The Experts below are selected from a list of 957 Experts worldwide ranked by ideXlab platform
Piedrahita Villarraga, Elkin Mauricio - One of the best experts on this subject based on the ideXlab platform.
-
Análisis comparativo de un Firewall de aplicaciones Web comerciales y un Open Source frente al top 10 de Owasp.
Universidad Nacional Abierta y a Distancia UNAD, 2016Co-Authors: Piedrahita Villarraga, Elkin MauricioAbstract:Desarrollar una aplicación Web podría conllevar un gran número de riesgos informáticos inherentes, existen diferentes tipos de técnicas que han sido utilizadas para tomar provecho de este tipo de aplicaciones algunas de las más conocidas se pueden encontrar en el top OWASP 10, sin embargo día a día nuevas vulnerabilidades son encontradas y la posibilidad que un riesgo se materialicé es cada vez mayor. Por esta razón, las empresas que hacen uso de este tipo de aplicaciones deben tomar conciencia de las vulnerabilidades a las que pueden estar expuestos y establecer algún tipo de control que permita disminuir los riesgos. Los controles que se pueden llevar a cabo en una aplicación Web son dos, el primero es realizar una auditoria periódica donde se hace una revisión del código y se ejecutan pruebas de sombrero blanco con el fin de encontrar algún tipo de vulnerabilidad, la segunda es implementar un Firewall de aplicación Web. Cada control ofrece sus ventajas y desventajas, y en el mejor de los casos lo ideal sería disponer de ambos, si bien la auditoria permitiría generar código más robusto habría una brecha de seguridad en el lapso que una nueva vulnerabilidad sea encontrada hasta el momento en que la auditoria sea realizada. Así que disponer de un WAF que esté en todo momento revisando las peticiones de los usuarios podría incrementar el nivel de seguridad. Ahora la pregunta sería, ¿Qué nivel de seguridad y confiabilidad ofrece un WAF?, históricamente los WAF empezaron a ganar popularidad luego que en el Consejo de Estándares de Seguridad (PCI-DSS) exigieran a las entidades emisoras de tarjetas de crédito realizar controles sobre las aplicaciones Web bien sea por revisión del código o mediante un WAF. Hoy en día existen diferentes fabricantes dedicados al desarrollo de WAF y analizando lenguajes de programación tales como HTML, HTTPS, SOAP and XML-RPC, además permiten prevenir ataques como XSS, inyecciones de SQL, secuestro de sesión, desbordamiento de buffer, ataques de día cero entre otros. Así que con base en la anterior los WAF hoy en día tienen una gran reputación y ofrecen un alto nivel de seguridad. Teniendo en cuenta que existen tantas marcas de WAF así como beneficios a nivel seguridad, este proyecto se enfocó en evaluar las diferencias que podrían existir entre un WAF comercial frente a uno de libre de distribución, esta comparación se hizo con base en el Top 10 de OWASP donde cada una de las vulnerabilidades fue probada en cada uno de los WAF. La implementación del esquema de pruebas requirió que el WAF operará en un modo de proxy reverso de esta forma el servidor Web no sufrió ningún tipo de alteración durante el desarrollo del proyecto y así garantizar unas pruebas ecuánimes. Los resultados obtenidos de la prueba han permitido evidenciar que el WAF de marca F5 dispone una plantilla de gran cantidad lenguajes de programación Web que permiten implementar reglas tan granulares tanto como se especifiquen por el administrador, además dispone un consola de administración Web amigable que permite identificar de forma fácil el ataque o información anómala detectada, también se observa que la herramienta dispone de esquema de aprendizaje el cual permite notificar al WAF eventos como falso positivos y aceptar parámetros que en un principio son marcados como anómalos y lo cual es modelo de seguridad positivo permitiendo tener una mayor escalabilidad. Por su parte Modsecurity ofrece una gran versatilidad para el desarrollo de nuevas firmas de ataques, su consola de administración es a través de línea de comando, y el nivel de seguridad que se ofrece es igual al proporcionado por WAF de marca F5 con base en las pruebas realizadas en este proyecto, las cuales no involucrando técnicas avanzadas de ataques Web. Así que los niveles de seguridad brindados por el WAF comercial como el de libre distribución están iguales, sin embargo las diferencias radican en las funcionalidades que ofrece el WAF comercial que permite una mayor escalabilidad y mejor modelo de implementación.Developing a Web Application