GAMESEC06-BP01 Use tools for detecting and responding to threats to your infrastructure
To continuously monitor for malicious activities and unauthorized
behaviors within your AWS environment, consider
using Amazon GuardDuty
Level of risk exposed if this best practice is not established: High
Implementation guidance
AWS Security Hub CSPM
It's common for bad actors to employ bots to take over accounts
and cheat in
games. WAF
Bot Control
Ransomware is malicious code designed to gain unauthorized access
to systems and datasets and encrypt that data to block access by
legitimate players. After ransomware has locked players out of
their systems and encrypted their sensitive data, cyber criminals
demand a ransom before providing a decryption key to unlock the
data. Organizations can be completely shut down by a malicious
event, incurring significant costs and loss of business
productivity. Refer
to Securing
your AWS Cloud environment from ransomware
Your game may provide players with the ability to contact player
support agents through a call center such
as Amazon
Connect
Finally, conduct penetration testing exercises as part of your
infrastructure protection strategy. Whether you are performing
these assessments in-house or through an AWS Partner, adhere to
the
AWS customer support policies for penetration testing
Implementation steps
-
Use Amazon GuardDuty to monitor account behavior, network activity, and data access patterns for threats, and integrate with Security Hub CSPM for a unified security view.
-
Implement AWS WAF Bot Control to help detect and mitigate bot traffic that can harm resources and player experiences.
-
Conduct penetration testing exercises regularly, adhering to AWS customer support policies, to assess and strengthen your security posture.