ModSecurity_The_Open_Source_Web_Application_Firewall_Nov2007.pdf

(556 KB) Pobierz
ModSecurity
The Open Source Web
Application Firewall
Ivan Ristic
Chief Evangelist
Breach Security
1/30
Introduction
Breach Security
Global headquarters in
Carlsbad, California
Web application security
provider for over six
years
Led by experienced
security executives
Trusted by large
enterprise customers
• Next-generation web application security solutions for protecting
business-critical applications transmitting privileged information.
• Resolve security challenges such as identity theft, information
leakage, regulatory compliance, and insecurely coded applications.
• Best threat detection in the industry and the most flexible
deployment options available.
2/30
Introduction
Ivan Ristic
Web application security
and
web application firewall
specialist.
Author of
Apache Security.
Author of
ModSecurity.
OWASP London Chapter
leader.
Officer of the
Web Application
Security Consortium.
WAFEC project leader.
3/30
Part 1
What are Web Application Firewalls?
4/30
Problems with Web Applications
How did it all start?
HTTP and browsers designed for document
exchange.
Web applications built using a number of loosely
integrated technologies.
No one thought about security at the time.
Most web applications suffer from one type of
problem or another. It is very difficult to develop
a reasonably secure web application.
Not possible to achieve 100% security.
Where are we today?
5/30
Zgłoś jeśli naruszono regulamin