Fix EKS anonymous API health check filter to cover all RFC 1918 - #2065
Conversation
The ELB health-check noise filter in Amazon.EKS.AnonymousAPIAccess only matched source IPs starting with `10.0.`, so it missed health checks from clusters whose VPC CIDR sits elsewhere in 10.0.0.0/8, or in 172.16.0.0/12 or 192.168.0.0/16. Use ipaddress.ip_network to cover the full RFC 1918 space and add unit tests for each range plus a public-IP positive case. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
PR SummaryMedium Risk Overview New rule tests cover ELB health checks from 10.128.x.x, 172.16.0.0/12, and 192.168.0.0/16 (expected no alert) and from a public IP (still expected to alert). Reviewed by Cursor Bugbot for commit 74ecb14. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
@flip-z why not use the .is_private or .is_public method like |
Per review feedback, simplify the EKS anonymous API health-check filter by using Python's built-in is_private property rather than maintaining a hand-rolled RFC1918 network list. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Oh nice, didn't know that existed. Updated |
Summary
Amazon.EKS.AnonymousAPIAccessonly suppressedELB-HealthChecker/2.0events when the source IP started with10.0., so clusters with VPC CIDRs elsewhere in 10.0.0.0/8 (e.g. 10.128.x.x) or in 172.16.0.0/12 / 192.168.0.0/16 still produced noisy anonymous-access alerts on health checks.startswith("10.0.")prefix check with a properipaddress-based RFC 1918 membership test (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).Context: the original
10.0.filter was added in #1433 as noise-tuning based on a lab cluster whose VPC happened to live in 10.0.x.x — there's no commit/PR comment suggesting the narrow prefix was intentional, so this broadens the filter to its intended scope.Test plan
make fmtmake lint(rule scores 10/10; the unrelated pre-existingdata_models_test.pypylint error is untouched)pipenv run panther_analysis_tool test --path rules/aws_eks_rules/ --filter RuleID=Amazon.EKS.AnonymousAPIAccess— all 8 cases pass, including the 3 new RFC 1918 suppression tests and the new public-IP positive case🤖 Generated with Claude Code