SlideShare une entreprise Scribd logo
1  sur  15
Télécharger pour lire hors ligne
Web Application Firewall
as-a-service
Qualys GmbH September, 2013
Web Applications
•  Are everywhere: Webmail, CMS, CRM, Corporate WWW
etc.
•  HTTP is powering all new applications using new data
format like XML and JSON
•  Organisations are publishing data for B2B through APIs
using HTTP and XML/JSON or SOAP
•  Mobile applications usually connect to APIs or Web
Applications using HTTP
New security issues
•  Network firewalls are useless, they can’t inspect HTTP
Protocol
•  Web Applications can be developed in-house or
provided by software editor, with closed or open source
code
•  Each web applications is different, depending on the
business logic, development framework and data used
and stored
•  To secure Web applications, a WAF (Web Application
Firewal) Must be deployed additionnaly to network
firewall
Existing solutions
•  From network security,
application delivery and
compliance
–  Fortinet, SonicWall,
Deny All, imperva
–  F5, Citrix Netscaler,
Radware, BeeWare
–  Mod_security
•  Saas vendors
–  Cloudflare, incapsula,
–  Art of defense
–  Trend Micro
–  Akamai Kona
Hard to maintain and operate,
security, development,
infrastructure team are involved,
policies are unique and not shared
between customers
Few clic deployment, no expertise
needed, security is compiled from
all website knowledge, but traffic
MUST be processed in the cloud
Technical Challenge
•  Web application security policies are complex
–  Need to use regular expression
–  Need to understand how the application works
•  Today, WAF are too complex to maintain and operate.
Vendors are adding others feature to make it a must
have product
•  Qualys stay focused on WAF security features but
dramaticaly reduce TCO of this kind of protection by
providing a distributed solution.
Qualys alternative
•  Qualys Distributed WAF
–  Security ruleset provided from all Qualys WAF feedback
–  Virtual Appliance deployment, you keep managing your traffic
•  Available as
–  Amazon EC2 AMI (beta)
–  VMware image (beta)
–  GA Planned to early december
–  HW WAF Appliance is under development for 2014
•  Manage security events and rules from a single UI
•  With Qualys WAF, you don’t spend time on managing rules, you can
stay focused on managing security events
http://www.qualys.com/waf
Qualys Web Application Firewall 

Beta available
WAF
Provides protection against known 

and emerging web application threats,
and helps increase web site
performance through caching,
compression and content
optimization, with no equipment
needed.

