Top Banner
w w w . . c o m WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010
24

Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

Dec 23, 2015

Download

Documents

Emil Gallagher
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAFs in the CloudA new direction for WAFs?

Ofer ShezafJanuary 2010

Page 2: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

What is a WAF?

Page 3: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

The two faces of information security:

Attack Detection:• Anti-Virus• Anti-Malware• IDS/IPS

Policy Enforcement:• Firewall• NAC• Scanners

Page 4: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

Which one is a WAF?

It’s a firewall isn’t it? So it

must be a policy enforcer.

But it does signatures, so it is probably an attack detector.

Page 5: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

Depends

Page 6: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

The XIOM Definition

Intimate understanding of HTTP

A positive security model

Application layer rules

Session based protection

Fine grained policy management

Page 7: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

What is a cloud?

Page 8: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

This is a cloud

Page 9: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

More Seriously

SaaS: SalesForce

PaaS:Shared Hosting

IaaS: Amazon EC2

Page 10: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

What Role Can a WAF Play in the Cloud?

Page 11: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

The Menu

• Enterprise Security Gateway• WAF as a service

– For protecting a data center– For protecting SaaS

• WAF for a cloud deployment– Host Based– Infrastructure Based

• WAF stubs– For a data center– For a cloud deployment

Page 12: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

Enterprise Security Gateway

Page 13: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

Enterprise Security Gateway

Protect in the cloud services through unified security gateway.

Pros:• Unified access control• Security for 3rd party

code

Cons:• Double bandwidth• Hard to create positive

security rules

Page 14: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF as a ServiceFor SaaS

For a Data Center

Page 15: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF as a service

Use an in the cloud WAF to protect enterprise data center.

Pros:• Very easy deployment.• Fast signature updates.• Might be the only solution

for a SaaS

Cons:• Double bandwidth• Preventing direct access

Page 16: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF as a service - Akamai

• Applies ModSecurity Core Rules to HTTP traffic.

• Uses Akamai internal HTTP processing technology

• Signatures only, hardly a WAF

Page 17: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF for Cloud Environment

Page 18: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF for Cloud Environment

Use an in the cloud WAF to protect enterprise data center.

Pros:• No Bandwidth

Overhead Cons:• Might be harder to deploy

Page 19: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

Host based WAF

Page 20: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

Host based WAF

• The most mature approach to WAF in the cloud.

• ModSecurity, SecureIIS, Applicure, PHPIDS….

• However many times not more than an Host based IPS.

Page 21: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF stubs

Page 22: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF Stubs

• Host based stub and a remote brain.• Different separation levels:

– Remote monitoring & configuration– Remote learning– Remote enforcement– In-between.

Page 23: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

WAF Stubs

• Art of Defence stub for AWS

• Breach Global Event Manager– Monitoring Only

Page 24: Www..com WAFs in the Cloud A new direction for WAFs? Ofer Shezaf January 2010.

ww

w. .c

om

Thank [email protected]