Amazon Web Services (AWS) announced the public preview of its new Amazon CodeGuru Security, the enhancement of its zero-trust offerings and the general availability of Amazon Security Lake at this week’s AWS re:Inforce event.

One of the major topics at this year’s event is artificial intelligence (AI) and machine learning (ML)-powered security service. And its latest announcement is the Amazon CodeGuru Security, which is a static application security tool that detects security policy violations and vulnerabilities, provides recommendations for addressing security risks and generates metrics of security health.

“This newest service in our AppSec tool chain integrates with IDEs [integrated development environments] and the CI/CD [continuous integration/continuous delivery] pipelines, and uses ML and automated reasoning to help you build more secure code by detecting vulnerabilities in your code at any stage of the development lifecycle,” AWS CISO CJ Moses explained, adding its enhanced algorithms help engineering and InfoSec teams save time by reducing false positives.

Moses also said generative AI and large language models (LLMs) can have a significant impact on security teams by enhancing and complementing existing tools and processes, while taking care of lower-level tasks. “For example, we can train generative AI models to create threat-hunting queries, summarize the event data from an attack, write a remediation code for vulnerabilities [and] write penetration test scripts to automate the creation of YARA rules for malware detection.”

On the other hand, generative AI can make it easier for threat actors that don't have deep experience to create malicious code. “Even though these tools may be used to generate more sophisticated and accurate phishing emails, the way we protect our users against them shouldn't and doesn't need to really change,” he added.

AWS doubles down on zero trust

AWS has been supporting the zero-trust approach for over a decade, including its combination of identity and network signals deeply integrated into AWS Identity and Access Management (IAM) and Amazon Virtual Private Cloud, noted senior principal engineer Becky Weiss, adding that its IAM service right now is handling over 1 billion AWS API calls per second worldwide.

“In a zero-trust architecture, it's not just a network perimeter that's evaluated once upon entry. Rather, it's a combination of identity, network, devices and other increasingly sophisticated factors that get evaluated, ideally on each and every access,” she said during her keynote at the event.

Now AWS is building the next chapter of its zero-trust journey with the launch of AWS Verified Access and Amazon Verified Permissions, both introduced in preview at last year’s AWS re:Invent event.

AWS Verified Access is the vendor’s VPN-less, zero-trust network access (ZTNA)-like secure connectivity service. It is designed to deliver customers secure access to corporate applications running on AWS without the need for a VPN while, at the same time, enforcing zero-trust principles.

And Amazon Verified Permissions is a service that enables customers to implement and enforce fine-grained permissions for their applications. This service utilizes Cedar — an open-source policy language — to define a schema for an authorization model, enabling granular permission controls and aiding compliance audits. Users can then connect their applications to Amazon Verified Permissions through AWS software development kits (SDKs) to authorize access requests.

Amazon Security Lake

Additionally, Moses underscored the significance of Amazon Security Lake. Launched last month, the service is designed to automatically centralize users’ security data from on-premises, AWS and other cloud providers, and third-party sources into a purpose-built data lake in their AWS account to enable faster security actions.

The service builds the security data lake using Amazon Simple Storage Service (Amazon S3) and AWS Lake Formation. It collects, combines and analyzes security data from more than 80 sources, including Amazon VPC Flow Logs and AWS CloudTrail, plus third-party sources like Splunk, CrowdStrike, Datadog and Cribl, making it easier for security teams to detect threats and respond to security events faster.

“Customers want the centralized security data from the cloud, on-premises and custom sources to gain better visibility and insights — which is difficult with all the different login formats,” Moses said.

He touted the data lake “enables customers to centrally aggregate, manage and derive value from the security-related logs and event data.” And now more than 50 partners already integrate with the Amazon Security Lake “to store and provide security analytics.”