AWS uses internal threat intelligence tools like Sonaris to stay ahead of potential threats and protect customers quickly when activities could be potentially harmful to their business.
Sonaris is an active defense tool that analyses potentially harmful network traffic and restricts threat actors who are hunting for exploitable vulnerabilities.
Sonaris identifies and automatically restricts unauthorized scanning and S3 bucket discovery, reducing risk for AWS customers.
Sonaris applies heuristic, statistical, and machine learning algorithms to vast amounts of summarized metadata and service health telemetry.
Sonaris uses threat intelligence data from MadPot, which emulates hundreds of different services and mimics customer accounts, to increase its accuracy for automatically restricting known malicious vulnerability enumeration attacks.
Sonaris has been effectively protecting customers from a large active botnet known as Dota3 that has been scanning the internet for vulnerable hosts and devices to install cryptominer malware.
AWS is committed to making the internet a safer place for customers, and encourages feedback through comments, customer support, or preferred channels.
As organizations continue to migrate to the cloud, AWS continuously invests and innovates in advancing its security capabilities to tackle emerging threats.
Sonaris is an example of how AWS proactively mitigates potential threats to prevent security incidents from disrupting customers' businesses.
Through the creation of active security tools like Sonaris, AWS is committed to a strong security posture that aligns with business objectives.