48 sessions
- Builders' session300 - AdvancedNetwork and Infrastructure SecurityTuesday, Jun 1712:00 p.m. Tuesday, Jun 17You can now privately access Amazon VPC resources, including load balancers and Amazon EC2 instances, and restrict these resources to be only accessed via Amazon CloudFront distribution through a new feature in CloudFront. In this builders' session, we will set up a website located in a private subnet and access it via a CloudFront distribution. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Code talk300 - AdvancedNetwork and Infrastructure SecurityZero TrustCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAmazon Virtual Private Cloud (Amazon VPC)Amazon VPC LatticeAWS Identity and Access Management (IAM)Cross-Industry SolutionsTuesday, Jun 171:00 p.m. Tuesday, Jun 17Join us for a session exploring Amazon VPC Lattice's security capabilities and fine-grained access controls. We'll explore authentication mechanisms, authorization policies, and service-level permissions that enable precise control over network traffic between services. You'll learn how to leverage authorization policies in VPC Lattice to create layered security controls, and see practical examples of implementing Zero Trust principles within your application network. The session will cover best practices for auditing and monitoring service-to-service communications, managing cross-account access, and implementing security patterns for microservices architectures.Session Type: Code talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Code talk300 - AdvancedNetwork and Infrastructure SecurityZero TrustCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAmazon Virtual Private Cloud (Amazon VPC)Amazon VPC LatticeAWS Identity and Access Management (IAM)Cross-Industry SolutionsWednesday, Jun 181:00 p.m. Wednesday, Jun 18Join us for a session exploring Amazon VPC Lattice's security capabilities and fine-grained access controls. We'll explore authentication mechanisms, authorization policies, and service-level permissions that enable precise control over network traffic between services. You'll learn how to leverage authorization policies in VPC Lattice to create layered security controls, and see practical examples of implementing Zero Trust principles within your application network. The session will cover best practices for auditing and monitoring service-to-service communications, managing cross-account access, and implementing security patterns for microservices architectures.Session Type: Code talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Breakout session300 - AdvancedNetwork and Infrastructure SecurityWednesday, Jun 184:00 p.m. Wednesday, Jun 18Starting with core security principles, this session demonstrates how to build robust network security architectures in AWS. Learn to establish effective network isolation boundaries using AWS Cloud WAN and AWS PrivateLink, followed by implementing traffic filtering through strategic firewall deployments. We'll compare centralized versus distributed inspection architectures, culminating in how AWS Cloud WAN's service insertion and policy-based approach enables global-scale centralized inspection flows. Through practical scenarios, attendees will master designing scalable network security architectures that maintain security posture across complex cloud environments. Ideal for security engineers and architects managing enterprise-scale AWS deployments.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Breakout session200 - IntermediateNetwork and Infrastructure SecurityNewly announced contentThreat IntelligenceCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAWS Transit GatewayCross-Industry SolutionsFinancial Services8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18This technical session covers recent AWS Network Firewall enhancements that help improve traffic inspection and management. Learn about active threat defense with AWS threat intelligence, native Transit Gateway integration, automated domain lists, and multiple VPC endpoints, and more. Explore implementation patterns and operational best practices to help maintain consistent security controls while simplifying deployment.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Network and Infrastructure Security
- Builders' session200 - IntermediateNetwork and Infrastructure SecurityMonday, Jun 1610:00 a.m. Monday, Jun 16Effective network security requires comprehensive visibility into your security posture and traffic patterns. This hands-on session demonstrates how to build and customize Amazon CloudWatch dashboards for real-time insights into AWS Network Firewall operations. Learn to visualize critical metrics including dropped packets, traffic patterns, and potential threats. We'll explore creating dynamic widgets to track stateful rule matches, analyze top talkers, and identify suspicious patterns. Through step-by-step guidance, discover how to monitor bandwidth utilization, track rule effectiveness, and create custom alarms. Leave with ready-to-implement templates for enhancing your security operations. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 200 - IntermediateTrack: Network and Infrastructure Security
