Impact of Paranoia Levels on the Effectiveness of the ModSecurity Web Application Firewall

Jatesh Jagraj Singh, Hamman Samuel, Pavol Zavarsky · 2018

Organizations use various approaches to safeguard their web applications. One such approach is to deploy a web application firewall. These firewalls work when configured with appropriate rules. Optimal selection of rules ensure that the firewall will properly identify attacks and hence block them or take appropriate actions. Our study analyzes various bypass attack vectors against the popular ModSecurity web application firewall with the open source Core Rule Set (CRS) version 3. The attack vectors focus on the OWASP Top 10 risks, and are tested against different settings of the paranoia level in ModSecurity. Our aim is to assist in better transparency about the default configuration of the CRS with ModSecurity and hence help administrators in taking informed decisions about web applications security for different paranoia levels configurations.

Read the paper · More papers on PaperTik