AWS Security ChangesHomeSearch

AWS network-firewall: Add aws:SourceAccount conditions to Network Firewall S3 log bucket policies

Service: network-firewall · 2026-09-27 · Documentation medium

File: network-firewall/latest/developerguide/logging-s3.md · Type: authz

Summary

Rewrites the S3 bucket policy and permissions examples for Network Firewall log delivery, adding aws:SourceAccount conditions, correcting resource ARNs (wildcards, folder paths), and using standard AWSLogDeliveryWrite/AWSLogDeliveryAclCheck Sids.

Security assessment

The added aws:SourceAccount conditions on the delivery.logs.amazonaws.com principal restrict log delivery to specific source accounts, mitigating confused-deputy cross-account write risks; this is security best-practice documentation rather than a fix for a named vulnerability.

Evidence

              "aws:SourceAccount": "111122223333"

Diff

diff --git a/network-firewall/latest/developerguide/logging-s3.md b/network-firewall/latest/developerguide/logging-s3.md
index dd1237e78..70f3ff9b8 100644
--- a//network-firewall/latest/developerguide/logging-s3.md
+++ b//network-firewall/latest/developerguide/logging-s3.md
@@ -78,5 +78 @@ You must have the following permissions settings to configure your firewall to s
-JSON
-    
-
-****
-    
+###### Example – Permissions policy for sending firewall logs to Amazon S3
@@ -89,10 +85 @@ JSON
-                "Action": [
-                    "logs:CreateLogDelivery",
-                    "logs:GetLogDelivery",
-                    "logs:UpdateLogDelivery",
-                    "logs:DeleteLogDelivery",
-                    "logs:ListLogDeliveries"
-                ],
-                "Resource": [
-                    "*"
-                ],
+          "Sid": "AWSLogDeliveryWrite",
@@ -100 +87,11 @@ JSON
-                "Sid": "FirewallLogging"
+          "Principal": {
+            "Service": "delivery.logs.amazonaws.com"
+          },
+          "Action": "s3:PutObject",
+          "Resource": "arn:aws:s3:::amzn-s3-demo-bucket/optional-folder/AWSLogs/111122223333/*",
+          "Condition": {
+            "StringEquals": {
+              "s3:x-amz-acl": "bucket-owner-full-control",
+              "aws:SourceAccount": "111122223333"
+            }
+          }
@@ -103,9 +100,12 @@ JSON
-                "Sid": "FirewallLoggingS3",
-                "Action": [
-                    "s3:PutBucketPolicy",
-                    "s3:GetBucketPolicy"
-                ],
-                "Resource": [
-                    "arn:aws:s3:::bucket-name"
-                ],
-                "Effect": "Allow"
+          "Sid": "AWSLogDeliveryAclCheck",
+          "Effect": "Allow",
+          "Principal": {
+            "Service": "delivery.logs.amazonaws.com"
+          },
+          "Action": "s3:GetBucketAcl",
+          "Resource": "arn:aws:s3:::amzn-s3-demo-bucket",
+          "Condition": {
+            "StringEquals": {
+              "aws:SourceAccount": "111122223333"
+            }
+          }
@@ -121,5 +120 @@ If the user creating the log owns the bucket, the service automatically attaches
-JSON
-    
-
-****
-    
+###### Example – Bucket policy for a single account log delivery
@@ -134 +129,3 @@ JSON
-                "Principal": {"Service": "delivery.logs.amazonaws.com"},
+          "Principal": {
+            "Service": "delivery.logs.amazonaws.com"
+          },
@@ -136,2 +133,7 @@ JSON
-                "Resource": "arn:aws:s3:::bucket-name/optional-folder/AWSLogs/123456789012/*",
-                "Condition": {"StringEquals": {"s3:x-amz-acl": "bucket-owner-full-control"}}
+          "Resource": "arn:aws:s3:::amzn-s3-demo-bucket/AWSLogs/111122223333/*",
+          "Condition": {
+            "StringEquals": {
+              "s3:x-amz-acl": "bucket-owner-full-control",
+              "aws:SourceAccount": "111122223333"
+            }
+          }
@@ -142 +144,3 @@ JSON
-                "Principal": {"Service": "delivery.logs.amazonaws.com"},
+          "Principal": {
+            "Service": "delivery.logs.amazonaws.com"
+          },
@@ -144 +148,6 @@ JSON
-                "Resource": "arn:aws:s3:::bucket-name"
+          "Resource": "arn:aws:s3:::amzn-s3-demo-bucket",
+          "Condition": {
+            "StringEquals": {
+              "aws:SourceAccount": "111122223333"
+            }
+          }
@@ -154,5 +162 @@ For example, the following bucket policy allows AWS accounts `111122223333` and
-JSON
-    
-
-****
-    
+###### Example – Bucket policy for multiple account log delivery
@@ -167 +171,3 @@ JSON
-                "Principal": {"Service": "delivery.logs.amazonaws.com"},
+          "Principal": {
+            "Service": "delivery.logs.amazonaws.com"
+          },
@@ -170,2 +176,2 @@ JSON
-                	"arn:aws:s3:::amzn-s3-demo-bucket:/flow-logs/AWSLogs/111122223333/",
-                	"arn:aws:s3:::amzn-s3-demo-bucket:/flow-logs/AWSLogs/444455556666/"
+            "arn:aws:s3:::amzn-s3-demo-bucket/flow-logs/AWSLogs/111122223333/*",
+            "arn:aws:s3:::amzn-s3-demo-bucket/flow-logs/AWSLogs/444455556666/*"
@@ -173 +179,9 @@ JSON
-                "Condition": {"StringEquals": {"s3:x-amz-acl": "bucket-owner-full-control"}}
+          "Condition": {
+            "StringEquals": {
+              "s3:x-amz-acl": "bucket-owner-full-control",
+              "aws:SourceAccount": [
+                "111122223333",
+                "444455556666"
+              ]
+            }
+          }
@@ -178 +192,3 @@ JSON
-                "Principal": {"Service": "delivery.logs.amazonaws.com"},
+          "Principal": {
+            "Service": "delivery.logs.amazonaws.com"
+          },
@@ -180 +196,9 @@ JSON
-                "Resource": "arn:aws:s3:::amzn-s3-demo-bucket"
+          "Resource": "arn:aws:s3:::amzn-s3-demo-bucket",
+          "Condition": {
+            "StringEquals": {
+              "aws:SourceAccount": [
+                "111122223333",
+                "444455556666"
+              ]
+            }
+          }