- Chalk talk300 - AdvancedNetwork and Infrastructure SecurityResilienceMigrationTuesday, Jun 173:00 p.m. Tuesday, Jun 17Strong adherence to architecture best practices and proactive controls are the foundation of web application security. These techniques allow developers to build applications that are more resilient. In this chalk talk, learn how to build a layered network security approach to achieve defense-in-depth; to protect, detect, and respond to issues faster; and to accelerate your secure migrations to AWS. Discover key considerations, best practices, and reference architectures that include Amazon VPC, Amazon Route 53, Amazon CloudFront, AWS WAF, AWS Shield, Application Load Balancer, and AWS Elastic Disaster Recovery to achieve your defense-in-depth objectives.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Chalk talk300 - AdvancedNetwork and Infrastructure SecurityResilienceMigration10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Strong adherence to architecture best practices and proactive controls are the foundation of web application security. These techniques allow developers to build applications that are more resilient. In this chalk talk, learn how to build a layered network security approach to achieve defense-in-depth; to protect, detect, and respond to issues faster; and to accelerate your secure migrations to AWS. Discover key considerations, best practices, and reference architectures that include Amazon VPC, Amazon Route 53, Amazon CloudFront, AWS WAF, AWS Shield, Application Load Balancer, and AWS Elastic Disaster Recovery to achieve your defense-in-depth objectives.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- MeetupNetwork and Infrastructure SecurityAutomationZero TrustWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Modern cloud architectures require sophisticated network security controls that can scale automatically. This meetup can explore strategies for implementing Zero Trust networking principles using AWS services. Attendees can engage in discussions around microsegmentation, identity-aware access controls, and automated policy enforcement. Topics may include defense-in-depth architectures, security automation, and operational best practices. Share experiences and learn from peers about building secure, scalable network infrastructure.Session Type: MeetupTrack: Network and Infrastructure Security
- MeetupNetwork and Infrastructure SecurityAutomationZero Trust2:00 p.m. Monday, Jun 16Monday, Jun 16Modern cloud architectures require sophisticated network security controls that can scale automatically. This meetup can explore strategies for implementing Zero Trust networking principles using AWS services. Attendees can engage in discussions around microsegmentation, identity-aware access controls, and automated policy enforcement. Topics may include defense-in-depth architectures, security automation, and operational best practices. Share experiences and learn from peers about building secure, scalable network infrastructure.Session Type: MeetupTrack: Network and Infrastructure Security
- Workshop300 - AdvancedNetwork and Infrastructure SecurityCloud Security SpecialistSolution / Systems ArchitectAWS Cloud WANAWS Network FirewallAWS Site-to-Site VPNWednesday, Jun 1812:00 p.m. Wednesday, Jun 18In this hands-on workshop, learn to build secure global hybrid networks using AWS Cloud WAN and AWS Network Firewall. Design and establish hybrid connectivity between your global network and on-premises environments. Configure AWS Network Firewall to implement comprehensive traffic inspection for both east-west (VPC to VPC) and north-south (internet egress and on-premises) traffic flows. After completing this workshop, you will have practical experience designing scalable, secure, and well-architected global hybrid network architectures. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Workshop300 - AdvancedNetwork and Infrastructure SecurityCloud Security SpecialistSolution / Systems ArchitectAWS Cloud WANAWS Network FirewallAWS Site-to-Site VPNMonday, Jun 1610:00 a.m. Monday, Jun 16In this hands-on workshop, learn to build secure global hybrid networks using AWS Cloud WAN and AWS Network Firewall. Design and establish hybrid connectivity between your global network and on-premises environments. Configure AWS Network Firewall to implement comprehensive traffic inspection for both east-west (VPC to VPC) and north-south (internet egress and on-premises) traffic flows. After completing this workshop, you will have practical experience designing scalable, secure, and well-architected global hybrid network architectures. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Chalk talk300 - AdvancedNetwork and Infrastructure SecurityDeveloper / EngineerDevOps EngineerSolution / Systems ArchitectAmazon VPC LatticeAWS PrivateLinkCross-Industry SolutionsWednesday, Jun 181:00 p.m. Wednesday, Jun 18In this chalk talk, we review the best practices and reference architectures for building secure connectivity with Amazon VPC Lattice and AWS PrivateLink. We focus on service and resource oriented connectivity as we dive into the new VPC Lattice capabilities, such as support for VPC Resources and service network endpoints, and cross-Region support for AWS PrivateLink.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Chalk talk300 - AdvancedNetwork and Infrastructure SecurityDeveloper / EngineerDevOps EngineerSolution / Systems ArchitectAmazon VPC LatticeAWS PrivateLinkCross-Industry Solutions2:00 p.m. Monday, Jun 16Monday, Jun 16In this chalk talk, we review the best practices and reference architectures for building secure connectivity with Amazon VPC Lattice and AWS PrivateLink. We focus on service and resource oriented connectivity as we dive into the new VPC Lattice capabilities, such as support for VPC Resources and service network endpoints, and cross-Region support for AWS PrivateLink.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Chalk talk400 - ExpertNetwork and Infrastructure SecurityCloud Security SpecialistDeveloper / EngineerIT Professional / Technical ManagerAmazon DetectiveAmazon Virtual Private Cloud (Amazon VPC)AWS Network FirewallCross-Industry SolutionsWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Organizations struggle to maintain comprehensive network visibility in complex cloud environments. This session demonstrates how to implement advanced network monitoring and analysis using AWS's native services. Learn to leverage VPC Flow Logs, AWS Network Firewall Logs, Route 53 Resolver Logs, WAF Logs and other data sources for traffic analysis. Discover practical implementation of tools for enhanced security and real-time monitoring. Walk away with reference architectures and best practices for building robust network visibility solutions that scale across your AWS environment while maintaining performance. Perfect for security teams modernizing their network defense strategy.Session Type: Chalk talkLevel: 400 - ExpertTrack: Network and Infrastructure Security
- Lightning talk100 - FoundationalNetwork and Infrastructure SecurityResilienceZero TrustThreat IntelligenceIT ExecutiveIT Professional / Technical ManagerAmazon Security LakeAWS Security HubAutomotiveHealthcare & Life SciencesManufacturing & IndustrialTuesday, Jun 174:00 p.m. Tuesday, Jun 17Cyber-physical systems (CPS) such as operational technology, IoT devices, and building management systems are becoming increasingly connected to enterprise IT networks and the internet. Driven by growing demand for remote access and real-time data, this interconnectivity delivers numerous business benefits - from efficiency, to innovation, to sustainability - yet also increases these critical systems' exposure to cyber threats. Join us as we examine the evolving CPS threat landscape, IT/OT convergence and explore specialized solutions for protecting the mission-critical infrastructure powered by CPS. This presentation is brought to you by Claroty, an AWS Partner.Session Type: Lightning talkLevel: 100 - FoundationalTrack: Network and Infrastructure Security
- Chalk talk300 - AdvancedNetwork and Infrastructure SecurityZero TrustCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAmazon Verified PermissionsAmazon VPC LatticeAWS Verified AccessCross-Industry Solutions8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Traditional perimeter-based security and network segmentation often fall short in today's dynamic microservices environments, creating operational overhead and potential security gaps. Join us in this session to discuss how to evolve beyond conventional security models by implementing Zero Trust architecture in AWS. We will cover different services and techniques such as AWS Verified Access in the human-to-application connectivity, Amazon VPC Lattice for service-to-service communication, and the use of AWS Verified Permissions for fine-grained application authorization. We'll explore how these services can work together to enable continuous authentication.