Guide | Securing GenAI Apps on AWS with Check Point | Check Point Software
Guide | Securing GenAI Apps on AWS with Check Point
Standing on the shoulders of giants Decades of experience have provided us with well-established tools and principles to protect clouds and web apps: From Next-Generation Hybrid Mesh Firewalls that protect and segment cloud and on-prem resources, to Web and API Firewalls (WAFs) that protect web-facing applications and exposed API endpoints. However, with the meteoric rise of Generative AI (GenAI) applications, such as chatbot assistants in internal and external-facing applications, and multi-step/multi-agent agentic flows/systems with access to sensitive data and tools such as web-browsing and code execution, new attack vectors and unique risks have emerged that challenge our established notions of web app security. Additionally, to reduce costs and rapidly adopt the era-defining revolution of GenAI technologies, companies are adopting hybrid cloud deployments, making infrastructure-agnostic IP-free firewalls an absolute necessity for consistent, repeatable security controls. This white paper discusses Check Point’s approach and its new capabilities to address the security risks of GenAI applications by seamlessly extending existing security controls and well-established security practices. Specifically, Check Point’s Hybrid Mesh Firewall with extended cloud-native capabilities, and the Check Point WAF (previously known as CloudGuard WAF), which has been supercharged with specially crafted GenAI security capabilities.
Securing GenAI Apps on AWS with Check Point
Preface
Why we must secure traffic from packets up to APIs The proliferation of networks across regions, branches, and on-premises data centers, along with the expansion into an increasing number of private and public cloud providers, as well as the increasing reliance on web applications and APIs with CVE-riddled open source dependencies, has led to the rise of integrated security controls such as centrally managed, infrastructure-agnostic, and IP-free Hybrid Mesh Firewalls. This shift also demanded that WAFs extend their security to API enforcement, with an increasing emphasis on embedded intrusion-prevention systems capable of handling zero-day exploits. Now, with the advent of GenAI, the traditional security blueprints and controls are being challenged yet again by new attack methods that network firewalls and WAFs cannot handle. For instance:
- Jailbreaking models directly (user prompts) or indirectly (prompt injection) to trick GenAI-powered assistants/agents to exfiltrate sensitive data in DLP-resistant outputs (e.g., output privileged information in ASCII art), mint unauthorized coupons, sell cars for $1, and more.
- Tricking AI Agents into launching attacks, such as executing arbitrary code, performing SQL injections on an SQL database in Retrieval Augmented Generation (RAG) setups.
- The introduction of agentic frameworks such as CrewAI, Flowise, and n8n that introduce an ever-increasing number of CVEs in internet-exposed systems with direct or indirect access to highly sensitive assets via Model Context Protocol (MCP) servers.
Now, over three decades after Check Point invented the first-ever firewall, Check Point has extended the battle-tested foundations of web application and cloud security to address the challenges of GenAI security. To achieve this, Check Point has (1) added GenAI-specific security layers to its Web Application and API Firewall (WAF), addressing issues such as model jailbreaking, misuse, excessive agency, and more, and (2) increased its Hybrid Mesh Firewall's ability to inspect cloud-spanning networks with deep cloud-native integrations to facilitate rapid adoption of hosted GenAI-based systems. In other words, Check Point now offers a holistic threat-prevention security solution to secure traffic from the packets in your network, through APIs in your apps, and up to prompts in your LLMs.
Definitions and Disambiguation
- AI: Unless specified otherwise, for the purposes of this document, AI stands for Generative AI (GenAI), such as Large Language Models (LLMs), Vision Language Models (VLMs), etc.
- AI Agents: Autonomous AI-based systems that can perceive their environment, reason, and take action to achieve a specific goal.
- Agentic Flows: Workflows that use multiple autonomous AI agents in multi-step flows to make decisions, plan tasks, and perform.
Existing Cloud/Web-App Security & Generative AI
What Current Controls Can Protect The standard combination of Hybrid Mesh Firewalls and WAFs ensures that security encompasses all traffic layers, from packets traversing the network to API/HTTP requests. And since, at the end of the day, GenAI-powered web applications are still web applications, Hybrid Mesh Firewalls and WAFs together remain effective at blocking many attacks targeting them. Specifically:
- The WAF will still enforce API schemas, including LLM-bound APIs.
- Layer 3 and Layer 7 DLPs will still capture many instances of sensitive data leaks.
- IPSs will still block most malicious activities – GenAI-bound or otherwise.
Current Controls Are Good, But Not Good Enough for GenAI
As noted, even without GenAI-specific features, modern security controls and security blueprints provide adequate security, either directly or indirectly, against the most common GenAI attacks and their consequences as long as the GenAI-borne attack shares common denominators with more standard attacks against cloud infrastructure and web applications. Unfortunately, no matter how effective these systems are at protecting cloud apps and assets, they do not address the new attack methods to which LLMs are exposed, nor the attacks that LLMs expose the company to. Attacks such as model jailbreaking, prompt injection, model misuse, excessive agency (e.g., too many tools/permissions), and RegEx-resistant data exfiltration cannot be fully addressed by traditional security blueprints and the firewalls they employ.