Benefits

Zero-footprint, low cost deployment

Ease of use, ease of maintenance

Real-time attack prevention

Virtual patching and application
hardening
Qualys Web Application Firewall 

Beta available

Qualys Security intelligence
•  A team of dedicated security researchers computing
rules for industry standard web applications
•  Blocking attacks according to OWASP TOP10 and WASC
TCv2
•  Correlating security events on Qualys sensors all around
the world
•  Detecting and researching 0-days
Qualys distributed WAF
Security Features
•  Always up-to-date WAF
–  Qualys is directly managing the security
engine and ruleset, they are updated in less
than 5 minutes when a security or
maintenance fix is avaible
•  Qualys Security Ruleset
–  Provided by Qualys Security Researcher Team,
this ruleset is the default security policy
avalaible on all WAF. It’s blocking injection
attacks like command, SQL, Javascript, Files
etc.
•  Custom Security rules
–  Provided by the customer or partner, these
rules are adapted to the website specific
design and can be setup depending on each
HTTP Request field.
•  Integration with QualysGuard WAS*
–  No need to setup twice your web applications
in these security tools, it’s automaticaly
provisionned and the WAF deployment made
easy from what the Web Application Scanner
found.
•  HTTP Security
–  HTTP protocol can be implemented in
different ways depending on web server and
browsers. To avoid some attack based on bad
implementation, the Qualys WAF will verify the
protocol is correctly used.
•  IP/Country Blacklist
–  Depending on your activity, you may not want
some request from specific countries or IP.
The Qualys WAF is able to increase/decrease
the request score, or directly block depending
of source IP or country.
•  Information leakage
–  By doing Web Cloaking, the Qualys WAF is
able to shadow all critical informations sent by
the Web Server, Application server or
development framwork used to develop the
web application
•  Reporting
–  Build your own report containing key indicators
you need to speak with managers
•  Session tracking
Deployment
•  Virtual appliance available
–  On EC2 as an AMI you can instanciate
–  On VMWare vCenter as an image you can run
•  Mode of operation
–  Reverse-Proxy:Terminating TCP connection
–  Out-of-Band*: Sniffing traffic (Passive device)
•  Available as OpenSource
–  IronBee project
Qualys advantage
•  Always uptodate & Always at maximum efficiency
–  Get the latest security rules and engine on your WAF
•  Prevention with WAS and Protection with WAF
available in the same UI and security suite
•  Available as subscription (Pay per year) OPEX vs
CAPEX
•  All the SaaS advantage on a virtual appliance product
Release schedule 2013
Amazon EC2 Beta 1
Limited to first 10 subscribers
August 1st
Amazon EC2 Beta 2
Limited to first 100 subscribers
October 1st
WAF GA*
VMWare & EC2
December 1st
November 1st
VMWare Beta 2
Limited to first 100 subscribers
September 1st
VMWare beta 1
Limited to first 10 subscribers
*: can be delayed until we reach 100% quality and availibility
Next releases
•  Advanced reporting
•  SSL Support
•  Integration between WAF and WAS
•  Qualys WAF Microsoft Edition for Exchange and
Sharepoint

Contenu connexe

Tendances

[OWASP Poland Day] Web App Security Architectures
[OWASP Poland Day] Web App Security Architectures[OWASP Poland Day] Web App Security Architectures
[OWASP Poland Day] Web App Security Architectures
OWASP
 

Tendances (20)

Radware - WAF (Web Application Firewall)
Radware - WAF (Web Application Firewall)Radware - WAF (Web Application Firewall)
Radware - WAF (Web Application Firewall)
 
Forti web
Forti webForti web
Forti web
 
FortiWeb
FortiWebFortiWeb
FortiWeb
 
CSS 17: NYC - Stories from the SOC
CSS 17: NYC - Stories from the SOCCSS 17: NYC - Stories from the SOC
CSS 17: NYC - Stories from the SOC
 
CSS 17: NYC - Realities of Security in the Cloud
CSS 17: NYC - Realities of Security in the CloudCSS 17: NYC - Realities of Security in the Cloud
CSS 17: NYC - Realities of Security in the Cloud
 
The Cloud - What's different
The Cloud - What's differentThe Cloud - What's different
The Cloud - What's different
 
mod_security introduction at study2study #3
mod_security introduction at study2study #3mod_security introduction at study2study #3
mod_security introduction at study2study #3
 
Realities of Security in the Cloud - CSS ATX 2017
Realities of Security in the Cloud - CSS ATX 2017Realities of Security in the Cloud - CSS ATX 2017
Realities of Security in the Cloud - CSS ATX 2017
 
Css sf azure_8-9-17-stories_from_the_soc_paul fletcher_al
Css sf azure_8-9-17-stories_from_the_soc_paul fletcher_alCss sf azure_8-9-17-stories_from_the_soc_paul fletcher_al
Css sf azure_8-9-17-stories_from_the_soc_paul fletcher_al
 
Stories from the Security Operations Center (S.O.C.)
Stories from the Security Operations Center (S.O.C.)Stories from the Security Operations Center (S.O.C.)
Stories from the Security Operations Center (S.O.C.)
 
12 palo alto app-id concept
12 palo alto app-id concept12 palo alto app-id concept
12 palo alto app-id concept
 
Microservices Security
Microservices SecurityMicroservices Security
Microservices Security
 
[OWASP Poland Day] Web App Security Architectures
[OWASP Poland Day] Web App Security Architectures[OWASP Poland Day] Web App Security Architectures
[OWASP Poland Day] Web App Security Architectures
 
Stories from the Security Operations Center
Stories from the Security Operations CenterStories from the Security Operations Center
Stories from the Security Operations Center
 
CSS 17: NYC - Building Secure Solutions in AWS
CSS 17: NYC - Building Secure Solutions in AWSCSS 17: NYC - Building Secure Solutions in AWS
CSS 17: NYC - Building Secure Solutions in AWS
 
Owasp top 10 2017
Owasp top 10 2017Owasp top 10 2017
Owasp top 10 2017
 
Realities of Security in the Cloud
Realities of Security in the CloudRealities of Security in the Cloud
Realities of Security in the Cloud
 
#ALSummit: Cyber Resiliency: Surviving the Breach
#ALSummit: Cyber Resiliency: Surviving the Breach#ALSummit: Cyber Resiliency: Surviving the Breach
#ALSummit: Cyber Resiliency: Surviving the Breach
 
F5 Web Application Security
F5 Web Application SecurityF5 Web Application Security
F5 Web Application Security
 
CSS17: Houston - Stories from the Security Operations Center
CSS17: Houston - Stories from the Security Operations CenterCSS17: Houston - Stories from the Security Operations Center
CSS17: Houston - Stories from the Security Operations Center
 

Similaire à QualysGuard InfoDay 2013 - Web Application Firewall

Security and Compliance for Enterprise Cloud Infrastructure
Security and Compliance for Enterprise Cloud InfrastructureSecurity and Compliance for Enterprise Cloud Infrastructure
Security and Compliance for Enterprise Cloud Infrastructure
CloudPassage
 
QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014
QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014
QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014
Risk Analysis Consultants, s.r.o.
 
WAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rulesWAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rules
Dimitris Gkizanis
 

Similaire à QualysGuard InfoDay 2013 - Web Application Firewall (20)

Web Access Firewall
Web Access FirewallWeb Access Firewall
Web Access Firewall
 
Kona Web Application Firewall Product Brief - Application-layer defense to pr...
Kona Web Application Firewall Product Brief - Application-layer defense to pr...Kona Web Application Firewall Product Brief - Application-layer defense to pr...
Kona Web Application Firewall Product Brief - Application-layer defense to pr...
 
Security and Compliance for Enterprise Cloud Infrastructure
Security and Compliance for Enterprise Cloud InfrastructureSecurity and Compliance for Enterprise Cloud Infrastructure
Security and Compliance for Enterprise Cloud Infrastructure
 
Azure F5 Solutions
Azure F5 SolutionsAzure F5 Solutions
Azure F5 Solutions
 
WAF Deployment proposal
WAF Deployment proposalWAF Deployment proposal
WAF Deployment proposal
 
QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014
QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014
QualysGuard InfoDay 2013 - QualysGuard RoadMap for H2-­2013/H1-­2014
 
淺談WAF在AWS的架構_20171027
淺談WAF在AWS的架構_20171027淺談WAF在AWS的架構_20171027
淺談WAF在AWS的架構_20171027
 
Un-clouding the cloud
Un-clouding the cloudUn-clouding the cloud
Un-clouding the cloud
 
WAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rulesWAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rules
 
Web Application Security for Continuous Delivery Pipelines
Web Application Security for Continuous Delivery PipelinesWeb Application Security for Continuous Delivery Pipelines
Web Application Security for Continuous Delivery Pipelines
 
Centurylink - Acceleration and securing modern applications!
Centurylink - Acceleration and securing modern applications!Centurylink - Acceleration and securing modern applications!
Centurylink - Acceleration and securing modern applications!
 
