SlideShare a Scribd company logo
WAF In DevOps DevOpsFusion2019
Web Application Firewall
in DevOps
WAF In DevOps DevOpsFusion2019
whoami
● franziska bühler
● architect @ puzzle ITC
● OWASP ModSecurity Core Rule Set
(WAF Rules)
● OWASP DevSlop
Outline
1. Web
Application
Firewall
2. ModSecurity
and Core Rule
Set
3. WAF a Part
of DevOps
Outline
2. ModSecurity
and Core Rule
Set
3. WAF a Part
of DevOps
1. Web
Application
Firewall
1st
line of defense
APPWAF
SQLi Attack
XSS Attack
WAF In DevOps DevOpsFusion2019
Too late !
« We need a better process to get WAFs into production. »
- Franziska Bühler
Test WAF
Outline
1. Web
Application
Firewall
2. ModSecurity
and Core Rule
Set
3. WAF a Part
of DevOps
WAF In DevOps DevOpsFusion2019
WAF In DevOps DevOpsFusion2019
Installation on NGINX
Request Rules
Malicous Request
Response Rules
Response : SQL Stack Trace
False Positive
Fight False Positive
Outline
1. Web
Application
Firewall
2. ModSecurity
and Core Rule
Set
3. WAF a Part
of DevOps
WAF In DevOps DevOpsFusion2019
ModSecDevOps
Setup
Setup
WAF
WAF In DevOps DevOpsFusion2019
Fast Feedback
CRS Container
$> docker pull franbuehler/modsecurity-crs-rp
$> docker run -dt 
-e BACKEND=http://172.17.0.1:8000 
franbuehler/modsecurity-crs-rp
WAF at
WAF In DevOps DevOpsFusion2019
WAF makes everyone happy!
Links
https://www.puzzle.ch
https://coreruleset.org
franbuehler/modsecurity-crs-rp
https://github.com/DevSlop/pixi-crs/
https://github.com/DevSlop/pixi-crs-demo/
https://modsecurity.org
https://devslop.co
Let’s make the world of web applications more
secure
-
Let’s add a WAF !
Franziska Bühler
buehler@puzzle.ch
@bufrasch

More Related Content

PDF
Web Application Firewall - Friend of your DevOps Pipeline?
PPTX
Nodejs Security
DOCX
Np web ii-devel-installation
PPTX
Mod security
PPTX
Pxosys Webinar Amplify your Security
PDF
Node Day - Node.js Security in the Enterprise
PPTX
Web Application firewall-Mod security
PDF
I'm watir
Web Application Firewall - Friend of your DevOps Pipeline?
Nodejs Security
Np web ii-devel-installation
Mod security
Pxosys Webinar Amplify your Security
Node Day - Node.js Security in the Enterprise
Web Application firewall-Mod security
I'm watir

What's hot (20)

PDF
/bin/tails from OpenStack Operations: Rarm Nagalingam, Red Hat
PPTX
.NET Conf 2018: Build Great Libraries using .NET Standard
PPTX
Neil Desai - Data Driven Analytics
PDF
Cypress e2e automation testing - day1 intor by: Hassan Hameed
PDF
Advanced nginx in mercari - How to handle over 1,200,000 HTTPS Reqs/Min
PPTX
WAF in Scale
PDF
[English][Test Girls] Zero to Hero: Start Test automation with Cypress
PPTX
Cypress Automation
ODP
Setting up and open fidy dev environment
PPTX
Deep dive networking
PDF
Build and deploy to the cloud using NetflixOSS (Gradle Summit 2016)
PPTX
[Wroclaw #7] Security test automation
PPTX
OWASP CSRF Protector
PDF
Null bhopal Sep 2016: What it Takes to Secure a Web Application
PPTX
[Wroclaw #7] AWS (in)security - the devil is in the detail
PPTX
Cloud Security Hardening та аудит хмарної безпеки за допомогою Scout Suite
PDF
Openstack bug list
PPTX
Apache Struts2 CVE-2017-5638
PPTX
ModSecurity and NGINX: Tuning the OWASP Core Rule Set (Updated)
PDF
SSL Pinning and Bypasses: Android and iOS
/bin/tails from OpenStack Operations: Rarm Nagalingam, Red Hat
.NET Conf 2018: Build Great Libraries using .NET Standard
Neil Desai - Data Driven Analytics
Cypress e2e automation testing - day1 intor by: Hassan Hameed
Advanced nginx in mercari - How to handle over 1,200,000 HTTPS Reqs/Min
WAF in Scale
[English][Test Girls] Zero to Hero: Start Test automation with Cypress
Cypress Automation
Setting up and open fidy dev environment
Deep dive networking
Build and deploy to the cloud using NetflixOSS (Gradle Summit 2016)
[Wroclaw #7] Security test automation
OWASP CSRF Protector
Null bhopal Sep 2016: What it Takes to Secure a Web Application
[Wroclaw #7] AWS (in)security - the devil is in the detail
Cloud Security Hardening та аудит хмарної безпеки за допомогою Scout Suite
Openstack bug list
Apache Struts2 CVE-2017-5638
ModSecurity and NGINX: Tuning the OWASP Core Rule Set (Updated)
SSL Pinning and Bypasses: Android and iOS
Ad

