LOCK DOWN Your Amazon API Gateways

preview_player
Показать описание
** Don't forget to please subscribe to the channel **

This video shows an Amazon API Gateway reference deployment for securing a Serverless application built previously in this channel. Following is the list of things we do in this video make our serverless application's api gateway more secure:

* Locked down the API GW to the external world by:
** Requiring a custom security token to be present in the requests
** Not exposing the valid security token value to external users
* Adding a Cloudfront distribution in front of the API Gateway:
** The distribution would inject the security token value in all the requests
** Users would send requests to the distribution
** This also provides additional DDoS protection
* Added usage plans for throttling/rate limiting. Requests with no valid usage plan key would be denied
* Added request validation. Invalid requests would not reach our code and would be denied
* Added a WAF to check against common exploits
Рекомендации по теме
Комментарии
Автор

Thank you for the video shared and say Hi to oscar

SabihaMazhar-zy
Автор

Salaam Shah Sahib, can we talk sometime... Dr Khizer Saeed

KhizerSaeed-hlex
visit shbcf.ru