Cette page n'est pas encore disponible en français, sa traduction est en cours. Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.
Description
Reduce the probability of a breach by checking EC2 security groups for outbound rules that allow unfettered access to any TCP/UDP ports and restrict access to IP addresses that require this port.
Rationale
Malicious activity, such as denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks, can occur when permitting unfettered outbound access.
Remediation
From the console
Follow the Security group rules docs to learn how to add a security group rule that will restrict access to IP addresses that require a specific port.
From the command line
Run revoke-security-group-egress to remove IP permissions for the selected EC2 security group.