OWASP Top 10: Effectiveness of Web Application Firewalls

No ratings

Presented at BsidesOttawa 2016 by

Web Application Firewalls (WAF) are essential components of a secure web application deployment. Capable of filtering network traffic on all OSI layers, they understand web specific communication protocols and programming languages. In addition, many WAFs can now generate rules and policies based on legitimate network traffic analysis, making them easier than ever to deploy. In a nutshell, if you are not using one already, you probably need one! But these specialized firewalls are not the silver bullets they sometime claim to be. When vendors say that their WAF enables organizations to be protected against the OWASP Top 10 most critical web application security risks, is this really accurate? In late 2015, we conducted intensive tests on the most common commercial and open source WAFs, where a team of penetration testers tried to exploit vulnerable web applications. We tested these products to their limits against each of the OWASP Top 10, trying to bypass their attack detection algorithms. We will conclude our presentation with an overview of additional safeguards that complement the use of web application firewalls to provide a high level of security against malicious attacks.