SlideShare a Scribd company logo
Secure Web Applications with
Alibaba Cloud Web Application Firewall
by Forster Chiu
Principal Consultant – iCON Business Systems Limited
2
Principle Consultant - Cybersecurity Assurance and Compliance
(iCON Business Systems Ltd. Hong Kong)
Vulnerability Assessment, Security Audit (ISO 27001, GDPR), and Pen Tester
Speaker, Trainer - Security awareness and Offensive
Subject Matter Expert – EC-Council
PECB Certified Trainer
MSc in Computer and Security, PgD in IT Forensics,
BSc (Hons) Business Information Technology
About Me
2009
Alibaba Cloud is founded
R&D centers are opened in Beijing,
Hangzhou and Silicon Valley
2010
Alibaba Cloud’s first data center opens
2014
2017
Alibaba announced as the as the Official Cloud
Services and Infrastructure Partner for the Olympic
Games at the World Economic Forum in Davos.
2018
Alibaba Cloud Timeline
Data Centers open in Beijing,
Shenzhen and Hong Kong
Included in Gartner’s Magic Quadrant
for Data Analytics
Alibaba Cloud Services
Data Migration
Web Hosting
Internet of Things
Elastic Computing
Storage
Networking
Security
Alibaba Cloud Services
Alibaba Cloud Regions
Security and compliance
What is Web Application Firewall WAF
OWASP – Top 10 2017
Protects your website
against OWASP web
application attacks
Regular and timely
patches against 0day
vulnerabilities
Attack event management
What Alibaba Cloud WAF Can Do
Advantages of Alibaba Cloud WAF
Alibaba Cloud WAF
Function Solving traditional Web application attacks, solve business security
issues such as HTTP connections attack and etc.
Real Time Auto update the latest Web 0 Day vulnerability signature in 24 hours
Performance Second level elastic expansion, support for millions of QPS business
protection
Deployment Quick deployment in just 5 minutes, both cloud and non-cloud
Support Professional Expert Protection and IM Support
Editions and features
• Note: WAF instances created in International regions must be upgraded to the Enterprise edition.
Scalability
Maintenance Cost
Cloud WAF Versus On-Prem WAF
High security infrastructure
Demo 1: Purchase Alibaba Cloud WAF
Onsite Training - Secure Web Applications with  Alibaba Cloud Web Application Firewall
Onsite Training - Secure Web Applications with  Alibaba Cloud Web Application Firewall
Demo 2: Quick Start Configuration
Method 1 - Add website configurations automatically
Prerequisites :
The DNS records of the website are managed by Alibaba Cloud DNS, and at least one A
record is valid.
Add Domain and Verify HTTPS Certificate
Exception may be displayed after you have added the
website configuration. Wait a few seconds and check the
DNS status again, or check whether the DNS settings are
configured correctly at your DNS service provider.
Method 2 –
Add website configurations manually
On the Fill in the website information page,
complete the following configuration.
Demo 3: WAF Protection Policies
HTTP ACL Policy
Web Application Protection
HTTP Flood Protection
Big Data Deep Learning Engine
Block IPs Initiating High-frequency
Web Attacks
WAF Features And Protection Rules
Directory Scan Protection
Threat Intelligence
Blocked Regions
Data Risk Control
Website Tamper-proofing
Data Leakage Prevention
Onsite Training - Secure Web Applications with  Alibaba Cloud Web Application Firewall
Demo 4: Reporting and Loging
Total QPS and the malicious QPS (triggering protection rules) of the latest 30 days
Inbound and Outbound bandwidth of the latest 30 days
Number of abnormal responses of the latest 30 days
Top 5 cities and Top 10 IP addresses that requests originate from
Mobile operating systems and PC browsers that requests originate from
Top 5 URLs with the slowest response speed
Top 5 URLs that are most frequently requested
Onsite Training - Secure Web Applications with  Alibaba Cloud Web Application Firewall
Frequencies of Web application attacks, HTTP flood attacks, and Web ACL events of the latest 30 days
Risk warnings of newly exposed industry or business security events
Messages of update of Alibaba Cloud WAF protection rule sets
Web application attacks
of the latest 30 days
HTTP flood attacks
of the latest 30 days
Web ACL events
of the latest 30 days
You can query the details of the following attack protection records:
Onsite Training - Secure Web Applications with  Alibaba Cloud Web Application Firewall
Onsite Training - Secure Web Applications with  Alibaba Cloud Web Application Firewall
Lab Prerequisites:
WebGoat 8 (https://github.com/WebGoat/WebGoat)
OWASP ZAP (https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project)
Vega Vulnerability Scanner (https://subgraph.com/vega/)
Alibaba Cloud WAF Protection Rules Configuration
Alibaba Cloud WAF Lab DEMO
Lab Objectives:
Discover web vulnerabilities of WebGoat 8
Attack WebGoat 8 without Alibaba Cloud WAF Protection
Attack WebGoat 8 with Alibaba Cloud WAF Protection
Verify the business values offered by Alibaba Cloud WAF Protection
Reference
https://www.alibabacloud.com/help/doc-
detail/58487.htm?spm=a2c63.p38356.b99.9.2e106981OxhLej
https://www.alibabacloud.com/product/waf
http://docs-aliyun.cn-hangzhou.oss.aliyun-inc.com/pdf/comparison-AlicloudlvsAWS-intl-en-
2018-03-26.pdf
https://www.alibabacloud.com/blog/web-application-firewall-cloud-options-alibaba-cloud-
waf-%26-aws-waf_304201
https://video-intl.alicdn.com/Campaign%20038%20Introducing%20AC%20Whitepaper%20v5e.pdf
Onsite Training - Secure Web Applications with  Alibaba Cloud Web Application Firewall