could entail a large number of inherent computer risks, there are different types of techniques that have been used to take advantage of these types of Applications some of the best known can be found in the top OWASP 10, however day by day New vulnerabilities are encountered and the possibility that a risk materialized is increasing. For this reason, companies that use this type of Applications must be aware of the vulnerabilities to which they may be exposed and establish some type of control to reduce risks. The controls that can be performed in a Web Application are two, the first is to perform a periodic audit where the code is checked and white hat tests are run in order to find some kind of vulnerability, the second is to implement A Web Application Firewall. Each control offers its advantages and disadvantages, and in the best case the ideal would be to have both, although the audit would allow to generate more robust code would have a security gap in the time that a new vulnerability is found until the moment in which The audit is performed. So having a WAF that is at all times reviewing the requests of users could increase the level of security. Now the question would be, what level of security and reliability does a WAF ?, WAF historically began to gain popularity after the PCI-DSS required credit card issuers to perform checks on The Web Applications either by revision of the code or by means of a WAF. Nowadays there are different manufacturers dedicated to the development of WAF and analyzing programming languages such as HTML, HTTPS, SOAP and XML-RPC, besides they can prevent attacks like XSS, SQL injections, session hijacking, buffer overflow, day attacks Zero among others. So based on the above the WAFs today have a great reputation and offer a high level of security. Considering that there are so many WAF marks as well as security benefits, this project focused on evaluating the differences that could exist between a commercial WAF versus a free-distribution one, this comparison was based on the Top 10 of OWASP where each of the vulnerabilities was tested in each of the WAFs. The implementation of the test scheme required that the WAF will operate in a reverse proxy mode in this way the Web server did not suffer any type of alteration during the development of the project and thus ensure fair tests. The results obtained from the test have made it possible to show that the WAF F5 brand has a large number of Web programming languages that allow the implementation of such granular rules as specified by the administrator, and has a friendly Web management console that allows the identification It is also observed that the tool has a learning scheme which allows to notify the WAF events as false positives and to accept parameters that are initially marked as anomalous and which is a positive security model Allowing greater scalability. On the other hand, Modsecurity offers a great versatility for the development of new signatures of attacks, its console of administration is through line of command, and the level of security that is offered is equal to the one provided by WAF of mark F5 based on the Tests carried out in this project, which do not involve advanced techniques of Web attacks. So the security levels offered by the commercial WAF as the free distribution are the same, however the differences lie in the functionality offered by the commercial WAF that allows a greater scalability and better implementation model
Brasil. Superior Tribunal De Justiça - One of the best experts on this subject based on the ideXlab platform.
-
Portaria STJ/SAD n. 24 de 15 de janeiro de 2019
2019Co-Authors: Brasil. Superior Tribunal De JustiçaAbstract:Designa a Comissão de Recebimento provisório e definitivo referente ao Contrato STJ n. 87/2018, que tem por objeto o fornecimento de solução de Web Application Firewall (WAF) com serviços de instalação, configuração, suporte técnico e treinamento
-
Portaria STJ/SAD n. 23 de 15 de janeiro de 2019
2019Co-Authors: Brasil. Superior Tribunal De JustiçaAbstract:Designa o titular da Seção de Segurança de Rede e o seu substituto, respectivamente, como gestor e gestor substituto do Contrato STJ n. 87/2018, firmado com a empresa Teltec Solutions Ltda., que tem por objeto o fornecimento de solução de Web Application Firewall (WAF) com serviços de instalação, configuração, suporte técnico e treinamento
Elkin Mauricio - One of the best experts on this subject based on the ideXlab platform.
