SlideShare a Scribd company logo
Confidential │ ©2019 VMware, Inc.
Webinar
Christian Treutler
R&D Security Engineer – NSBU,
VMwareSeptember 5th 2019
Prevent Threats with
Analytics-Driven Web
Application Firewall
Confidential │ ©2019 VMware, Inc.
Agenda
2
Why Application Security has become Critical
Need for Analytics-driven Application Security
Prevent Threats with Analytics-Driven Web Application Firewall
Live Demos
Customer success story
Summary & Next Steps
3Confidential │ ©2019 VMware, Inc.
We live in a time of data
breaches.
Confidential │ ©2019 VMware, Inc. 4
Correlation of incidents into breaches
Source: Verizon Data Breach Investigations Report (DBIR) 2019
Cost of a Data Breach report 2019 – Ponemon Institute
Web Application Breaches and Cost
$3.92M
Average total cost of a data
breach
Confidential │ ©2019 VMware, Inc. 5
Application Security is part
of all of our lives.
Breaches affect
everybody.
6Confidential │ ©2019 VMware, Inc.
“The biggest
threat to
security is the
hyper-focus on
security
threats.”
Pat Gelsinger - RSA conference
2019
Focus on
Applications
Make security
intrinsic ___
Invest in Prevention
7Confidential │ ©2019 VMware, Inc.
NSX Advanced Load Balancer
& Web Application Firewall
Technology overview
Confidential │ ©2019 VMware, Inc. 8
Why is WAF not Pervasively Deployed
Rule
Complexity
Lack of
Visibility
Poor
Scalability
Confidential │ ©2019 VMware, Inc. 9
BARE METAL VIRTUALIZED CONTAINERSON PREMISES PUBLIC CLOUDVIRTUALIZED CONTAINERS
Modern, Scalable, Multi-Cloud Architecture
CONTROLLER
SERVICE
ENGINE
SEPARATE CONTROL
& DATA PLANE
ELASTICITY
INTELLIGENCE AUTOMATIONMULTI-CLOUD
Confidential │ ©2019 VMware, Inc. 10
Comprehensive Security Stack
NSX Advanced Load Balancer
Encryption
SSL/TLS
L3/4 Firewall Rules
IP-Port based Security Rules
L7 Firewall Rules
Content (URI) based security rules
DDoS Protection
DDoS detection and mitigation with elastic scaling
Application Rate Limiting
Control and restrict by application or tenants
Security
Insights
Security score
Attack insights
SSL Insights
WAF analytics
Web Application Firewall
OWASP TOP 10, Application protection, Attack Analytics
Centralized Management
Multi-Cloud Elastic Fabric
Automation & Programmability
Real Time Visibility & Analytics
REST API
Data Center Private Cloud Public Cloud
Confidential │ ©2019 VMware, Inc. 11
NSX Advanced Load Balancer WAF - Core Design Principles
Automated Policy Creation
Native OWASP Top 10 Protection
Advanced Learning
One-click Policy Tuning
Real-time Insights
Intelligence on Attacks, Application Behavior,
and Rule Matches
Elasticity and Automation
High-Performance
Auto-Scaling
API-First Platform
Confidential │ ©2019 VMware, Inc. 12
Avi’s WAF Capabilities
Application defense in depth
• Application Learning and Positive Security
• OWASP Top 10 Protection
• Signatures and app-specific rules
• HTTP protocol enforcement and input
Validation – XSS, SQLi, etc.
• Virtual patching using scripting for
application logic flaws
• API protection for JSON, XML
• Metrics and statistics about the current
application attack surface
• Bot detection
Backend
Application
Untrusted Trusted
WAN
Confidential │ ©2019 VMware, Inc.
iWAF policy checks
Whitelist
• High performance for trusted traffic
• Match Criteria: Headers, IP, Path and more
• Similar to HTTP policy matching
PSM
• Positive definition of Application behavior
• Zero-day attacks defence and performance
• Rules: Learning, Scanners, Manual
Signatures
• Scans for common attack patterns
• Rules: OWASP Top 10 protection rules
Confidential │ ©2019 VMware, Inc. 14
Automating Application Security using ML
FastPas
s
Deep Inspection
Negative Security
Deny
Allow
Traffic
ML Classifier
Confidential │ ©2019 VMware, Inc. 15
Client
AppResponse
Security
Application defense in depth
Analytics Driven Security
Application
All metrics are
accessible via
API and can be
used for policy
updates.
Analytics
Engine
supports over
1k data points
Confidential │ ©2019 VMware, Inc. 16
Application Security Automation
CONTROLLER
Deploy
Anywhere
CICD-capable
Shift Left
Security
Scanner
Integrations
Metrics Engine App Behavior
Learning
Automated
App Rule
Updates
Integrated Machine Learning
Control Analytics
17Confidential │ ©2019 VMware, Inc.
Demo
WAF Introduction
WAF Learning & Protection
18Confidential │ ©2019 VMware, Inc.
Customer success
Swisslos & Avi - A continuing success story
Confidential │ ©2019 VMware, Inc. 19
Challenges (2017)
• Avi - easy to deploy very user friendly
• Detailed analytics for cost reduction
• API-first model for automation and self-
service
Solution (2017)
• Avi has successfully handled all
scaling requirements
• Traffic peaks are seasonal; scale-out
and scale-in continues to reduce costs
Solution (2019)
• 60% operational savings
• Analytics and Insights simplify daily
operations and troubleshooting
• East Policy tuning
Impact
Location: Basel, Switzerland
Securing the lottery - The Swisslos story
Products Strategic Priorities
Avi Networks ADC
Avi Networks iWAF
Software defined network and datacenter
Secure all internet-facing applications
Lotteries, sport bets and instant tickets for Switzerland
 Modernizing DC to replace legacy HW
 Appliance-based WAF
 Lack of elasticity and poor
performance => bad customer
experience
“The iWAF is so well integrated in
the Avi solution that not using it
would be a crime. It is not only
protecting our applications but
giving us loads of insights about
threats and attacks thanks to the
out of the box analytics.”
JORIS VUFFRAY,
HEADNETWORK & SYSTEM
MANAGEMENT
20Confidential │ ©2019 VMware, Inc.
Summary
21Confidential │ ©2019 VMware, Inc.
Focus on Applications
Make security intrinsic ____
Invest in Preventioneducing attack surface by adding WAF protection___________________________________
Learning application behavior to auto tune security policy_________________________
Security build into NSX Advanced Load Balancer by default ___________________
“NSX Advanced Load Balancer focuses
on the application."
Confidential │ ©2019 VMware, Inc.
Thank You

More Related Content

PPTX
How to Eliminate Load Balancer Upgrade Disruptions
PPTX
What's New VMware NSX Advanced Load Balancer (Avi Networks)
PPTX
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
PPTX
How Multi-Cloud Load Balancing Automates Application Delivery and Drives Oper...
PPTX
Advanced Web Application Security with an Intelligent WAF
PPTX
Multi Cloud Load balancing 101 and Hands-on Lab
PPTX
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World
PPTX
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
How to Eliminate Load Balancer Upgrade Disruptions
What's New VMware NSX Advanced Load Balancer (Avi Networks)
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
How Multi-Cloud Load Balancing Automates Application Delivery and Drives Oper...
Advanced Web Application Security with an Intelligent WAF
Multi Cloud Load balancing 101 and Hands-on Lab
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing

What's hot (20)

PPTX
Multi Cloud Load Balancing 101 and Hands On Lab
PPTX
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
PPTX
Enabling Remote Employees with Horizon VDI and Avi Networks
PDF
7 Requirements for Modern Load Balancers
PPTX
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
PPTX
Avi v20.1 — What’s New in Scalable, Multi-Cloud Load Balancing
PDF
Working From Anywhere​ with​ Advanced Load Balancing​ and ​ VMware Horizon VDI
PDF
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
PPTX
Avi workshop-101
PPTX
Multi-Cloud Load Balancing – Separating Fact from Fiction
PDF
7 Virtues of a Next-gen ADC
PPTX
Deploying Elastic, Self-Service Load Balancing for VMware NSX-T
PPTX
Enterprise-Grade Load Balancing for VMware Cloud on AWS (VMC)
PPTX
Multi-Cloud Load Balancing 101 and Hands-On Lab
PPTX
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
PPTX
State of Load Balancing 2020
PPTX
Multi-Cloud Load Balancing and Application Services
PPTX
L4-L7 Application Services with Avi Networks
PPTX
Private Cloud with Microsoft Technologies
PDF
VMware Cloud on Amazon Web Services
Multi Cloud Load Balancing 101 and Hands On Lab
Securing Web Applications with Deep Automation with VMware NSX Advanced Load ...
Enabling Remote Employees with Horizon VDI and Avi Networks
7 Requirements for Modern Load Balancers
Deliver Modern Applications with an Elastic Load Balancing Fabric Powered by ...
Avi v20.1 — What’s New in Scalable, Multi-Cloud Load Balancing
Working From Anywhere​ with​ Advanced Load Balancing​ and ​ VMware Horizon VDI
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
Avi workshop-101
Multi-Cloud Load Balancing – Separating Fact from Fiction
7 Virtues of a Next-gen ADC
Deploying Elastic, Self-Service Load Balancing for VMware NSX-T
Enterprise-Grade Load Balancing for VMware Cloud on AWS (VMC)
Multi-Cloud Load Balancing 101 and Hands-On Lab
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
State of Load Balancing 2020
Multi-Cloud Load Balancing and Application Services
L4-L7 Application Services with Avi Networks
Private Cloud with Microsoft Technologies
VMware Cloud on Amazon Web Services
Ad

Similar to Prevent threats With Analytics Driven Web Application Firewall (20)

PPTX
Radware - WAF (Web Application Firewall)
PDF
Extend Enterprise Application-level Security to Your AWS Environment
PDF
2021 02-17 v mware-algo-sec securely accelerate your digital transformation w...
PPTX
VMware overview presentation by alamgir hossain
PPTX
#PCMVision: VMware NSX - Transforming Security
 
PPT
Protecting web aplications with machine learning and security fabric
PDF
Protect Your Data and Apps in the Public Cloud
PPTX
Why Network and Endpoint Security Isn’t Enough
PPTX
Application Control - Maintenance Headache or Manageable Solution?
PPTX
VMware Customer references - Cloud
PDF
V Mworld 2010 Lab Cloud
PDF
AppTrana SECaaS (Security as a Service)
PDF
IT Security As A Service
PDF
[OPD 2019] Top 10 Security Facts of 2020
PPTX
VMware vShield - Overview
PDF
G05.2013 gartner top security trends
PPTX
Radware Cloud Security Services
PPTX
Web_Appication_Security_Training_For_Developers.pptx
PDF
Nvis pitch deck version 4 - 2021 dec
PDF
Protecting the Core of Your Network
Radware - WAF (Web Application Firewall)
Extend Enterprise Application-level Security to Your AWS Environment
2021 02-17 v mware-algo-sec securely accelerate your digital transformation w...
VMware overview presentation by alamgir hossain
#PCMVision: VMware NSX - Transforming Security
 
Protecting web aplications with machine learning and security fabric
Protect Your Data and Apps in the Public Cloud
Why Network and Endpoint Security Isn’t Enough
Application Control - Maintenance Headache or Manageable Solution?
VMware Customer references - Cloud
V Mworld 2010 Lab Cloud
AppTrana SECaaS (Security as a Service)
IT Security As A Service
[OPD 2019] Top 10 Security Facts of 2020
VMware vShield - Overview
G05.2013 gartner top security trends
Radware Cloud Security Services
Web_Appication_Security_Training_For_Developers.pptx
Nvis pitch deck version 4 - 2021 dec
Protecting the Core of Your Network
Ad

More from Avi Networks (10)

PPTX
DR On Demand At Fraction of the Cost (1).pptx
PPTX
Cloud_controllers_public_webinar_aug31_v1.pptx
PPTX
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
PPTX
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
PPTX
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptx
PPTX
One And Done Multi-Cloud Load Balancing Done Right.pptx
PPTX
Virtualize Application Security Today - Hardware is No Longer Needed.pptx
PDF
Deploying Elastic Self-Service Load Balancing
PPTX
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
PPTX
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation
DR On Demand At Fraction of the Cost (1).pptx
Cloud_controllers_public_webinar_aug31_v1.pptx
Top 4 Reasons to Migrate From NSX Load Balancing to NSX Advanced Load Balancer
23.06.15 NSX ALB and vCD integration deepdive_webinar0615.pptx
Enterprises-Have-Replaced-12000-ADCs-See-Why.pptx
One And Done Multi-Cloud Load Balancing Done Right.pptx
Virtualize Application Security Today - Hardware is No Longer Needed.pptx
Deploying Elastic Self-Service Load Balancing
NSX_Advanced_Load_Balancer_Solution_with_Oracle.pptx
Delivering Turnkey Load Balancing in VMware Cloud with Day 0 Automation

Recently uploaded (20)

PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Machine learning based COVID-19 study performance prediction
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
Big Data Technologies - Introduction.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Empathic Computing: Creating Shared Understanding
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Cloud computing and distributed systems.
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Electronic commerce courselecture one. Pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Encapsulation_ Review paper, used for researhc scholars
Chapter 3 Spatial Domain Image Processing.pdf
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Machine learning based COVID-19 study performance prediction
Network Security Unit 5.pdf for BCA BBA.
Mobile App Security Testing_ A Comprehensive Guide.pdf
Big Data Technologies - Introduction.pptx
Unlocking AI with Model Context Protocol (MCP)
Empathic Computing: Creating Shared Understanding
Spectral efficient network and resource selection model in 5G networks
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Cloud computing and distributed systems.
Reach Out and Touch Someone: Haptics and Empathic Computing
“AI and Expert System Decision Support & Business Intelligence Systems”
Understanding_Digital_Forensics_Presentation.pptx
Electronic commerce courselecture one. Pdf
MYSQL Presentation for SQL database connectivity
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025

Prevent threats With Analytics Driven Web Application Firewall

  • 1. Confidential │ ©2019 VMware, Inc. Webinar Christian Treutler R&D Security Engineer – NSBU, VMwareSeptember 5th 2019 Prevent Threats with Analytics-Driven Web Application Firewall
  • 2. Confidential │ ©2019 VMware, Inc. Agenda 2 Why Application Security has become Critical Need for Analytics-driven Application Security Prevent Threats with Analytics-Driven Web Application Firewall Live Demos Customer success story Summary & Next Steps
  • 3. 3Confidential │ ©2019 VMware, Inc. We live in a time of data breaches.
  • 4. Confidential │ ©2019 VMware, Inc. 4 Correlation of incidents into breaches Source: Verizon Data Breach Investigations Report (DBIR) 2019 Cost of a Data Breach report 2019 – Ponemon Institute Web Application Breaches and Cost $3.92M Average total cost of a data breach
  • 5. Confidential │ ©2019 VMware, Inc. 5 Application Security is part of all of our lives. Breaches affect everybody.
  • 6. 6Confidential │ ©2019 VMware, Inc. “The biggest threat to security is the hyper-focus on security threats.” Pat Gelsinger - RSA conference 2019 Focus on Applications Make security intrinsic ___ Invest in Prevention
  • 7. 7Confidential │ ©2019 VMware, Inc. NSX Advanced Load Balancer & Web Application Firewall Technology overview
  • 8. Confidential │ ©2019 VMware, Inc. 8 Why is WAF not Pervasively Deployed Rule Complexity Lack of Visibility Poor Scalability
  • 9. Confidential │ ©2019 VMware, Inc. 9 BARE METAL VIRTUALIZED CONTAINERSON PREMISES PUBLIC CLOUDVIRTUALIZED CONTAINERS Modern, Scalable, Multi-Cloud Architecture CONTROLLER SERVICE ENGINE SEPARATE CONTROL & DATA PLANE ELASTICITY INTELLIGENCE AUTOMATIONMULTI-CLOUD
  • 10. Confidential │ ©2019 VMware, Inc. 10 Comprehensive Security Stack NSX Advanced Load Balancer Encryption SSL/TLS L3/4 Firewall Rules IP-Port based Security Rules L7 Firewall Rules Content (URI) based security rules DDoS Protection DDoS detection and mitigation with elastic scaling Application Rate Limiting Control and restrict by application or tenants Security Insights Security score Attack insights SSL Insights WAF analytics Web Application Firewall OWASP TOP 10, Application protection, Attack Analytics Centralized Management Multi-Cloud Elastic Fabric Automation & Programmability Real Time Visibility & Analytics REST API Data Center Private Cloud Public Cloud
  • 11. Confidential │ ©2019 VMware, Inc. 11 NSX Advanced Load Balancer WAF - Core Design Principles Automated Policy Creation Native OWASP Top 10 Protection Advanced Learning One-click Policy Tuning Real-time Insights Intelligence on Attacks, Application Behavior, and Rule Matches Elasticity and Automation High-Performance Auto-Scaling API-First Platform
  • 12. Confidential │ ©2019 VMware, Inc. 12 Avi’s WAF Capabilities Application defense in depth • Application Learning and Positive Security • OWASP Top 10 Protection • Signatures and app-specific rules • HTTP protocol enforcement and input Validation – XSS, SQLi, etc. • Virtual patching using scripting for application logic flaws • API protection for JSON, XML • Metrics and statistics about the current application attack surface • Bot detection Backend Application Untrusted Trusted WAN
  • 13. Confidential │ ©2019 VMware, Inc. iWAF policy checks Whitelist • High performance for trusted traffic • Match Criteria: Headers, IP, Path and more • Similar to HTTP policy matching PSM • Positive definition of Application behavior • Zero-day attacks defence and performance • Rules: Learning, Scanners, Manual Signatures • Scans for common attack patterns • Rules: OWASP Top 10 protection rules
  • 14. Confidential │ ©2019 VMware, Inc. 14 Automating Application Security using ML FastPas s Deep Inspection Negative Security Deny Allow Traffic ML Classifier
  • 15. Confidential │ ©2019 VMware, Inc. 15 Client AppResponse Security Application defense in depth Analytics Driven Security Application All metrics are accessible via API and can be used for policy updates. Analytics Engine supports over 1k data points
  • 16. Confidential │ ©2019 VMware, Inc. 16 Application Security Automation CONTROLLER Deploy Anywhere CICD-capable Shift Left Security Scanner Integrations Metrics Engine App Behavior Learning Automated App Rule Updates Integrated Machine Learning Control Analytics
  • 17. 17Confidential │ ©2019 VMware, Inc. Demo WAF Introduction WAF Learning & Protection
  • 18. 18Confidential │ ©2019 VMware, Inc. Customer success Swisslos & Avi - A continuing success story
  • 19. Confidential │ ©2019 VMware, Inc. 19 Challenges (2017) • Avi - easy to deploy very user friendly • Detailed analytics for cost reduction • API-first model for automation and self- service Solution (2017) • Avi has successfully handled all scaling requirements • Traffic peaks are seasonal; scale-out and scale-in continues to reduce costs Solution (2019) • 60% operational savings • Analytics and Insights simplify daily operations and troubleshooting • East Policy tuning Impact Location: Basel, Switzerland Securing the lottery - The Swisslos story Products Strategic Priorities Avi Networks ADC Avi Networks iWAF Software defined network and datacenter Secure all internet-facing applications Lotteries, sport bets and instant tickets for Switzerland  Modernizing DC to replace legacy HW  Appliance-based WAF  Lack of elasticity and poor performance => bad customer experience “The iWAF is so well integrated in the Avi solution that not using it would be a crime. It is not only protecting our applications but giving us loads of insights about threats and attacks thanks to the out of the box analytics.” JORIS VUFFRAY, HEADNETWORK & SYSTEM MANAGEMENT
  • 20. 20Confidential │ ©2019 VMware, Inc. Summary
  • 21. 21Confidential │ ©2019 VMware, Inc. Focus on Applications Make security intrinsic ____ Invest in Preventioneducing attack surface by adding WAF protection___________________________________ Learning application behavior to auto tune security policy_________________________ Security build into NSX Advanced Load Balancer by default ___________________ “NSX Advanced Load Balancer focuses on the application."
  • 22. Confidential │ ©2019 VMware, Inc. Thank You