ACL or rules
  • Only aggregated results are passed to the AI. Request bodies, headers, cookies and query strings are never passed
  • The only things that leave AWS are the license key and an identifier that distinguishes the deployment
LIMITS

What it does not do

  • It does not judge each request on the spot. The report runs once a day, and instant blocking takes one to two minutes after detection
  • It does not provide 24/7 staffed monitoring
  • If you need to stop a flood of requests within seconds, use it together with AWS WAF rate-based rules
  • Instant blocking works only with logs delivered to CloudWatch Logs
START

Adoption is a single stack

  1. Check your WAF logs
  2. Create the stack
  3. The first report arrives the next morning

Confirm that your AWS WAF logs are delivered to CloudWatch Logs or S3, then create the stack from the deployment link. If you use instant blocking, run it in dry-run mode for one to two weeks before switching to enforcement.

Why not start by looking at what your current logs show? Contact us for pricing and how adoption proceeds.

Go to the contact form

Amazon Web Services, AWS, AWS WAF and Amazon Bedrock are trademarks of Amazon.com, Inc. or its affiliates.