Download presentation
Presentation is loading. Please wait.
Published bySimon Hamilton Modified over 9 years ago
1
www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010
2
www..com Xiom: the WAF experts Focus on real time web application security solutions. Free & unbiased expert information about web application firewalls and related technologies. Help in making WAFs deliver: –Selecting the correct WAF solution for you. –Optimizing your WAF implementation. –Write rules to ensure effective security. –Analyze alerts to understand risk and vulnerabilities of your web application. –Implementing ModSecurity based solutions.
3
www..com What is a WAF?
4
www..com The two faces of information security: Attack Detection: Anti-Virus Anti-Malware IDS/IPS Policy Enforcement: Firewall NAC Scanners
5
www..com Which one is a WAF? It’s a firewall isn’t it? So it must be a policy enforcer. But it does signatures, so it is probably an attack detector.
6
www..com Depends
7
www..com The XIOM Definition Intimate understanding of HTTP A positive security model Application layer rules Session based protection Fine grained policy management
8
www..com What is a cloud?
9
www..com This is a cloud
10
www..com More Seriously SaaS: SalesForce PaaS: Shared Hosting PaaS: Shared Hosting IaaS: Amazon EC2
11
www..com What Role Can a WAF Play in the Cloud?
12
www..com The Menu Enterprise Security Gateway WAF as a service –For protecting a data center –For protecting SaaS WAF for a cloud deployment –Host Based –Infrastructure Based WAF stubs –For a data center –For a cloud deployment
13
www..com Enterprise Security Gateway
14
www..com Enterprise Security Gateway Protect in the cloud services through unified security gateway. Pros: Unified access control Security for 3 rd party code Cons: Double bandwidth Hard to create positive security rules
15
www..com WAF as a Service For SaaS For a Data Center
16
www..com WAF as a service Use an in the cloud WAF to protect enterprise data center. Pros: Very easy deployment. Fast signature updates. Might be the only solution for a SaaS Cons: Double bandwidth Preventing direct access
17
www..com WAF as a service - Akamai Applies ModSecurity Core Rules to HTTP traffic. Uses Akamai internal HTTP processing technology Signatures only, hardly a WAF
18
www..com WAF for Cloud Environment
19
www..com WAF for Cloud Environment Use an in the cloud WAF to protect enterprise data center. Pros: No Bandwidth Overhead Cons: Might be harder to deploy
20
www..com Host based WAF
21
www..com Host based WAF The most mature approach to WAF in the cloud. ModSecurity, SecureIIS, Applicure, PHPIDS…. However many times not more than an Host based IPS.
22
www..com WAF stubs
23
www..com WAF Stubs Host based stub and a remote brain. Different separation levels: –Remote monitoring & configuration –Remote learning –Remote enforcement –In-between.
24
www..com WAF Stubs Art of Defence stub for AWS Breach Global Event Manager –Monitoring Only
25
www..com Thank You! shezaf@xiom.com
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.