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Chalk talk300 - AdvancedNetwork and Infrastructure SecurityZero TrustCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAmazon Verified PermissionsAmazon VPC LatticeAWS Verified AccessCross-Industry Solutions11:00 a.m. Monday, Jun 16Monday, Jun 16Traditional perimeter-based security and network segmentation often fall short in today's dynamic microservices environments, creating operational overhead and potential security gaps. Join us in this session to discuss how to evolve beyond conventional security models by implementing Zero Trust architecture in AWS. We will cover different services and techniques such as AWS Verified Access in the human-to-application connectivity, Amazon VPC Lattice for service-to-service communication, and the use of AWS Verified Permissions for fine-grained application authorization. We'll explore how these services can work together to enable continuous authentication.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Chalk talk200 - IntermediateNetwork and Infrastructure Security4:00 p.m. Monday, Jun 16Monday, Jun 16In this thrilling session, we'll build a robust protection setup using AWS WAF and Amazon CloudFront, demonstrating how to fend off increasingly sophisticated live attacks. Learn to leverage CloudFront, configure rate-based rules, implement WAF Managed Rule groups, bot control, and create custom defenses. As we construct our digital fortress, our resident "black hat" will launch progressively complex events, showcasing how each layer of defense performs under pressure. Suitable for both newcomers and experienced AWS security professionals.Session Type: Chalk talkLevel: 200 - IntermediateTrack: Network and Infrastructure Security
- Chalk talk200 - IntermediateNetwork and Infrastructure SecurityWednesday, Jun 184:00 p.m. Wednesday, Jun 18In this thrilling session, we'll build a robust protection setup using AWS WAF and Amazon CloudFront, demonstrating how to fend off increasingly sophisticated live attacks. Learn to leverage CloudFront, configure rate-based rules, implement WAF Managed Rule groups, bot control, and create custom defenses. As we construct our digital fortress, our resident "black hat" will launch progressively complex events, showcasing how each layer of defense performs under pressure. Suitable for both newcomers and experienced AWS security professionals.Session Type: Chalk talkLevel: 200 - IntermediateTrack: Network and Infrastructure Security
- Breakout session300 - AdvancedNetwork and Infrastructure SecurityWednesday, Jun 181:00 p.m. Wednesday, Jun 18Learn how Itaú, Latin America's largest bank, uses AWS Shield Advanced to protect their critical financial infrastructure from sophisticated DDoS events. In this session, Itaú's security team shares how they architected their defense strategy by integrating Shield Advanced with existing security operations and collaborating with the AWS DDoS Response Team. Discover how they maintain robust protection while meeting financial regulatory requirements and examine the business value of their implementation. Whether you work in financial services or other regulated industries, you'll gain actionable insights for enterprise-grade DDoS protection.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Lightning talk300 - AdvancedNetwork and Infrastructure Security1:00 p.m. Monday, Jun 16Monday, Jun 16Meta envisions 2025 as the breakthrough year for its leading AI assistant, aiming to reach over 1 billion people with highly intelligent and personalized interactions. Partnering with AWS, Meta has made substantial investments in AI infrastructure, providing its developers with specialized compute resources for AI training. To secure this ambitious initiative, Meta has had to evolve not just their cloud security but also culture and mindset to secure a growing AWS footprint/infrastructure. Meta leverages AWS Network Firewall (ANF) to centrally inspect and filter VPC traffic before reaching external destinations, using rule-based filtering to control domain access, block malicious IPs, and prevent data exfiltration.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Lightning talk300 - AdvancedNetwork and Infrastructure SecurityTuesday, Jun 171:00 p.m. Tuesday, Jun 17This lightning talk will uncover powerful yet often-overlooked capabilities that can transform your network security game. In just 20 minutes, we'll speed through eye-opening features that even experienced practitioners might have missed. From stateful traffic manipulation to sophisticated protocol inspection and real-world architectural patterns, you'll discover practical techniques to leverage AWS Network Firewall's full potential. Whether you're managing complex multi-account deployments or hunting for advanced threats, this rapid-fire session will equip you with new tools for your security arsenal.