-
analisis comparativo de un Firewall de aplicaciones Web comerciales y un open source frente al top 10 de owasp
2016Co-Authors: Piedrahita Villarraga, Elkin MauricioAbstract:Developing a Web Application could entail a large number of inherent computer risks, there are different types of techniques that have been used to take advantage of these types of Applications some of the best known can be found in the top OWASP 10, however day by day New vulnerabilities are encountered and the possibility that a risk materialized is increasing. For this reason, companies that use this type of Applications must be aware of the vulnerabilities to which they may be exposed and establish some type of control to reduce risks. The controls that can be performed in a Web Application are two, the first is to perform a periodic audit where the code is checked and white hat tests are run in order to find some kind of vulnerability, the second is to implement A Web Application Firewall. Each control offers its advantages and disadvantages, and in the best case the ideal would be to have both, although the audit would allow to generate more robust code would have a security gap in the time that a new vulnerability is found until the moment in which The audit is performed. So having a WAF that is at all times reviewing the requests of users could increase the level of security. Now the question would be, what level of security and reliability does a WAF ?, WAF historically began to gain popularity after the PCI-DSS required credit card issuers to perform checks on The Web Applications either by revision of the code or by means of a WAF. Nowadays there are different manufacturers dedicated to the development of WAF and analyzing programming languages such as HTML, HTTPS, SOAP and XML-RPC, besides they can prevent attacks like XSS, SQL injections, session hijacking, buffer overflow, day attacks Zero among others. So based on the above the WAFs today have a great reputation and offer a high level of security. Considering that there are so many WAF marks as well as security benefits, this project focused on evaluating the differences that could exist between a commercial WAF versus a free-distribution one, this comparison was based on the Top 10 of OWASP where each of the vulnerabilities was tested in each of the WAFs. The implementation of the test scheme required that the WAF will operate in a reverse proxy mode in this way the Web server did not suffer any type of alteration during the development of the project and thus ensure fair tests. The results obtained from the test have made it possible to show that the WAF F5 brand has a large number of Web programming languages that allow the implementation of such granular rules as specified by the administrator, and has a friendly Web management console that allows the identification It is also observed that the tool has a learning scheme which allows to notify the WAF events as false positives and to accept parameters that are initially marked as anomalous and which is a positive security model Allowing greater scalability. On the other hand, Modsecurity offers a great versatility for the development of new signatures of attacks, its console of administration is through line of command, and the level of security that is offered is equal to the one provided by WAF of mark F5 based on the Tests carried out in this project, which do not involve advanced techniques of Web attacks. So the security levels offered by the commercial WAF as the free distribution are the same, however the differences lie in the functionality offered by the commercial WAF that allows a greater scalability and better implementation model.
Hafiz Farooq Ahmad - One of the best experts on this subject based on the ideXlab platform.
-
formal reasoning of Web Application Firewall rules through ontological modeling
2012 15th International Multitopic Conference (INMIC), 2012Co-Authors: Ali Ahmad, Ali Hur, Zahid Anwar, Hafiz Farooq AhmadAbstract:Web Application Firewalls (WAF)s are security tools that protect Web Application from external attacks. They do so by applying a set of security policy rules on HTTP traffic generated and received by Web Applications. These policies Rules are in-fact the heart of WAFs which are unable to provide strong protection on their own without well-written policy rules. Unfortunately due to complexity of Web Application and increased sophistication of Application level attacks the rule configuration and management for WAFs is an error prone and tedious task. This paper is an effort to explore the effectiveness of an Ontology based framework for modeling, configuring, querying and reasoning overWAF Firewall configurations.We have tested our framework on a leading open source Web Application Firewalls known as ModSecurity. Our preliminary results show that our framework significantly improves configuration errors in the WAF ruleset that arise because of duplication and policy conflicts.
-
Application for autonomous decentralized multi layer cache system to Web Application Firewall
International Symposium on Autonomous Decentralized Systems, 2011Co-Authors: Hironao Takahashi, Hafiz Farooq Ahmad, Kinji MoriAbstract:Web service demand is heterogeneous and it is expanding day by day. Malicious Web attacks particularly at Application layer, are also increasing significantly. It is estimated eighty percent (80%) malicious attacks are Web Application layer attacks such as Cross Site Scripting and SQL injection. Such attacks have affected financial organizations, government institutes, hospitals and enterprise companies and so on. It is required to detect such attacks instantly to maintain the safe operations. Existing Web Application Firewalls (WAF) aim at protection of Web Application attacks using Black and White list based approach. Black list based WAFs operate at security operation center (SOC) to protect known attacks and it is easy to maintain same black list by other WAF nodes. However, white list independent signature from each Web service and it is generated by each Web site policy. When the event of WAF fails, other WAF doesn't have same level of White list at that time. Black list is common type of signature and it can be keep the assurance by multiple WAF nodes or proxy node but White list is individual type of signature and can't maintain assurance by same policy of node. Therefore, to maintain high detection rate, dynamic adaptability of White list is required. It also requires online property and timeliness response. To solve these issues, an integrated Autonomous Decentralized Multi Layer Cache (ADMLC) system with Web Application Firewall is proposed. Evaluation shows that proposed architecture detection rate is much better than other traditional WAF based systems.