Data Center Server security
Data Center Server securityData Center Server security
Data Center Server security
 
Trust No-One Architecture For Services And Data
Trust No-One Architecture For Services And DataTrust No-One Architecture For Services And Data
Trust No-One Architecture For Services And Data
 
What's New VMware NSX Advanced Load Balancer (Avi Networks)
What's New VMware NSX Advanced Load Balancer (Avi Networks)What's New VMware NSX Advanced Load Balancer (Avi Networks)
What's New VMware NSX Advanced Load Balancer (Avi Networks)
 
在小學有效運用雲端電腦以促進電子學習(第一節筆記)
在小學有效運用雲端電腦以促進電子學習(第一節筆記)在小學有效運用雲端電腦以促進電子學習(第一節筆記)
在小學有效運用雲端電腦以促進電子學習(第一節筆記)
 
Web Application Firewall (WAF) Data Sheet - Array Networks
Web Application Firewall (WAF) Data Sheet - Array NetworksWeb Application Firewall (WAF) Data Sheet - Array Networks
Web Application Firewall (WAF) Data Sheet - Array Networks
 
Security As A Service In Cloud(SECaaS)
Security As A Service In Cloud(SECaaS)Security As A Service In Cloud(SECaaS)
Security As A Service In Cloud(SECaaS)
 
Protect Your Data and Apps in the Public Cloud
Protect Your Data and Apps in the Public CloudProtect Your Data and Apps in the Public Cloud
Protect Your Data and Apps in the Public Cloud
 
Securing virtual workload and cloud
Securing virtual workload and cloudSecuring virtual workload and cloud
Securing virtual workload and cloud
 
Business Agility and Security with VMware
Business Agility and Security with VMwareBusiness Agility and Security with VMware
Business Agility and Security with VMware
 

Plus de Risk Analysis Consultants, s.r.o.

QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
Risk Analysis Consultants, s.r.o.
 
QualysGuard InfoDay 2014 - QualysGuard Continuous Monitoring
QualysGuard InfoDay 2014 - QualysGuard Continuous MonitoringQualysGuard InfoDay 2014 - QualysGuard Continuous Monitoring
QualysGuard InfoDay 2014 - QualysGuard Continuous Monitoring
Risk Analysis Consultants, s.r.o.
 
QualysGuard InfoDay 2013 - Případová studie ČNB - QG WAS
QualysGuard InfoDay 2013 - Případová studie ČNB - QG WASQualysGuard InfoDay 2013 - Případová studie ČNB - QG WAS
QualysGuard InfoDay 2013 - Případová studie ČNB - QG WAS
Risk Analysis Consultants, s.r.o.
 
QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...
QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...
QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...
Risk Analysis Consultants, s.r.o.
 

Plus de Risk Analysis Consultants, s.r.o. (20)

Best practice v testování zranitelností
Best practice v testování zranitelnostíBest practice v testování zranitelností
Best practice v testování zranitelností
 
Shadow IT
Shadow ITShadow IT
Shadow IT
 
Představení nástroje Nuix
Představení nástroje NuixPředstavení nástroje Nuix
Představení nástroje Nuix
 
FTK5 - HW požadavky a instalace
FTK5 - HW požadavky a instalaceFTK5 - HW požadavky a instalace
FTK5 - HW požadavky a instalace
 
Použití EnCase EnScript
Použití EnCase EnScriptPoužití EnCase EnScript
Použití EnCase EnScript
 
RAC DEAS - Univerzální SW nástroj k zajištění digitálních stop
RAC DEAS - Univerzální SW nástroj k zajištění digitálních stopRAC DEAS - Univerzální SW nástroj k zajištění digitálních stop
RAC DEAS - Univerzální SW nástroj k zajištění digitálních stop
 
RAC DEAT - Univerální HW nástroje pro zajištění digitálních stop
RAC DEAT - Univerální HW nástroje pro zajištění digitálních stopRAC DEAT - Univerální HW nástroje pro zajištění digitálních stop
RAC DEAT - Univerální HW nástroje pro zajištění digitálních stop
 
QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
QualysGuard InfoDay 2014 - QualysGuard Web Application Security a Web Applica...
 
