Home icon

Identifying security risks using AWS Cost and Usage Report data

Cloud Financial Management Blog



This article explains how to use AWS Cost and Usage Report (CUR) data to identify security risks in your AWS environment through SQL queries and analysis.

  • Unencrypted CloudFront traffic (HTTP) violates compliance frameworks and exposes data to interception
  • Unauthorized region usage may indicate compromised credentials or policy violations
  • Unprotected CloudFront/Route 53 without AWS Shield Advanced creates DDoS vulnerability gaps
  • Extended support charges signal outdated software with unpatched security vulnerabilities
  • Abnormal data transfer cost spikes may indicate data exfiltration or malicious activity
  • Use provided SQL queries against CUR data in Amazon Athena to detect these risks
  • Complement with AWS Budgets, Cost Anomaly Detection, GuardDuty, and Security Hub

Organizations can transform billing data into a security intelligence platform by implementing cost-based monitoring alongside traditional security tools to detect threats through financial footprints.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 19
2025
How to prioritize security risks using AWS Security Hub exposure findings
Aug 29
2025
Implementing usage and security reporting for Amazon ECR
Jul 31
2025
Secure file sharing solutions in AWS: A security and cost analysis guide: Part 2
Nov 21
2025
AWS Cost Anomaly Detection accelerates anomaly identification

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.