Главная
Study mode:
on
1
Intro
2
Topics to Cover
3
Akamai & OWASP CRS
4
Akamai Intelligent Platform
5
CSI Platform Statistics
6
CSI High Level Architecture
7
Yoda (Distributed Query Engine)
8
Sample Data App - SARA
9
WAF Accuracy Lingo
10
Things You Need to Know
11
Akamai WAF Testing (AWT) Framework
12
AWT Built-In Test Cases
13
AWT Reports - False Positives Analysis
14
Risk Groups
15
Multiple Thresholds
16
CRS Issue #2
17
HTTP Violations
18
960015 - Research into 3 hours of triggers
19
Cookies
20
Score Spreading Across Selectors
21
Rule Inefficiency
22
Summary
Description:
Explore a comprehensive conference talk on harnessing petabytes of Web Application Firewall (WAF) statistics to analyze and improve web protection in the cloud. Delve into the challenges of managing massive amounts of security event data and learn about a unique platform for collecting, analyzing, and distilling WAF security intelligence information. Discover insights on the OWASP ModSecurity Core Rule Set project's accuracy, common attack trends, and suggestions for optimizing its use. Gain knowledge about using big data for web application security trend analysis, Akamai's Cloud Security Intelligence (CSI) platform, and a demo of the Security Analytics Research Application (SARA) for navigating and analyzing big WAF data. Examine the precision, recall, and accuracy statistics of the OWASP CRS project against real-world traffic, and learn about frequent false positive scenarios and their remediation. Understand the top 10 web application attacks, trends, and triggering rules statistics to enhance your web protection strategies in the cloud era. Read more

Big Data Intelligence - Harnessing Petabytes of WAF Statistics for Web Protection

OWASP Foundation
Add to list
0:00 / 0:00