AWS network-firewall: Add aws:SourceAccount conditions to Network Firewall S3 log bucket policies
Summary
Rewrites the S3 bucket policy and permissions examples for Network Firewall log delivery, adding aws:SourceAccount conditions, correcting resource ARNs (wildcards, folder paths), and using standard AWSLogDeliveryWrite/AWSLogDeliveryAclCheck Sids.
Security assessment
The added aws:SourceAccount conditions on the delivery.logs.amazonaws.com principal restrict log delivery to specific source accounts, mitigating confused-deputy cross-account write risks; this is security best-practice documentation rather than a fix for a named vulnerability.
Evidence
"aws:SourceAccount": "111122223333"
Diff
diff --git a/network-firewall/latest/developerguide/logging-s3.md b/network-firewall/latest/developerguide/logging-s3.md index dd1237e78..70f3ff9b8 100644 --- a//network-firewall/latest/developerguide/logging-s3.md +++ b//network-firewall/latest/developerguide/logging-s3.md @@ -78,5 +78 @@ You must have the following permissions settings to configure your firewall to s -JSON - - -**** - +###### Example – Permissions policy for sending firewall logs to Amazon S3 @@ -89,10 +85 @@ JSON - "Action": [ - "logs:CreateLogDelivery", - "logs:GetLogDelivery", - "logs:UpdateLogDelivery", - "logs:DeleteLogDelivery", - "logs:ListLogDeliveries" - ], - "Resource": [ - "*" - ], + "Sid": "AWSLogDeliveryWrite", @@ -100 +87,11 @@ JSON - "Sid": "FirewallLogging" + "Principal": { + "Service": "delivery.logs.amazonaws.com" + }, + "Action": "s3:PutObject", + "Resource": "arn:aws:s3:::amzn-s3-demo-bucket/optional-folder/AWSLogs/111122223333/*", + "Condition": { + "StringEquals": { + "s3:x-amz-acl": "bucket-owner-full-control", + "aws:SourceAccount": "111122223333" + } + } @@ -103,9 +100,12 @@ JSON - "Sid": "FirewallLoggingS3", - "Action": [ - "s3:PutBucketPolicy", - "s3:GetBucketPolicy" - ], - "Resource": [ - "arn:aws:s3:::bucket-name" - ], - "Effect": "Allow" + "Sid": "AWSLogDeliveryAclCheck", + "Effect": "Allow", + "Principal": { + "Service": "delivery.logs.amazonaws.com" + }, + "Action": "s3:GetBucketAcl", + "Resource": "arn:aws:s3:::amzn-s3-demo-bucket", + "Condition": { + "StringEquals": { + "aws:SourceAccount": "111122223333" + } + } @@ -121,5 +120 @@ If the user creating the log owns the bucket, the service automatically attaches -JSON - - -**** - +###### Example – Bucket policy for a single account log delivery @@ -134 +129,3 @@ JSON - "Principal": {"Service": "delivery.logs.amazonaws.com"}, + "Principal": { + "Service": "delivery.logs.amazonaws.com" + }, @@ -136,2 +133,7 @@ JSON - "Resource": "arn:aws:s3:::bucket-name/optional-folder/AWSLogs/123456789012/*", - "Condition": {"StringEquals": {"s3:x-amz-acl": "bucket-owner-full-control"}} + "Resource": "arn:aws:s3:::amzn-s3-demo-bucket/AWSLogs/111122223333/*", + "Condition": { + "StringEquals": { + "s3:x-amz-acl": "bucket-owner-full-control", + "aws:SourceAccount": "111122223333" + } + } @@ -142 +144,3 @@ JSON - "Principal": {"Service": "delivery.logs.amazonaws.com"}, + "Principal": { + "Service": "delivery.logs.amazonaws.com" + }, @@ -144 +148,6 @@ JSON - "Resource": "arn:aws:s3:::bucket-name" + "Resource": "arn:aws:s3:::amzn-s3-demo-bucket", + "Condition": { + "StringEquals": { + "aws:SourceAccount": "111122223333" + } + } @@ -154,5 +162 @@ For example, the following bucket policy allows AWS accounts `111122223333` and -JSON - - -**** - +###### Example – Bucket policy for multiple account log delivery @@ -167 +171,3 @@ JSON - "Principal": {"Service": "delivery.logs.amazonaws.com"}, + "Principal": { + "Service": "delivery.logs.amazonaws.com" + }, @@ -170,2 +176,2 @@ JSON - "arn:aws:s3:::amzn-s3-demo-bucket:/flow-logs/AWSLogs/111122223333/", - "arn:aws:s3:::amzn-s3-demo-bucket:/flow-logs/AWSLogs/444455556666/" + "arn:aws:s3:::amzn-s3-demo-bucket/flow-logs/AWSLogs/111122223333/*", + "arn:aws:s3:::amzn-s3-demo-bucket/flow-logs/AWSLogs/444455556666/*" @@ -173 +179,9 @@ JSON - "Condition": {"StringEquals": {"s3:x-amz-acl": "bucket-owner-full-control"}} + "Condition": { + "StringEquals": { + "s3:x-amz-acl": "bucket-owner-full-control", + "aws:SourceAccount": [ + "111122223333", + "444455556666" + ] + } + } @@ -178 +192,3 @@ JSON - "Principal": {"Service": "delivery.logs.amazonaws.com"}, + "Principal": { + "Service": "delivery.logs.amazonaws.com" + }, @@ -180 +196,9 @@ JSON - "Resource": "arn:aws:s3:::amzn-s3-demo-bucket" + "Resource": "arn:aws:s3:::amzn-s3-demo-bucket", + "Condition": { + "StringEquals": { + "aws:SourceAccount": [ + "111122223333", + "444455556666" + ] + } + }