Towards Model-Driven Virtual Patching for Web Applications
Gustavo Betarte, Rodrigo De La Fuente, Rodrigo Martinez, Juan Pirez, Felipe Zipitría · 2016
The use of virtual patching tools to prevent attackers exploiting vulnerabilities of a web application is a widely adopted defensive approach. The constant evolution of applications, and thereby of attack techniques, requires a big maintenance and tuning effort to ensure that the remediation patches are working correctly. We put forward in this paper a tool supported process here security requirements expressed in a high level language over a model of the vulnerable application can be translated into rules enforceable by virtual patching tools. We present and discuss the results of applying this approach for securing WAVSEP, a vulnerable web application designed to help assessing the features, quality and accuracy of web application vulnerability scanners.