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Breakout session300 - AdvancedNetwork and Infrastructure SecurityZero TrustMigration8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18In this session, learn how to adopt Zero Trust alongside traditional network security functions such as firewalls and VPNs. Explore how services like Amazon VPC Lattice and AWS Verified Access complement your existing network security posture by leveraging identity and network controls to continuously authenticate and monitor access. and how these services can integrate into your existing network architecture. Learn about common adoption approaches and migration patterns, and hear best practices for building Zero Trust mechanisms into a secure, modern network architecture.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Builders' session200 - IntermediateNetwork and Infrastructure Security1:00 p.m. Monday, Jun 16Monday, Jun 16Join this interactive workshop to explore Amazon VPC Block Public Access, a feature designed for secure, scalable cloud environments. Learn to block ingress and egress traffic, enforce compliance, and configure granular exclusions for public and private subnets, with a focus on both IPv4 and IPv6 traffic. Through practical labs, you'll enable Block Public Access, create exclusions, and use Reachability Analyzer to test connectivity before and after enabling the feature. By the end, you'll be equipped to secure VPCs effectively while maintaining flexibility for modern workloads. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 200 - IntermediateTrack: Network and Infrastructure Security
- Breakout session300 - AdvancedNetwork and Infrastructure SecurityAmazon Route 53AWS Network FirewallFinancial ServicesTuesday, Jun 1712:00 p.m. Tuesday, Jun 17Discover the latest AWS Network Firewall features that simplify implementation and enhance your security posture against ransomware and malware attacks. Learn how recent updates to AWS Network Firewall and Amazon Route 53 Resolver DNS Firewall streamline deployment, simplify your egress controls, reduce threat exposure, and strengthen security policies. We’ll share practical recommendations for configuring firewall rules that match your specific use cases and help verify that your security controls meet intended objectives.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Lightning talk100 - FoundationalNetwork and Infrastructure SecurityGenerative AIContainer/Serverless SecuritySupply Chain SecurityCloud Security SpecialistDeveloper / EngineerIT AdministratorCross-Industry SolutionsSoftware & Internet5:00 p.m. Monday, Jun 16Monday, Jun 16AI workloads bring new security challenges, but we don’t have to build from scratch. Learn how to build AI model development pipelines with security practices and open source tooling for the entire software development lifecycle. Attendees will learn to adopt existing workflows and security practices developed over the last 15 years to safely build, deploy, and run AI models in their environments. This presentation is brought to you by Red Hat, an AWS Partner.Session Type: Lightning talkLevel: 100 - FoundationalTrack: Network and Infrastructure Security
- Lightning talk100 - FoundationalNetwork and Infrastructure SecurityThreat IntelligenceCloud Security SpecialistIT ExecutiveIT Professional / Technical ManagerAmazon GuardDutyAWS MarketplaceAWS Security HubCross-Industry Solutions2:00 p.m. Tuesday, Jun 17Tuesday, Jun 17Armis Centrix is the ultimate solution for proactive cyber exposure management, offering a frictionless, cloud-based platform that secures your organization’s critical assets 24/7 and in real time. Available on AWS Marketplace, learn how you can seamlessly integrate Armis with your existing security ecosystem, as it identifies and mitigates risks, remediates vulnerabilities, and safeguards your entire attack surface. Discover how Armis Centrix delivers unmatched peace of mind, ensuring comprehensive asset protection without disrupting your operations. Listen to how customers trust the #1 cyber exposure management company to keep their organization secure in today’s rapidly evolving threat landscape. Armis Centrix - modern security for a connected world. This presentation is brought to you by Armis, an AWS Partner.Session Type: Lightning talkLevel: 100 - FoundationalTrack: Network and Infrastructure Security
- Builders' session300 - AdvancedNetwork and Infrastructure SecurityTuesday, Jun 174:00 p.m. Tuesday, Jun 17Suricata is an open-source network intrusion prevention system (IPS) that includes a standard rule-based language for stateful network traffic inspection. AWS Network Firewall lets you define rules to inspect and control traffic to and from your VPC using IP, port, protocol, domain names, and general pattern matches. Building rules, in this format, for your security needs can be challenging but rewarding. During this session you will learn how you can utilize Suricata-compatible rules in AWS Network Firewall and build rulesets for common use cases as well as complex scenarios. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Builders' session300 - AdvancedNetwork and Infrastructure Security4:00 p.m. Monday, Jun 16Monday, Jun 16Suricata is an open-source network intrusion prevention system (IPS) that includes a standard rule-based language for stateful network traffic inspection. AWS Network Firewall lets you define rules to inspect and control traffic to and from your VPC using IP, port, protocol, domain names, and general pattern matches. Building rules, in this format, for your security needs can be challenging but rewarding. During this session you will learn how you can utilize Suricata-compatible rules in AWS Network Firewall and build rulesets for common use cases as well as complex scenarios. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Workshop300 - AdvancedNetwork and Infrastructure SecuritySupply Chain Security3:00 p.m. Wednesday, Jun 18Wednesday, Jun 18In this practical workshop, you will learn how to leverage AWS security services like AWS Network Firewall, Amazon Route 53 Resolver DNS Firewall, and AWS Firewall Manager to implement comprehensive egress controls. Attendees will gain the knowledge to effectively mitigate risks from software supply chain attacks, zero-day exploits, cryptocurrency mining, and ransomware. The session will showcase real-world use cases and provide step-by-step guidance on deploying these solutions to help strengthen your AWS environment's security posture. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Workshop300 - AdvancedNetwork and Infrastructure SecuritySupply Chain Security1:00 p.m. Monday, Jun 16Monday, Jun 16In this practical workshop, you will learn how to leverage AWS security services like AWS Network Firewall, Amazon Route 53 Resolver DNS Firewall, and AWS Firewall Manager to implement comprehensive egress controls. Attendees will gain the knowledge to effectively mitigate risks from software supply chain attacks, zero-day exploits, cryptocurrency mining, and ransomware. The session will showcase real-world use cases and provide step-by-step guidance on deploying these solutions to help strengthen your AWS environment's security posture. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Breakout session300 - AdvancedNetwork and Infrastructure SecurityAWS Network FirewallTuesday, Jun 171:00 p.m. Tuesday, Jun 17AWS customers use multiple security services to build strong network defenses, but visibility into threats, misconfigurations, and vulnerabilities across multi-VPC and multi-account environments can remain a challenge. This session covers AWS network security fundamentals - Security Groups, NACLs, Network Firewall, DNS Firewall, and Gateway Load Balancer - for a layered defense strategy. We will also highlight observability tools like VPC Flow Logs, Reachability Analyzer, and Network Access Analyzer to detect security gaps and troubleshoot access issues. By integrating these tools, organizations can proactively enhance network security, detect vulnerabilities, and ensure secure, scalable architectures across AWS accounts and environments.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Breakout session200 - IntermediateNetwork and Infrastructure SecurityNewly announced contentCulture of SecurityAmazon CloudFrontAWS WAFWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Transform your web security management with AWS WAF's new simplified experience. This streamlined experience extends to Amazon CloudFront, offering unified configuration for comprehensive protection. Our intuitive single-page workflow and expert-curated protection packs enables rapid protection implementation across your web applications, APIs, and Amazon CloudFront distributions. From day one, gain expert-level guidance on optimal security configurations through our unified dashboard. Get clear visibility, actionable insights, and automated recommendations for continuous improvement of your security posture. This innovative approach helps to ensure robust protection against evolving threats while reducing web application security configuration steps by up to 80%. Amazon CloudFront developers can now leverage the same simplified experience to secure their distributions efficiently.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Network and Infrastructure Security
- Code talk300 - AdvancedNetwork and Infrastructure Security1:00 p.m. Monday, Jun 16Monday, Jun 16Discover how to transform AWS WAF into a powerful threat intelligence platform by building sophisticated honeypots that attract, analyze, and adapt to emerging threats. In this code talk, we'll demonstrate how to combine AWS WAF with AWS Lambda functions to create intelligent traps that not only capture malicious activity but also generate actionable security insights. Through live coding demonstrations, you'll learn to implement advanced honeypot techniques including dynamic bait generation, automated attacker profiling, and real-time threat pattern analysis.Session Type: Code talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Code talk300 - AdvancedNetwork and Infrastructure SecurityTuesday, Jun 173:00 p.m. Tuesday, Jun 17Discover how to transform AWS WAF into a powerful threat intelligence platform by building sophisticated honeypots that attract, analyze, and adapt to emerging threats. In this code talk, we'll demonstrate how to combine AWS WAF with AWS Lambda functions to create intelligent traps that not only capture malicious activity but also generate actionable security insights. Through live coding demonstrations, you'll learn to implement advanced honeypot techniques including dynamic bait generation, automated attacker profiling, and real-time threat pattern analysis.Session Type: Code talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Builders' session300 - AdvancedNetwork and Infrastructure Security10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Amazon Route 53 Profile is an innovative feature of Route 53 that enables the effortless sharing of hosted zones, resolver rules, and DNS firewall rules across multiple VPCs. This builders' session will guide you through the process of creating Route 53 profiles and demonstrate how to restrict access using various features tailored to your specific needs, such as different environments. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Lightning talk300 - AdvancedNetwork and Infrastructure SecurityWell-Architected FrameworkDevSecOpsThreat IntelligenceCloud Security SpecialistSolution / Systems ArchitectAmazon Simple Storage Service (Amazon S3)AWS Cloud WANAWS Network FirewallGamesMedia & EntertainmentSoftware & InternetWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Securing and managing network traffic efficiently is crucial for modern cloud architectures. AWS Cloud WAN, combined with Network Firewall and Route 53 DNS Firewall, provides a robust framework for protecting both egress and east-west traffic. This presentation explores how these security services enhance resilience, prevent threats, and enforce compliance across distributed environments. By integrating firewall policies and DNS security, organizations can strengthen their cloud infrastructure against cyber threats while maintaining optimal performance. Learn how to build a secure, scalable, and resilient network with AWS’s advanced security solutions.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Breakout session200 - IntermediateNetwork and Infrastructure SecurityNewly announced contentCulture of SecurityCloud Security SpecialistAWS Shield10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18AWS Shield has expanded its capabilities to provide network security analysis with AWS Shield network security director, combining DDoS protection with proactive identification of network configuration issues. This new capability provides visibility into your network topology, identifies AWS network service configurations that don’t adhere to AWS best practices, and provides actionable recommendations to improve security posture. Combined with existing AWS Shield DDoS protection, customers can address both immediate threats and potential risks through a unified service. Learn how AWS Shield's new capabilities work, including network security analysis, visualization of security issues, and step-by-step remediation recommendations. Discover best practices for strengthening your AWS environment's overall security resilience using these new features.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Network and Infrastructure Security
- Breakout session300 - AdvancedNetwork and Infrastructure Security8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18In this session, we'll discuss a brave new world where we think beyond traditional firewalling architectures. We'll explore the use-cases that require firewalls including workload-to-workload, client-to-workload, and workload-to-internet traffic flows. After defining the use cases, we'll discuss AWS services that allow customers to retain their desired security posture without inserting inline firewalls. We'll wrap with specific considerations on when firewalling is a good option. For example, for scenarios when customers require AppId-like functionality, or for creating data loss prevention (DLP) deployments for egress traffic.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Builders' session400 - ExpertNetwork and Infrastructure SecurityWednesday, Jun 181:00 p.m. Wednesday, Jun 18Suspicious of an activity spike? Seeing odd traffic patterns? Introduced a new AWS WAF rule and want to make sure it is operating as it should? Join this session for a walkthrough of a day in the life of a security engineer operating AWS WAF, reviewing dashboards, exploring data in the logs, and building new dashboard widgets to make your life easier. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 400 - ExpertTrack: Network and Infrastructure Security