-
autonomous short latency system for Web Application layer Firewall
World Congress on Services, 2010Co-Authors: Hironao Takahashi, Kinji Mori, Hafiz Farooq AhmadAbstract:Real time Application was required many types of industrial controllers, factory machines since 20-century. It is also utilizing many types of real time controllers for vehicle such as train, automobile and so on [1]. On the other hand, Web services that are using Internet are required short latency system. When the accesses are increased, services of quality are so important factors to achieve their requirement. Thus, these Web services are facing different levels of requirement. One is short latency of time service and other one is protection from malicious access. To support two of both at same time, it is big challenge in Web service today. The main issue is malicious Web attacks on Web Application layer level accesses that came up recently. Today's Web service provider is attempting to achieve this level of service. There are a few Web Application level security technology but the all of their approach is black list or white list base. To analyze these HTTP protocol accesses, Web site is always required high performance list search and compares them. From the analyzing processes have some events overhead. Keeping short latency of time, it needs high I/O performance solution. This paper is proposing L3 block cache node with eventually consistency technology to achieve timeliness autonomous decentralized system. The latency of time is compared with traditional approach system. Jmeter based Web access response evaluation is shown very positive result. Thus, proposing short latency node system is great solution for Web Application Firewall with short latency.
Makiou Abdelhamid - One of the best experts on this subject based on the ideXlab platform.
-
Sécurité des Applications Web : Analyse, modélisation et détection des attaques par apprentissage automatique
HAL CCSD, 2016Co-Authors: Makiou AbdelhamidAbstract:Web Applications are the backbone of modern information systems. The Internet exposure of these Applications continually generates new forms of threats that can jeopardize the security of the entire information system. To counter these threats, there are robust and feature-rich solutions. These solutions are based on well-proven attack detection models, with advantages and limitations for each model. Our work consists in integrating functionalities of several models into a single solution in order to increase the detection capacity. To achieve this objective, we define in a first contribution, a classification of the threats adapted to the context of the Web Applications. This classification also serves to solve some problems of scheduling analysis operations during the detection phase of the attacks. In a second contribution, we propose an architecture of Web Application Firewall based on two analysis models. The first is a behavioral analysis module, and the second uses the signature inspection approach. The main challenge to be addressed with this architecture is to adapt the behavioral analysis model to the context of Web Applications. We are responding to this challenge by using a modeling approach of malicious behavior. Thus, it is possible to construct for each attack class its own model of abnormal behavior. To construct these models, we use classifiers based on supervised machine learning. These classifiers use learning datasets to learn the deviant behaviors of each class of attacks. Thus, a second lock in terms of the availability of the learning data has been lifted. Indeed, in a final contribution, we defined and designed a platform for automatic generation of training datasets. The data generated by this platform is standardized and categorized for each class of attacks. The learning data generation model we have developed is able to learn "from its own errors" continuously in order to produce higher quality machine learning datasets .Les Applications Web sont l’épine dorsale des systèmes d’information modernes. L’exposition sur Internet de ces Applications engendre continuellement de nouvelles formes de menaces qui peuvent mettre en péril la sécurité de l’ensemble du système d’information. Pour parer à ces menaces, il existe des solutions robustes et riches en fonctionnalités. Ces solutions se basent sur des modèles de détection des attaques bien éprouvés, avec pour chaque modèle, des avantages et des limites. Nos travaux consistent à intégrer des fonctionnalités de plusieurs modèles dans une seule solution afin d’augmenter la capacité de détection. Pour atteindre cet objectif, nous définissons dans une première contribution, une classification des menaces adaptée au contexte des Applications Web. Cette classification sert aussi à résoudre certains problèmes d’ordonnancement des opérations d’analyse lors de la phase de détection des attaques. Dans une seconde contribution, nous proposons une architecture de filtrage des attaques basée sur deux modèles d’analyse. Le premier est un module d’analyse comportementale, et le second utilise l’approche d’inspection par signature. Le principal défi à soulever avec cette architecture est d’adapter le modèle d’analyse comportementale au contexte des Applications Web. Nous apportons des réponses à ce défi par l’utilisation d’une approche de modélisation