AWS WAF is a web application firewall that helps you protect against common web exploits and bots that can affect availability, compromise security, or consume excessive resources.
Challenge actions is useful for detecting requests from automated tools without affecting the user experience.
Properly handling bot traffic can reduce the impact, which can help you optimize costs and improve the stability of your infrastructure and the availability of your business.
Implementing Challenge actions through a custom rule is a cost-effective way of using this action to help you reduce the impact of bot traffic in your applications.
Option 1: Implementing the Challenge action through a custom rule involves defining the expected normal behaviors of the users who access your app.
Option 2: Implementing the Challenge action by using Bot Control in AWS WAF is an easier, more robust and flexible solution than using a custom rule.
Bot Control is a managed rules group that provides improved visibility and automated detection and mitigation mechanisms for bots.
As your cloud infrastructure grows, you need to start managing your protection at scale and centrally. AWS Firewall Manager provides you with a single place to centrally configure, manage, and monitor your AWS WAF firewall, AWS Shield Advanced protections, and more.
This blog covers the basics of using the Bot Control feature to implement Challenge actions as a more sophisticated and robust option.
By implementing Challenge actions through a custom rule, you can set up basic, cost-effective measures to handle basic bots and control automated traffic to your applications.