Guide | Securing GenAI Apps on AWS with Check Point | Check Point Software
Guide | Securing GenAI Apps on AWS with Check Point
Standing on the shoulders of giants. Decades of experience have provided us with well-established tools and principles to protect clouds and web apps: From Next-Generation Hybrid Mesh Firewalls that protect and segment cloud and on-prem resources, to Web and API Firewalls (WAFs) that protect web-facing applications and exposed API endpoints.
However, with the meteoric rise of Generative AI (GenAI) applications, such as chatbot assistants in internal and external-facing applications, and multi-step/multi-agent agentic flows/systems with access to sensitive data and tools such as web-browsing and code execution, new attack vectors and unique risks have emerged that challenge our established notions of web app security. Additionally, to reduce costs and rapidly adopt the era-defining revolution of GenAI technologies, companies are adopting hybrid cloud deployments, making infrastructure-agnostic IP-free firewalls an absolute necessity for consistent, repeatable security controls. This white paper discusses Check Point’s approach and its new capabilities to address the security risks of GenAI applications by seamlessly extending existing security controls and well-established security practices. Specifically, Check Point’s Hybrid Mesh Firewall with extended cloud-native capabilities, and the Check Point WAF (previously known as CloudGuard WAF), which has been supercharged with specially crafted GenAI security capabilities.
Preface
Why we must secure traffic from packets up to APIs
The proliferation of networks across regions, branches, and on-premises data centers, along with the expansion into an increasing number of private and public cloud providers, as well as the increasing reliance on web applications and APIs with CVE-riddled open source dependencies, has led to the rise of integrated security controls such as centrally managed, infrastructure-agnostic, and IP-free Hybrid Mesh Firewalls. This shift also demanded that WAFs extend their security to API enforcement, with an increasing emphasis on embedded intrusion-prevention systems capable of handling zero-day exploits.
Now, with the advent of GenAI, the traditional security blueprints and controls are being challenged yet again by new attack methods that network firewalls and WAFs cannot handle. For instance:
- Jailbreaking models directly (user prompts) or indirectly (prompt injection) to trick GenAI-powered assistants/agents to exfiltrate sensitive data in DLP-resistant outputs.
- Tricking AI Agents into launching attacks, such as executing arbitrary code, performing SQL injections on an SQL database in Retrieval Augmented Generation (RAG) setups.
- The introduction of agentic frameworks such as CrewAI, Flowise, and n8n that introduce an ever-increasing number of CVEs in internet-exposed systems with direct or indirect access to highly sensitive assets via Model Context Protocol (MCP) servers.
Now, over three decades after Check Point invented the first-ever firewall, Check Point has extended the battle-tested foundations of web application and cloud security to address the challenges of GenAI security. To achieve this, Check Point has (1) added GenAI-specific security layers to its Web Application and API Firewall (WAF), addressing issues such as model jailbreaking, misuse, excessive agency, and more, and (2) increased its Hybrid Mesh Firewall's ability to inspect cloud-spanning networks with deep cloud-native integrations to facilitate rapid adoption of hosted GenAI-based systems.
In other words, Check Point now offers a holistic threat-prevention security solution to secure traffic from the packets in your network, through APIs in your apps, and up to prompts in your LLMs.
Definitions and Disambiguation
- AI: For the purposes of this document, AI stands for Generative AI (GenAI), such as Large Language Models (LLMs), Vision Language Models (VLMs), etc.
- AI Agents: Autonomous AI-based systems that can perceive their environment, reason, and take action to achieve a specific goal.
- Agentic Flows: Workflows that use multiple autonomous AI agents in multi-step flows to make decisions, plan tasks, and perform.
What Current Controls Can Protect
The standard combination of Hybrid Mesh Firewalls and WAFs ensures that security encompasses all traffic layers, from packets traversing the network to API/HTTP requests. And since, at the end of the day, GenAI-powered web applications are still web applications, Hybrid Mesh Firewalls and WAFs together remain effective at blocking many attacks targeting them. Specifically:
- The WAF will still enforce API schemas, including LLM-bound APIs.
- Layer 3 and Layer 7 DLPs will still capture many instances of sensitive data leaks.
- IPSs will still block most malicious activities – GenAI-bound or otherwise.
Current Controls Are Good, But Not Good Enough for GenAI
As noted, even without GenAI-specific features, modern security controls and security blueprints provide adequate security, either directly or indirectly, against the most common GenAI attacks and their consequences as long as the GenAI-borne attack shares common denominators with more standard attacks against cloud infrastructure and web applications.
Unfortunately, no matter how effective these systems are at protecting cloud apps and assets, they do not address the new attack methods to which LLMs are exposed, nor the attacks that LLMs expose the company to. Attacks such as model jailbreaking, prompt injection, model misuse, excessive agency (e.g., too many tools/permissions), and RegEx-resistant data exfiltration cannot be fully addressed by traditional security blueprints and the firewalls they employ.
Hybrid Mesh Firewall for the GenAI Era
While hybrid cloud deployments have long been standard in enterprise IT to secure complex, heterogeneous environments spanning multiple networks, the rise of Generative AI (GenAI) has further amplified their complexity.
Organizations are now combining Amazon Web Services’ extensive array of GenAI tools with other public/private-cloud and on-premises environments to build scalable GenAI pipelines that balance innovation, cost efficiency, and data-sovereignty requirements.
The Role of the Hybrid Mesh Firewall
Historically, modern environments have consisted of multiple disjoint networks unified by Network Connectivity Mesh tools, SD-WAN, virtual WANs, VPNs, and inter-cloud solutions. Check Point’s Hybrid Mesh Firewall (HMFW) extends this concept to the gateway layer, creating a single overlay firewall that unifies protection across on-premises, branch, cloud, and virtual firewalls.
Check Point Cloud Firewall integrates natively with AWS and other platforms through unified management, IP-free dynamic policies, and infrastructure-agnostic enforcement that automatically adapts to changing network and application contexts. This seamless integration enables consistent threat prevention, segmentation, and zero-trust enforcement across traffic flows—from on-prem data centers to AWS-hosted environments for any app and workload.
Prevention-First Security for GenAI Workloads
GenAI ecosystems introduce fast-moving, unpredictable attack surfaces, ranging from model-API misuse to code-execution agents and poisoned retrieval data. Static, detection-only, and signature-based approaches cannot anticipate these threats.
Check Point’s prevention-first architecture, driven by its AI-powered Intrusion Prevention System (IPS) and autonomous policy synchronization, stops both known and unknown exploits before they impact the environment.
Conclusion
Deploying Check Point Cloud Firewall gateways and Check Point WAFs lays the foundation for a robust, adaptable security framework that organizations need to navigate the challenges of network and web application security in AWS and beyond.
Now, by integrating cutting-edge GenAI security directly into Check Point Cloud Security, along with its proven effectiveness in virtually patching and blocking zero-days across agentic frameworks, Check Point equips organizations with a one-stop-shop security tool to safeguard AI agents and assistants, both web-facing and those running in internal multi-step task flows and tool use.