19
Web Application Security Made Easy Brian A. McHenry Security Solutions Architect [email protected] Web Application Security Made Easy Easier

Web Application Security Made Easy Easier

  • Upload
    lenhan

  • View
    228

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Web Application Security Made Easy Easier

Web Application Security Made Easy Brian A. McHenry Security Solutions Architect [email protected]

Web Application Security Made Easy Easier

Page 2: Web Application Security Made Easy Easier

© F5 Networks, Inc 2

•  Remediation rates are low, especially for legacy or 3rd-party applications

•  Building WAF policy is one tactic, but can also be challenging

•  Applications are like snowflakes; no two alike

•  WAF ownership varies, and AppSec expertise varies with it

•  A WAF is only as effective as the integration with the SDLC process

•  Management resources for WAF are often limited

Practical Web Application Security Facts

Page 3: Web Application Security Made Easy Easier

© F5 Networks, Inc 3

Policy Deployment Options

Security policy checked

Security policy applied

DYNAMIC POLICY BUILDER INTEGRATION WITH APP SCANNERS PRE-BUILT POLICIES

Automatic •  No knowledge of

the app required •  Adjusts policies if

app changes

Manual •  Advanced

configuration for custom policies

•  Virtual patching with continuous application scanning

•  Out-of-the-box •  Pre-configure and validated •  For mission-critical apps

including: Microsoft, Oracle, PeopleSoft

Page 4: Web Application Security Made Easy Easier

© F5 Networks, Inc 4

Identify, virtually patch, mitigate vulnerabilities

Configure vulnerability policy in BIG-IP ASM

Mitigate web app attacks Scan application with:

Hacker

Clients

Tim

ely

thre

at m

itiga

tion

Assurance

Manual

WAF

Scan

Page 5: Web Application Security Made Easy Easier

© F5 Networks, Inc 5

Configuration

Page 6: Web Application Security Made Easy Easier

© F5 Networks, Inc 6

Configuration

Page 7: Web Application Security Made Easy Easier

© F5 Networks, Inc 7

Importing Vulnerabilities

Page 8: Web Application Security Made Easy Easier

© F5 Networks, Inc 8

Importing Vulnerabilities

Page 9: Web Application Security Made Easy Easier

© F5 Networks, Inc 9

A Deeper Look

Page 10: Web Application Security Made Easy Easier

© F5 Networks, Inc 10

A Deeper Look

Page 11: Web Application Security Made Easy Easier

© F5 Networks, Inc 11

Resolve, Resolve and Stage

Page 12: Web Application Security Made Easy Easier

© F5 Networks, Inc 12

Resolve, Resolve and Stage

Page 13: Web Application Security Made Easy Easier

© F5 Networks, Inc 13

Resolve, Resolve and Stage

Page 14: Web Application Security Made Easy Easier

© F5 Networks, Inc 14

Ignore, Unignore

Page 15: Web Application Security Made Easy Easier

© F5 Networks, Inc 15

Retest

•  The same attack vectors will be re-sent during a retest.

•  Asynchronous

•  ... after a couple of minutes ...

Page 16: Web Application Security Made Easy Easier

© F5 Networks, Inc 16

Retest

•  ASM polls the status of the 'Retest Requested' vulnerabilities each 2 minutes.

•  Vulnerabilities are to be retested are queued in the Sentinel. Generally they process in some minutes.

•  Can end up with:

–  Opened (vulnerability was not mitigated)‏

–  Closed (vulnerability was solved)‏

–  Mitigated (vulnerability was mitigated by ASM)‏

Page 17: Web Application Security Made Easy Easier

“ © F5 Networks, Inc 17

We couldn’t have provided safe remote access to SharePoint without the security F5 offers through BIG-IP ASM. And we don’t have to spend hours

reviewing thousands of vulnerability log entries in order to configure ASM effectively.

-  IT Director, Large US Community College

Page 18: Web Application Security Made Easy Easier

“ © F5 Networks, Inc 18

By deploying F5’s comprehensive Application Security Manager (ASM) solution, Aura is now

enabling customers to fix its security issues within a reasonable timeframe, and subsequently shield

and prevent reoccurrences.

Page 19: Web Application Security Made Easy Easier