AWS Builder Center

Fifteen minutes after getting a public IP, someone was already knocking

I turned on VPC Flow Logs for a practice instance, sent them to S3 and queried them with Athena. Random hosts were trying SSH, RDP and database ports almost immediately.

Everybody says anything with a public IP gets scanned almost immediately. I believed it, but I wanted to see it with my own data. So I launched a small instance with a public IP in a practice VPC, with the security group only allowing SSH from my own IP, and turned on VPC Flow Logs  delivered to S3.
For querying, the VPC console has an option to generate a CloudFormation template for Athena integration for a flow log. It creates the Athena table, partitions included, over the logs in S3. That saved me from writing the table definition myself, which I'm fairly sure I would have gotten wrong the first time.
The first query I ran:
```sql
SELECT srcaddr, dstport, action, count(*) AS attempts
FROM vpc_flow_logs
WHERE action = 'REJECT'
GROUP BY srcaddr, dstport, action
ORDER BY attempts DESC
LIMIT 20;
```
About fifteen minutes after the instance got its public IP, there were already rejected connection attempts on port 22 from addresses I had never seen. By the next morning there were attempts on 3389 (RDP), 23 (Telnet) and a few common database ports too, on a Linux instance with nothing listening on any of them. Every one of them was REJECT, because the security group only allowed SSH from my IP.
A few things I took away. Security groups are doing real work all the time, and seeing thousands of rejected rows in a table makes that very concrete. Flow logs only show metadata, meaning addresses, ports, bytes and accept or reject, not what was inside the packets. And partitions matter for cost: querying one day's partition instead of the whole table keeps the amount of data Athena scans small.
Afterward I moved the instance into a private subnet with Session Manager access. Its flow logs are extremely boring now, which is exactly what I want.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article