QualysGuard InfoDay 2014 - QualysGuard Continuous Monitoring
QualysGuard InfoDay 2014 - QualysGuard Continuous MonitoringQualysGuard InfoDay 2014 - QualysGuard Continuous Monitoring
QualysGuard InfoDay 2014 - QualysGuard Continuous Monitoring
 
QualysGuard InfoDay 2014 - Asset management
QualysGuard InfoDay 2014  - Asset managementQualysGuard InfoDay 2014  - Asset management
QualysGuard InfoDay 2014 - Asset management
 
QualysGuard InfoDay 2014 - WAS
QualysGuard InfoDay 2014 - WASQualysGuard InfoDay 2014 - WAS
QualysGuard InfoDay 2014 - WAS
 
QualysGuard InfoDay 2014 - Policy compliance
QualysGuard InfoDay 2014 - Policy complianceQualysGuard InfoDay 2014 - Policy compliance
QualysGuard InfoDay 2014 - Policy compliance
 
QualysGuard InfoDay 2014 - Vulnerability management
QualysGuard InfoDay 2014 - Vulnerability managementQualysGuard InfoDay 2014 - Vulnerability management
QualysGuard InfoDay 2014 - Vulnerability management
 
Použití hashsetů v EnCase Forensic v7
Použití hashsetů v EnCase Forensic v7Použití hashsetů v EnCase Forensic v7
Použití hashsetů v EnCase Forensic v7
 
Analýza elektronické pošty v EnCase Forensic v7
Analýza elektronické pošty v EnCase Forensic v7Analýza elektronické pošty v EnCase Forensic v7
Analýza elektronické pošty v EnCase Forensic v7
 
Vybrané funkce Forensic Toolkit 5 + RAC Forensic Imager
Vybrané funkce Forensic Toolkit 5 + RAC Forensic ImagerVybrané funkce Forensic Toolkit 5 + RAC Forensic Imager
Vybrané funkce Forensic Toolkit 5 + RAC Forensic Imager
 
QualysGuard InfoDay 2013 - Případová studie ČNB - QG WAS
QualysGuard InfoDay 2013 - Případová studie ČNB - QG WASQualysGuard InfoDay 2013 - Případová studie ČNB - QG WAS
QualysGuard InfoDay 2013 - Případová studie ČNB - QG WAS
 
QualysGuard InfoDay 2013 - Qualys Questionnaire
QualysGuard InfoDay 2013 - Qualys QuestionnaireQualysGuard InfoDay 2013 - Qualys Questionnaire
QualysGuard InfoDay 2013 - Qualys Questionnaire
 
QualysGuard InfoDay 2013 - Nové funkce QG
QualysGuard InfoDay 2013 - Nové funkce QGQualysGuard InfoDay 2013 - Nové funkce QG
QualysGuard InfoDay 2013 - Nové funkce QG
 
QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...
QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...
QualysGuard InfoDay 2013 - QualysGuard Security & Compliance Suite supporting...
 

Dernier

Dernier (20)

AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 

QualysGuard InfoDay 2013 - Web Application Firewall

  • 2. Web Applications •  Are everywhere: Webmail, CMS, CRM, Corporate WWW etc. •  HTTP is powering all new applications using new data format like XML and JSON •  Organisations are publishing data for B2B through APIs using HTTP and XML/JSON or SOAP •  Mobile applications usually connect to APIs or Web Applications using HTTP
  • 3. New security issues •  Network firewalls are useless, they can’t inspect HTTP Protocol •  Web Applications can be developed in-house or provided by software editor, with closed or open source code •  Each web applications is different, depending on the business logic, development framework and data used and stored •  To secure Web applications, a WAF (Web Application Firewal) Must be deployed additionnaly to network firewall
  • 4. Existing solutions •  From network security, application delivery and compliance –  Fortinet, SonicWall, Deny All, imperva –  F5, Citrix Netscaler, Radware, BeeWare –  Mod_security •  Saas vendors –  Cloudflare, incapsula, –  Art of defense –  Trend Micro –  Akamai Kona Hard to maintain and operate, security, development, infrastructure team are involved, policies are unique and not shared between customers Few clic deployment, no expertise needed, security is compiled from all website knowledge, but traffic MUST be processed in the cloud
  • 5. Technical Challenge •  Web application security policies are complex –  Need to use regular expression –  Need to understand how the application works •  Today, WAF are too complex to maintain and operate. Vendors are adding others feature to make it a must have product •  Qualys stay focused on WAF security features but dramaticaly reduce TCO of this kind of protection by providing a distributed solution.
  • 6. Qualys alternative •  Qualys Distributed WAF –  Security ruleset provided from all Qualys WAF feedback –  Virtual Appliance deployment, you keep managing your traffic •  Available as –  Amazon EC2 AMI (beta) –  VMware image (beta) –  GA Planned to early december –  HW WAF Appliance is under development for 2014 •  Manage security events and rules from a single UI •  With Qualys WAF, you don’t spend time on managing rules, you can stay focused on managing security events
  • 7. http://www.qualys.com/waf Qualys Web Application Firewall 
 Beta available WAF Provides protection against known 
 and emerging web application threats, and helps increase web site performance through caching, compression and content optimization, with no equipment needed. Benefits Zero-footprint, low cost deployment Ease of use, ease of maintenance Real-time attack prevention
 Virtual patching and application hardening
  • 8. Qualys Web Application Firewall 
 Beta available

  • 9. Qualys Security intelligence •  A team of dedicated security researchers computing rules for industry standard web applications •  Blocking attacks according to OWASP TOP10 and WASC TCv2 •  Correlating security events on Qualys sensors all around the world •  Detecting and researching 0-days
  • 11. Security Features •  Always up-to-date WAF –  Qualys is directly managing the security engine and ruleset, they are updated in less than 5 minutes when a security or maintenance fix is avaible •  Qualys Security Ruleset –  Provided by Qualys Security Researcher Team, this ruleset is the default security policy avalaible on all WAF. It’s blocking injection attacks like command, SQL, Javascript, Files etc. •  Custom Security rules –  Provided by the customer or partner, these rules are adapted to the website specific design and can be setup depending on each HTTP Request field. •  Integration with QualysGuard WAS* –  No need to setup twice your web applications in these security tools, it’s automaticaly provisionned and the WAF deployment made easy from what the Web Application Scanner found. •  HTTP Security –  HTTP protocol can be implemented in different ways depending on web server and browsers. To avoid some attack based on bad implementation, the Qualys WAF will verify the protocol is correctly used. •  IP/Country Blacklist –  Depending on your activity, you may not want some request from specific countries or IP. The Qualys WAF is able to increase/decrease the request score, or directly block depending of source IP or country. •  Information leakage –  By doing Web Cloaking, the Qualys WAF is able to shadow all critical informations sent by the Web Server, Application server or development framwork used to develop the web application •  Reporting –  Build your own report containing key indicators you need to speak with managers •  Session tracking
  • 12. Deployment •  Virtual appliance available –  On EC2 as an AMI you can instanciate –  On VMWare vCenter as an image you can run •  Mode of operation –  Reverse-Proxy:Terminating TCP connection –  Out-of-Band*: Sniffing traffic (Passive device) •  Available as OpenSource –  IronBee project
  • 13. Qualys advantage •  Always uptodate & Always at maximum efficiency –  Get the latest security rules and engine on your WAF •  Prevention with WAS and Protection with WAF available in the same UI and security suite •  Available as subscription (Pay per year) OPEX vs CAPEX •  All the SaaS advantage on a virtual appliance product
  • 14. Release schedule 2013 Amazon EC2 Beta 1 Limited to first 10 subscribers August 1st Amazon EC2 Beta 2 Limited to first 100 subscribers October 1st WAF GA* VMWare & EC2 December 1st November 1st VMWare Beta 2 Limited to first 100 subscribers September 1st VMWare beta 1 Limited to first 10 subscribers *: can be delayed until we reach 100% quality and availibility
  • 15. Next releases •  Advanced reporting •  SSL Support •  Integration between WAF and WAS •  Qualys WAF Microsoft Edition for Exchange and Sharepoint