AWS Security Hub is a centralized security service that provides a
comprehensive view of security findings and alerts from various AWS services
and third-party integrations. It enables organizations to quickly identify and
address security issues, enhancing their security posture and compliance
capabilities.
AWS Security Hub integration is a convenient functionality that allows you to effortlessly
receive notifications based on specific triggers or events. These alerts can be
customized based on risk scores, findings, and other parameters such as publicly
exposed resources, sensitive data, or administrative privileges.
This outbound integration can be easily configured within the Plerion Platform for seamless implementation.
Note: AWS Security Hub integration is one-way only, meaning that alerts created or updated in Plerion will be reflected in Security Hub, but changes made directly to Security Hub findings will not be synced back to Plerion.
The alerts generated by our platform are tailored to the user-configured workflow.
These alerts are then directed to AWS Lambda via Amazon EventBridge and Amazon SQS. Within Lambda,
a batch of alerts is processed, ensuring their validity before dispatching them to
AWS Security Hub as findings in the ASFF format. The delivery status and state of
alerts are tracked and stored in a database, with the system checking the alert delivery
status prior to dispatching any alerts. Any failed scans are saved in a Dead-Letter
Queue (DLQ) which is checked for any formatting errors and resubmitted to the Lambda
function for processing after fixing the issue.
What is the duration between the creation of a finding in your product and
its transmission to AWS Security Hub?
Our platform takes around 2-3 minutes to deliver findings to AWS Security Hub.
Which categories of findings are sent to AWS Security Hub?
This depends on the workflow configured by the user. For e.g. If a user has
configured a workflow to send findings when an asset is discovered to be
publicly exposed, then only those findings will be sent to AWS Security Hub.
How is the Plerion risk score mapped to the ASFF severity label?
The Plerion risk score is mapped to the ASFF severity label as follows:
Risk Score
ASFF Severity Label
0.0
INFORMATIONAL
0.1 - 3.999
LOW
4.0 - 6.999
MEDIUM
7.0 - 8.999
HIGH
9.0 - 10.0
CRITICAL
How is an alert mapped to the ASFF (AWS Security Finding Format)
format?
Alerts from Plerion are mapped to the ASFF (AWS Security Finding Format)
format as follows: