Skip to content

Fix EKS anonymous API health check filter to cover all RFC 1918 - #2065

Merged
arielkr256 merged 2 commits into
developfrom
fix-eks-anonymous-api-access-rfc1918
Jun 11, 2026
Merged

arielkr256 merged 2 commits into
developfrom
fix-eks-anonymous-api-access-rfc1918

Conversation

@flip-z

@flip-z flip-z commented May 18, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Amazon.EKS.AnonymousAPIAccess only suppressed ELB-HealthChecker/2.0 events when the source IP started with 10.0., so clusters with VPC CIDRs elsewhere in 10.0.0.0/8 (e.g. 10.128.x.x) or in 172.16.0.0/12 / 192.168.0.0/16 still produced noisy anonymous-access alerts on health checks.
  • Replaced the startswith("10.0.") prefix check with a proper ipaddress-based RFC 1918 membership test (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
  • Added unit tests covering each RFC 1918 range plus a public-IP positive case to lock in the behavior.

Context: the original 10.0. filter was added in #1433 as noise-tuning based on a lab cluster whose VPC happened to live in 10.0.x.x — there's no commit/PR comment suggesting the narrow prefix was intentional, so this broadens the filter to its intended scope.

Test plan

  • make fmt
  • make lint (rule scores 10/10; the unrelated pre-existing data_models_test.py pylint error is untouched)
  • pipenv run panther_analysis_tool test --path rules/aws_eks_rules/ --filter RuleID=Amazon.EKS.AnonymousAPIAccess — all 8 cases pass, including the 3 new RFC 1918 suppression tests and the new public-IP positive case

🤖 Generated with Claude Code

The ELB health-check noise filter in Amazon.EKS.AnonymousAPIAccess only
matched source IPs starting with `10.0.`, so it missed health checks from
clusters whose VPC CIDR sits elsewhere in 10.0.0.0/8, or in 172.16.0.0/12
or 192.168.0.0/16. Use ipaddress.ip_network to cover the full RFC 1918
space and add unit tests for each range plus a public-IP positive case.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@flip-z
flip-z requested a review from a team as a code owner May 18, 2026 19:11
@cursor

cursor Bot commented May 18, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes detection logic for a security rule: wider suppression reduces false positives but could hide rare abuse that mimics ELB health checks from private space.

Overview
The Amazon.EKS.AnonymousAPIAccess rule no longer suppresses ELB-HealthChecker/2.0 events only when the source IP starts with 10.0.; it now skips alerting when that user agent comes from any RFC 1918 private address via ipaddress.ip_address(...).is_private, with invalid IPs falling through to normal anonymous-access logic.

New rule tests cover ELB health checks from 10.128.x.x, 172.16.0.0/12, and 192.168.0.0/16 (expected no alert) and from a public IP (still expected to alert).

Reviewed by Cursor Bugbot for commit 74ecb14. Bugbot is set up for automated code reviews on this repo. Configure here.

@arielkr256

Copy link
Copy Markdown
Contributor

@flip-z why not use the .is_private or .is_public method like

@arielkr256 arielkr256 added the tuning detection tuning label May 19, 2026
Per review feedback, simplify the EKS anonymous API health-check filter
by using Python's built-in is_private property rather than maintaining
a hand-rolled RFC1918 network list.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@flip-z

flip-z commented May 27, 2026 •

Copy link
Copy Markdown
Contributor Author

Oh nice, didn't know that existed. Updated

@arielkr256
arielkr256 added this pull request to the merge queue Jun 11, 2026
Merged via the queue into develop with commit 1530a3f Jun 11, 2026
18 checks passed
@arielkr256
arielkr256 deleted the fix-eks-anonymous-api-access-rfc1918 branch June 11, 2026 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tuning detection tuning

2 participants