AWS Network Firewall Adds Rule‑Hit‑Count to Spot Dormant Rules and Validate Controls
What Happened — AWS Network Firewall now surfaces a rule‑hit‑count metric for every stateful rule. The count increments each time a rule generates an alert, drop, or reject log entry, letting teams see which rules are actually matching traffic and which sit idle. The feature is enabled by default at no extra firewall charge (storage and query fees still apply).
Why It Matters for Compliance & Audit Readiness
- Unused or redundant firewall rules can constitute a control gap, violating policies that require “least‑privilege” network segmentation (e.g., PCI DSS 4.0, DORA).
- Continuous visibility of rule activity provides auditable evidence that security controls are in effect, simplifying SOC 2 CC6 (System and Communications Protection) testing.
- The built‑in dashboard and export to CloudWatch Logs Insights or Athena enable automated evidence collection for continuous‑compliance programs.
Who Is Affected — Cloud‑infrastructure operators, SaaS providers, and any organization that relies on AWS VPCs for network isolation (finance, healthcare, e‑commerce, etc.).
Recommended Actions
- Map the new rule‑hit‑count metric to your SOC 2 CC6 control‑monitoring procedures.
- Incorporate the “Top Rule Hits” view into your periodic control‑effectiveness reviews and de‑provision any rule with zero hits for a defined period.
- Automate log export to CloudWatch or Athena and retain evidence for the audit window required by your compliance framework.
Technical Notes – The capability applies only to stateful rules (custom and managed groups); stateless rules remain unsupported. Hit counts are generated when a rule logs an alert, drop, or reject action; pass‑only rules must include the alert keyword to be counted. Data is available in all AWS regions except the Middle East (UAE, Bahrain). Source: Help Net Security