des comportements malicieux. Ainsi, il est possible de construire pour chaque classe d’attaque son propre modèle de comportement anormal. Pour construire ces modèles, nous utilisons des classifieurs basés sur l’apprentissage automatique supervisé. Ces classifieurs utilisent des jeux de données d’apprentissage pour apprendre les comportements déviants de chaque classe d’attaques. Ainsi, un deuxième verrou en termes de disponibilité des données d’apprentissage a été levé. En effet, dans une dernière contribution, nous avons défini et conçu une plateforme de génération automatique des données d’entrainement. Les données générées par cette plateforme sont normalisées et catégorisées pour chaque classe d’attaques. Le modèle de génération des données d’apprentissage que nous avons développé est capable d’apprendre "de ses erreurs" d’une manière continue afin de produire des ensembles de données d’apprentissage de meilleure qualité
-
Web Application security : analysis, modeling and attacks detection using machine learning
2016Co-Authors: Makiou AbdelhamidAbstract:Les Applications Web sont l’épine dorsale des systèmes d’information modernes. L’exposition sur Internet de ces Applications engendre continuellement de nouvelles formes de menaces qui peuvent mettre en péril la sécurité de l’ensemble du système d’information. Pour parer à ces menaces, il existe des solutions robustes et riches en fonctionnalités. Ces solutions se basent sur des modèles de détection des attaques bien éprouvés, avec pour chaque modèle, des avantages et des limites. Nos travaux consistent à intégrer des fonctionnalités de plusieurs modèles dans une seule solution afin d’augmenter la capacité de détection. Pour atteindre cet objectif, nous définissons dans une première contribution, une classification des menaces adaptée au contexte des Applications Web. Cette classification sert aussi à résoudre certains problèmes d’ordonnancement des opérations d’analyse lors de la phase de détection des attaques. Dans une seconde contribution, nous proposons une architecture de filtrage des attaques basée sur deux modèles d’analyse. Le premier est un module d’analyse comportementale, et le second utilise l’approche d’inspection par signature. Le principal défi à soulever avec cette architecture est d’adapter le modèle d’analyse comportementale au contexte des Applications Web. Nous apportons des réponses à ce défi par l’utilisation d’une approche de modélisation des comportements malicieux. Ainsi, il est possible de construire pour chaque classe d’attaque son propre modèle de comportement anormal. Pour construire ces modèles, nous utilisons des classifieurs basés sur l’apprentissage automatique supervisé. Ces classifieurs utilisent des jeux de données d’apprentissage pour apprendre les comportements déviants de chaque classe d’attaques. Ainsi, un deuxième verrou en termes de disponibilité des données d’apprentissage a été levé. En effet, dans une dernière contribution, nous avons défini et conçu une plateforme de génération automatique des données d’entrainement. Les données générées par cette plateforme sont normalisées et catégorisées pour chaque classe d’attaques. Le modèle de génération des données d’apprentissage que nous avons développé est capable d’apprendre "de ses erreurs" d’une manière continue afin de produire des ensembles de données d’apprentissage de meilleure qualité.Web Applications are the backbone of modern information systems. The Internet exposure of these Applications continually generates new forms of threats that can jeopardize the security of the entire information system. To counter these threats, there are robust and feature-rich solutions. These solutions are based on well-proven attack detection models, with advantages and limitations for each model. Our work consists in integrating functionalities of several models into a single solution in order to increase the detection capacity. To achieve this objective, we define in a first contribution, a classification of the threats adapted to the context of the Web Applications. This classification also serves to solve some problems of scheduling analysis operations during the detection phase of the attacks. In a second contribution, we propose an architecture of Web Application Firewall based on two analysis models. The first is a behavioral analysis module, and the second uses the signature inspection approach. The main challenge to be addressed with this architecture is to adapt the behavioral analysis model to the context of Web Applications. We are responding to this challenge by using a modeling approach of malicious behavior. Thus, it is possible to construct for each attack class its own model of abnormal behavior. To construct these models, we use classifiers based on supervised machine learning. These classifiers use learning datasets to learn the deviant behaviors of each class of attacks. Thus, a second lock in terms of the availability of the learning data has been lifted. Indeed, in a final contribution, we defined and designed a platform for automatic generation of training datasets. The data generated by this platform is standardized and categorized for each class of attacks. The learning data generation model we have developed is able to learn "from its own errors" continuously in order to produce higher quality machine learning datasets