- Builders' session400 - ExpertNetwork and Infrastructure SecurityTuesday, Jun 174:00 p.m. Tuesday, Jun 17Suspicious of an activity spike? Seeing odd traffic patterns? Introduced a new AWS WAF rule and want to make sure it is operating as it should? Join this session for a walkthrough of a day in the life of a security engineer operating AWS WAF, reviewing dashboards, exploring data in the logs, and building new dashboard widgets to make your life easier. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 400 - ExpertTrack: Network and Infrastructure Security
- Builders' session300 - AdvancedNetwork and Infrastructure SecurityGenerative AITuesday, Jun 171:00 p.m. Tuesday, Jun 17When building generative AI applications using Large Language Models on Amazon Bedrock, customers want to generate responses without going over the public internet or without exposing their proprietary data. This builders' session introduces the Amazon Bedrock VPC endpoint, powered by AWS PrivateLink, as a solution for establishing secure and private connections between customer VPCs and Amazon Bedrock services. You'll learn how this technology enables communication without public IP addresses, mitigating potential threat vectors from internet exposure. We'll cover security challenges in generative AI, the architecture of VPC endpoint solution, and hands-on labs for implementation. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Builders' session300 - AdvancedNetwork and Infrastructure SecurityGenerative AIWednesday, Jun 1811:00 a.m. Wednesday, Jun 18When building generative AI applications using Large Language Models on Amazon Bedrock, customers want to generate responses without going over the public internet or without exposing their proprietary data. This builders' session introduces the Amazon Bedrock VPC endpoint, powered by AWS PrivateLink, as a solution for establishing secure and private connections between customer VPCs and Amazon Bedrock services. You'll learn how this technology enables communication without public IP addresses, mitigating potential threat vectors from internet exposure. We'll cover security challenges in generative AI, the architecture of VPC endpoint solution, and hands-on labs for implementation. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Lightning talk400 - ExpertNetwork and Infrastructure Security9:00 a.m. Wednesday, Jun 18Wednesday, Jun 18In hybrid environments where employees need to access AWS private services outside their corporate network, they typically use a VPN. This session demonstrates how to establish secure, VPN-free connectivity to an Amazon FSx for Windows File Server and an Amazon OpenSearch Serverless endpoint using the new TCP protocol support of AWS Verified Access (AVA).Session Type: Lightning talkLevel: 400 - ExpertTrack: Network and Infrastructure Security
- Lightning talk300 - AdvancedNetwork and Infrastructure SecurityWednesday, Jun 1812:00 p.m. Wednesday, Jun 18Drowning in AWS WAF logs? Transform raw security data into actionable insights with Amazon CloudWatch dashboards. In this high-energy session, discover how to build powerful visualizations that expose threats in real-time. We'll cut through the complexity to show you battle-tested patterns for threat detection and alerting that security teams love. Twenty minutes to level up your WAF monitoring game – no fluff, just results.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Workshop300 - AdvancedNetwork and Infrastructure SecurityResilience9:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Learn how to protect your applications from Distributed Denial of Service (DDoS) attacks. In this hands-on workshop, you will learn how to implement protection methodologies for web applications against DDoS events using AWS security services. Practice configuring DDoS resilience patterns and learn how to respond effectively to attacks. This session is ideal for builders who manage web applications, content delivery network (CDN) configurations, web application firewalls (WAF), and security controls. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Network and Infrastructure Security
- Workshop400 - ExpertNetwork and Infrastructure SecurityZero TrustTuesday, Jun 173:00 p.m. Tuesday, Jun 17Build a Zero Trust architecture for service-to-service workloads in this advanced hands-on workshop. Learn to secure your modern serverless applications using Amazon Verified Access (AVA) for remote application access, Amazon Verified Permissions (AVP) for fine-grained access controls, Amazon VPC Lattice for secure service-to-service communication, and AWS WAF for edge security controls. You'll implement these security controls with serverless services including Amazon API Gateway, AWS Lambda, and Amazon DynamoDB. You must bring your laptop to participate.Session Type: WorkshopLevel: 400 - ExpertTrack: Network and Infrastructure Security