More Related Content

PPTX
Introduction to WAF and Network Application Security
PPTX
Cyber Security Compliance Solutions for Foreign Companies in China - Alibaba ...
PPTX
Introduction to Elastic Compute Service on Alibaba Cloud to Power Your Busine...
PDF
An Introduction to Alibaba Cloud’s Message Service
PPTX
Alibaba Cloud
PDF
Next Level Digital Media with Alibaba Cloud (Part 2)
PDF
Serverless Computing: Driving Innovation and Business Value
PDF
RightScale Webinar: Hybrid-IT: Connecting Your On-Premises Infrastructure Wit...
Introduction to WAF and Network Application Security
Cyber Security Compliance Solutions for Foreign Companies in China - Alibaba ...
Introduction to Elastic Compute Service on Alibaba Cloud to Power Your Busine...
An Introduction to Alibaba Cloud’s Message Service
Alibaba Cloud
Next Level Digital Media with Alibaba Cloud (Part 2)
Serverless Computing: Driving Innovation and Business Value
RightScale Webinar: Hybrid-IT: Connecting Your On-Premises Infrastructure Wit...

Similar to Onsite Training - Secure Web Applications with Alibaba Cloud Web Application Firewall (20)

PPTX
Webscale webinar about Web Application Firewall
PDF
AWS WAF OWASP
PDF
Cloud Clout & The Chinese Agnostic
PPTX
Cloud Web Application Firewall - GlobalDots
PDF
Protect Your Data and Apps in the Public Cloud
PPTX
Firewall presentation
PPTX
#ALSummit: Alert Logic & AWS - AWS Security Services
PPTX
AWS Security and Compliance Presentation
PDF
Safety in the Cloud(s): 'Vaporizing' the Web Application Firewall to Secure C...
PDF
Edge immersion days module 2 - protect your application at the edge using a...
PDF
淺談WAF在AWS的架構_20171027
PDF
WAF Deployment proposal
PPTX
FullDay on Fridays Feb. 3, 2017
PPTX
FullDay Faeder on Friday
PPTX
Introduction to AWS WAF and AWS Firewall Manager
PDF
淺談WAF在AWS的架構
PDF
What are the top 10 web security risks?
PDF
Intro to threat_detection_and_remediation on aws
PPTX
Network Transformation: What it is, and how it’s helping companies stay secur...
PPTX
Security
Webscale webinar about Web Application Firewall
AWS WAF OWASP
Cloud Clout & The Chinese Agnostic
Cloud Web Application Firewall - GlobalDots
Protect Your Data and Apps in the Public Cloud
Firewall presentation
#ALSummit: Alert Logic & AWS - AWS Security Services
AWS Security and Compliance Presentation
Safety in the Cloud(s): 'Vaporizing' the Web Application Firewall to Secure C...
Edge immersion days module 2 - protect your application at the edge using a...
淺談WAF在AWS的架構_20171027
WAF Deployment proposal
FullDay on Fridays Feb. 3, 2017
FullDay Faeder on Friday
Introduction to AWS WAF and AWS Firewall Manager
淺談WAF在AWS的架構
What are the top 10 web security risks?
Intro to threat_detection_and_remediation on aws
Network Transformation: What it is, and how it’s helping companies stay secur...
Security
Ad

Recently uploaded (20)

PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPTX
Big Data Technologies - Introduction.pptx
PPTX
Cloud computing and distributed systems.
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
KodekX | Application Modernization Development
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
DOCX
The AUB Centre for AI in Media Proposal.docx
PPT
Teaching material agriculture food technology
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Machine learning based COVID-19 study performance prediction
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
Unlocking AI with Model Context Protocol (MCP)
Building Integrated photovoltaic BIPV_UPV.pdf
Big Data Technologies - Introduction.pptx
Cloud computing and distributed systems.
Digital-Transformation-Roadmap-for-Companies.pptx
KodekX | Application Modernization Development
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
The AUB Centre for AI in Media Proposal.docx
Teaching material agriculture food technology
Chapter 3 Spatial Domain Image Processing.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Machine learning based COVID-19 study performance prediction
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Per capita expenditure prediction using model stacking based on satellite ima...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Spectral efficient network and resource selection model in 5G networks
Advanced methodologies resolving dimensionality complications for autism neur...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
NewMind AI Weekly Chronicles - August'25 Week I
Reach Out and Touch Someone: Haptics and Empathic Computing
Ad

Onsite Training - Secure Web Applications with Alibaba Cloud Web Application Firewall