Use ModSecurity Web Application Firewall to Mitigate OWASP's Top 10 Web Application Vulnerabilities

S. Lokesh Raju, Santosh Sheshware, Ruchit R. Patel · River Publishers eBooks · 2022

In this era of globalization, web applications have become a core component for any organization to thrive and flourish. As the users of Internet increase, the attack on web applications has also increased. The web application firewall (WAF) is deployed to protect web applications and web services as it focuses on the 7th layer: the application layer of the OSI model. WAF acts a security tool which shields web applications and web application servers from Top 10 open web application security project (OWASP) attacks. When a web application is protected by WAF, WAFs act like a interface providing inclusive protection by validating every request with specified ‘Sec Rules.’ WAFs protect against a number of application layer security threats which are usually not protected by numerous tools like intrusion detection system (IDS), intrusion prevention system (IPS) and other categories of firewalls. As normal firewall installed for network layer protection and does not work for application layer security issues, this web applications can be easily attacked by hackers. In this chapter, we will discuss on how to set up and use ModSecurity WAF with Nginx (Dockerized) with log monitoring using Elastic Stack thus offering an additional layer of security.

Read the paper · More papers on PaperTik