Similar to WAF In DevOps DevOpsFusion2019 (20)

PDF
Web Application Firewall - Friend of your DevOps Chain?
PDF
BSides Rochester 2018: Chaim Sanders: Easily Deploying and Optimizing Open So...
PDF
PDF
Introduction to ModSecurity and the OWASP Core Rule Set
PDF
Introduction to Mod security session April 2016
PDF
Web Application Firewall. Enhancing web security in the digital age.pdf
PDF
Secure your web application with an open source WAF.pdf
PPTX
Secure your web application with open source waf (PPT).pptx
PDF
A little waf
PDF
Connect Ops and Security with Flexible Web App and API Protection
PDF
Opensource pnp container based waf
PDF
Folini Extended Introduction to ModSecurity and CRS3
PDF
Why Do You Need a Web Application Firewall?
PPT
2009: Securing Applications With Web Application Firewalls and Vulnerability ...
PDF
Defending your workloads with aws waf and deep security
PDF
Introducing the OWASP ModSecurity Core Rule Set
PDF
淺談WAF在AWS的架構_20171027
PDF
Web Application Frewall
PDF
Benefits of web application firewall (1).pdf
PDF
淺談WAF在AWS的架構
Web Application Firewall - Friend of your DevOps Chain?
BSides Rochester 2018: Chaim Sanders: Easily Deploying and Optimizing Open So...
Introduction to ModSecurity and the OWASP Core Rule Set
Introduction to Mod security session April 2016
Web Application Firewall. Enhancing web security in the digital age.pdf
Secure your web application with an open source WAF.pdf
Secure your web application with open source waf (PPT).pptx
A little waf
Connect Ops and Security with Flexible Web App and API Protection
Opensource pnp container based waf
Folini Extended Introduction to ModSecurity and CRS3
Why Do You Need a Web Application Firewall?
2009: Securing Applications With Web Application Firewalls and Vulnerability ...
Defending your workloads with aws waf and deep security
Introducing the OWASP ModSecurity Core Rule Set
淺談WAF在AWS的架構_20171027
Web Application Frewall
Benefits of web application firewall (1).pdf
淺談WAF在AWS的架構
Ad

Recently uploaded (20)

PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Machine learning based COVID-19 study performance prediction
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Electronic commerce courselecture one. Pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Programs and apps: productivity, graphics, security and other tools
PPTX
Cloud computing and distributed systems.
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
Reach Out and Touch Someone: Haptics and Empathic Computing
Machine learning based COVID-19 study performance prediction
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
MYSQL Presentation for SQL database connectivity
Mobile App Security Testing_ A Comprehensive Guide.pdf
Review of recent advances in non-invasive hemoglobin estimation
20250228 LYD VKU AI Blended-Learning.pptx
Electronic commerce courselecture one. Pdf
Understanding_Digital_Forensics_Presentation.pptx
NewMind AI Weekly Chronicles - August'25 Week I
Building Integrated photovoltaic BIPV_UPV.pdf
Unlocking AI with Model Context Protocol (MCP)
Advanced methodologies resolving dimensionality complications for autism neur...
Diabetes mellitus diagnosis method based random forest with bat algorithm
Programs and apps: productivity, graphics, security and other tools
Cloud computing and distributed systems.
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Per capita expenditure prediction using model stacking based on satellite ima...

WAF In DevOps DevOpsFusion2019