WAF Web ACL has no rate-based rule for DDoS protection

Severity
Critical
Service
AWS WAF
Check ID
WAF_NO_RATE_BASED_RULE

What this check finds

This Web ACL has no rate-based rule. Without rate limiting, a single IP can send unlimited requests, enabling DDoS or credential-stuffing attacks.

Passing looks like: WAF has a rate-based rule.

How to fix it

Add a rate-based rule with an appropriate request limit (e.g. 2000 requests per 5 minutes per IP).

AWS console

WAF → Web ACLs → Rules → Add rule → Rate-based rule.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to WAF Web ACL has no rate-based rule for DDoS protection
FrameworkControls
PCI-DSS v4.0.1
  • 6.4 Public-facing web applications are protected against attacks
NIST SP 800-53 Rev5 (Moderate)
  • SC-5 Denial-of-Service Protection
NIST Cybersecurity Framework 2.0
  • PR.IR-04 Adequate resource capacity for availability is maintained
ISO/IEC 27001:2022 Annex A
  • A.8.20 Networks security

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

More AWS WAF checks

All AWS WAF checks

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only