TalksAWS re:Invent 2025 - How Lumen Defender Managed Rules Supercharge AWS Network Firewall (SEC102)

AWS re:Invent 2025 - How Lumen Defender Managed Rules Supercharge AWS Network Firewall (SEC102)

AWS re:Invent 2025 - How Lumen Defender Managed Rules Supercharge AWS Network Firewall

Introduction to AWS Network Firewall

  • AWS Network Firewall is a fully managed cloud firewall service that allows you to deploy essential network protections
  • It can inspect traffic going in and out of VPCs and apply filtering policies to stop lateral movement
  • The service is fully managed, automatically scales up to 100 Gbps, and provides a built-in stateful inspection engine

Partner Managed Rules on AWS Network Firewall

  • Customers wanted simplified security and easier management of rules at scale
  • AWS launched Partner Managed Rules, which provides a curated list of threat intelligence from top AWS Marketplace partners
  • Lumen is one of the launch partners, providing their Defender Managed Rule groups
  • These rules are automatically updated and integrated directly into the Network Firewall console
  • With a single click, customers can add Lumen's threat intelligence to their firewall policy

Lumen's Threat Intelligence and Defender Managed Rules

  • Lumen is a leading internet service provider with global network visibility and scale
  • Their threat intelligence arm, Black Lotus Labs, provides early detection of threat infrastructure and rapid, automated protection
  • Lumen Defender Managed Rules offer:
    • Early threat infrastructure detection from Lumen's global network
    • Rapid, daily updates to the rule sets to stay ahead of attacks
    • Actionable intelligence with context on IPs, domains, and threats

Technical Architecture and Integration

  • Lumen's threat intelligence from Black Lotus Labs is ingested into the AWS Network Firewall
  • This protects both inbound and outbound traffic to your cloud workloads
  • The integration is seamlessly available in the Network Firewall console, allowing easy subscription and deployment

Key Takeaways

  • Lumen's threat intelligence, powered by their global network visibility, provides early detection and rapid protection
  • Defender Managed Rules offer a hassle-free way to enhance your cloud security with curated, context-rich threat intelligence
  • The integration with AWS Network Firewall simplifies deployment and management, allowing you to quickly apply the rules
  • Combining endpoint security with network-level threat intelligence from Lumen offers comprehensive protection

Real-World Examples and Impact

  • Lumen has a proven track record of taking down major network-based attacks, such as Mirai and SystemBC
  • Their threat intelligence and takedown capabilities have been leveraged by public sector organizations for years
  • By bringing this intelligence to the AWS ecosystem, Lumen Defender Managed Rules can help commercial enterprises and cloud customers enhance their security posture

Your Digital Journey deserves a great story.

Build one with us.

Cookies Icon

These cookies are used to collect information about how you interact with this website and allow us to remember you. We use this information to improve and customize your browsing experience, as well as for analytics.

If you decline, your information won’t be tracked when you visit this website. A single cookie will be used in your browser to remember your preference.