Главная
Study mode:
on
1
Intro
2
The seatbelt analogy
3
Agenda
4
Replication Firewall
5
What is ModSecurity
6
Demo
7
Research
8
Rule Files
9
Demonstration
10
Paranoia Levels
11
Protocol Enforcement
12
stricter siblings
13
rule exclusions
14
Questions
15
Improvements
Description:
Explore the OWASP ModSecurity Core Rule Set 3.0 in this comprehensive conference talk from AppSec EU 2017. Learn about the first line of defense against web application attacks, including installation, key concepts like anomaly scoring and thresholds, paranoia levels, and handling false positives. Discover how to implement this generic attack detection ruleset for ModSecurity or compatible web application firewalls, designed to protect against threats outlined in the OWASP Top Ten. Gain insights into important rule groups, stricter siblings, sampling mode, and pre-defined rule exclusions for popular web applications. Follow along with demonstrations and understand the improvements made in this major release, all while minimizing false alerts in your web application security setup.

Introducing the OWASP ModSecurity Core Rule Set 3.0 - AppSec EU 2017

OWASP Foundation
Add to list