AWS Transfer Family is a secure transfer service that lets you transfer files directly into and out of Amazon Web Services (AWS) storage services using popular protocols
There are multiple security configuration options that you can activate to fit your needs and provide instructions for each one
Newly created Transfer Family servers use the strongest security policy to reduce risks of known vulnerabilities such as CVE-2023-48795
Use slashes in session policies to limit access and set session policies on S3 bucket prefixes to avoid granting access to unwanted buckets
Creating a session policy for an S3 bucket with appropriate access using IAM managed policies provides extra protection against accidental changes to logical directory mappings
Avoid using Network Load Balancers (NLBs) in front of your Transfer Family server to maintain auditability, better performance, and fewer restrictions
Protect your API Gateway instance with AWS Web Application Firewall (WAF) to create access control lists (ACLs) for only AWS and anyone in the ACL for your API Gateway instance
FTPS customers should use TLS session resumption to help protect client connections as they hand off between the FTPS control port and the data port. Transfer Family endpoints provide options for session resumption
Transfer Family offers many benefits to help secure your managed file transfer (MFT) solution as the threat landscape evolves.