

Required AWS Permissions to use CloudFormation, WAF, IAM Policies, S3, Lambda, etc.Configured Elastic Load Balancer with target group routing to LabKey EC2 Instance.Using the AWS WAF as an example, review their documentation here: Deploying a Web Application Firewall (WAF) can protect against the OWASP top 10 vulnerabilities and many malicious bot networks. Fortunately there are some easy and low cost tools to protect against many attacks. Typically motivated by financial extortion, these individuals use DDoS and bot networks to attack victims.

Public-facing LabKey instances are subject to "internet background radiation" by nefarious miscreants who seek to comprise systems to gain access to protected data. The example in this topic uses AWS, but other firewall options can be configured similarly to protect your LabKey Server. This topic outlines the process for deploying an Web Application Firewall (WAF) to protect LabKey instances from DDoS (Distributed Denial of Service) and other malicious attacks.