Hybrid Mesh Firewall for the GenAI Era
While hybrid cloud deployments have long been standard in enterprise IT to secure complex, heterogeneous environments spanning multiple networks, the rise of Generative AI (GenAI) has further amplified their complexity. Organizations are now combining Amazon Web Services’ extensive array of GenAI tools with other public/private-cloud and on-premises environments to build scalable GenAI pipelines that balance innovation, cost efficiency, and data-sovereignty requirements.
The Role of the Hybrid Mesh Firewall
Historically, modern environments have consisted of multiple disjoint networks unified by Network Connectivity Mesh tools, SD-WAN, virtual WANs, VPNs, and inter-cloud solutions such as AWS Direct Connect. Check Point’s Hybrid Mesh Firewall (HMFW) extends this concept to the gateway layer, creating a single overlay firewall that unifies protection across on-premises, branch, cloud, and virtual firewalls. Check Point Cloud Firewall (previously known as CloudGuard Network Security) integrates natively with AWS and other platforms through unified management, IP-free dynamic policies, and infrastructure-agnostic enforcement that automatically adapts to changing network and application contexts. This seamless integration enables consistent threat prevention, segmentation, and zero-trust enforcement across traffic flows—from on-prem data centers to AWS-hosted environments—for any app and workload—with GenAI and without.
Why GenAI Changes Everything
The adoption of GenAI has accelerated the move toward heterogeneous environments. The main drivers include:
- Simplified AI enablement by leveraging AWS-provided, out-of-the-box GenAI tooling to build and deploy robust AI pipelines quickly by non-AI specialists.
- Cost optimization by avoiding datacenter-scale GPU investments. At the same time, data governance and compliance requirements in Retrieval Augmented Generation (RAG) pipelines often necessitate private-cloud or on-prem storage of sensitive data, while AI assistants and agentic workflows run in public clouds such as AWS. Many enterprise systems (HR, CRM, ERP) remain confined to private clouds with immutable deployment blueprints, making secure hybrid connectivity essential.
Consider a representative deployment of an Order Support Assistant that helps customers with orders, returns, and refunds while securely accessing their personal data. In our deployment, the sensitive data remains hosted in an on-premises database, while the web app and its AI logic run in a scalable AWS cloud environment, leveraging out-of-the-box GenAI tools to help non-AI experts build AI-powered systems. This division reflects a pattern increasingly common in enterprise GenAI: high-performance AI in the public cloud, with data sovereignty on-prem.
Unified Connectivity and Auto-Scaling
The first step in protecting hybrid environments is to establish secure connectivity between them, either via an IPsec VPN or connectivity tools such as AWS Direct Connect. Check Point Cloud Firewall’s integrated VPN provides immediate deployment simplicity, and its blueprint integrates seamlessly with AWS Direct Connect, leveraging it as a trusted, high-performance path within a unified security fabric. During workload fluctuations, AWS Auto Scaling Groups dynamically scale out or scale in Check Point Cloud Firewall instances. Each instance is (1) automatically provisioned, (2) establishes Secure Internal Communication (SIC), (3) applies a restrictive zero-trust baseline, and (4) promotes to a full policy post-validation. Importantly, this exact behavior is replicated across clouds with continuous asset synchronization and adaptive policies that automatically apply to new workloads and infrastructure changes without manual replumbing or rule editing – ensuring elasticity never compromises governance.
Dynamic, IP-Free Policy Enforcement
Modern GenAI applications rely on ephemeral components, kubernetes pods, serverless orchestrations, transient VMs, and dynamically scaled MCP servers. Static IP-based rules are brittle and unmanageable in this context. Check Point Cloud Firewall replaces them with attribute-driven, metadata-aware policies based on cloud tags, labels, and categories. AWS tags, kubernetes labels, and Nutanix categories are automatically discovered and synchronized, allowing segmentation and threat-prevention rules to follow workloads wherever they run. This declarative model yields a self-adjusting security fabric that evolves in real time with the infrastructure, maintaining visibility, compliance, and repeatable protection across AWS, private, and on-prem resources.
Prevention-First Security for GenAI Workloads
GenAI ecosystems introduce fast-moving, unpredictable attack surfaces, ranging from model-API misuse to code-execution agents and poisoned retrieval data. Static, detection-only, and signature-based approaches cannot anticipate these threats. Check Point’s prevention-first architecture, driven by its AI-powered Intrusion Prevention System (IPS) and autonomous policy synchronization, stops both known and unknown exploits before they impact the environment.
Conclusion
Deploying Check Point Cloud Firewall gateways and Check Point WAFs lays the foundation for a robust, adaptable security framework that organizations need to navigate the challenges of network and web application security in AWS and beyond. Now, by integrating cutting-edge GenAI security directly into Check Point Cloud Security, along with its proven effectiveness in virtually patching and blocking zero-days across agentic frameworks, Check Point equips organizations with a one-stop-shop security tool to safeguard AI agents and assistants, both web-facing and those running in internal multi-step task flows and tool use.