Home White Papers Information Security Web Application Firewall Primer with ModSecurity

Technology Consulting Services

Web Application Firewall Primer with ModSecurity
Written by David Torre   

Definition of a WAF

Unlike the general-purpose firewall which endures the daunting task of inspecting dozens of different applications, the sole purpose of the web application firewall or “WAF” is to protect web applications exclusively. As such, the WAF has intimate knowledge of the HTTP protocol, as well as associated vulnerabilities often found in web-based applications. WAF technology has seen increased interest with recent changes to Payment Card Industry Data Security Standards. PCI DSS Requirement 6.6 now requires public-facing web applications to either undergo annual security reviews, or alternatively, install proactive web application firewalls between the web application and Internet users.

The WAF is not merely another redundant firewall within your infrastructure. Technically, WAFs bear a closer resemblance to HTTP proxies. As with web proxies, web clients making direct connections to your web application must first connect to an intermediate control point which inspects the characteristics of the web request. If the request is benign, it is then forwarded off to the actual web application. However, things don't end there. Once the response is generated by the web application, it is again filtered through this intermediate control point prior to being sent back to the requesting user. This transparent, bidirectional filtering process is conducted in order to prevent both inbound exploits, as well as outbound information leakage.



Last Updated on Saturday, 21 November 2009 09:47
 

Add comment


Security code
Refresh


Atomic Fission, Information Technology Services, San Francisco, CA

Cloud Certification


Latest Comments

  • Thank you...this was very helpful
  • Nice well explained.
  • Yes, and Juniper now supports multiple proxyIDs in...
  • I think ProxyID is a Juniper thing.
  • What is proxy ID exactly? It is synonymous with se...

Atomic Fission RSS

feed-image Feed Entries