Home > Ask the Security Experts > Application Security Questions & Answers > Is my security program ready for Web application firewall deployment?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Is my security program ready for Web application firewall deployment?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 22 April 2009
Is a Web application firewall deployment more appropriate for enterprises that have a mature software security program, or can any company with any type of security program benefit from implementing one?

>
Occasionally, I come across an organization that has taken the defense-in-depth approach to security too far. It's an organization that has every conceivable security device plugged into its network somewhere. While it's great to see security being taken seriously, this type of setup is never going to be cost-effective or efficient. With that said, it's good to hear you asking when Web application firewall deployment may be appropriate. Despite many vendors' claims, having the latest product isn't a guarantee of security.

If we look to the Payment Card Industry Data Security Standard (PCI DSS) for some guidance, we see that it offers two options to protect Web applications: a review of all Web application code, or the deployment of a WAF. It goes on to say "Proper implementation of both options would provide the best multi-layered defense."

Taking your two example enterprises, the first, with a mature software security program, will no doubt already perform source code reviews and vulnerability assessments but could probably still benefit from installing a WAF. The second enterprise should definitely consider installing a WAF, as it's less likely to have the staff with both the extensive application development experience and security expertise required to carry out internal code reviews.

A good security policy will define your objectives and requirements of how you want to secure your data. Since each Web application is unique, risk mitigation must be tailored to the specific application, protecting against the potential threats identified during the threat-modeling process. To ensure a Web application firewall deployment will provide a real benefit, be sure to review which risks it will safeguard against. And from there you can decide which security devices are appropriate to meet those requirements.

It can, however, be difficult to compare the different WAFs once you have narrowed down your choices to a shortlist. Thankfully, the Web Application Security Consortium (WASC) develops and advocates standards for Web application security. They have created the Web Application Firewall Evaluation Criteria (WAFEC), the aim of which is to provide a way for someone to compare one firewall to another. Their testing methodology can be used by any reasonably skilled technician to independently assess the quality of a WAF product.

WAFs, though, aren't a cure-all. They won't protect against application logic flaws or underlying network and operating system-level vulnerabilities. And there are ongoing costs, too. Network administrators must learn how to install, configure and maintain it. You'll also need to ensure that your IT department has the resources to deal with any attacks it identifies, as well as its day-to-day administration. For example, WAFs have more extensive logging capabilities than older packet filter firewalls. Administrators will need time to make the most of this additional information.


BROWSE BY TAG
Application Security,   Application and Platform Security,   Web Security Tools and Best Practices,   Web Application Security,   Web Application and Web 2.0 Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Application Security
Security must-haves after building a Web application
How to secure online collaboration applications like Google Wave
How secure is an email with a .pdf attachment?
How to secure a .pdf file
How do hackers bypass a code signing procedure to inject malware
Do Facebook URL security concerns justify blocking social networks?
How to prevent ActiveX security risks
Should security tests be part of a software quality assurance program?
What are Google Chrome's security features?
Is there a way to block iPhone widgets that bypass Web filters?

Web Application Security
Noted cryptographer on SSL, encryption and cloud computing
Security must-haves after building a Web application
How to secure online collaboration applications like Google Wave
Improving software with the Building Security in Maturity Model (BSIMM)
Attackers zero in on Web application vulnerabilities
Self-defending Web applications thwart attacks
Facebook, McAfee partner to fix social network security issues
Web application attacks security guide: Preventing attacks and flaws
Using unique device identification for bank website security
Information security book excerpts and reviews

Web Application and Web 2.0 Threats
Social networking risks, benefits for enterprises weighed by RSA panel
Noted cryptographer on SSL, encryption and cloud computing
Microsoft issues advisory on new IE security vulnerability
Security must-haves after building a Web application
How to secure online collaboration applications like Google Wave
How to turn off Google Buzz and avoid privacy issues
CISOs take measured steps to reduce social media risks
Torrent phishing scheme trips up Twitter users
Browser exploit kit probe highlights need for patching, vigilance
Attackers continue barrage of SEO attacks

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
anonymous Web surfing  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cookie poisoning  (SearchSecurity.com)
dictionary attack  (SearchSecurity.com)
distributed denial-of-service attack  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
National Computer Security Center  (SearchSecurity.com)
threat modeling  (SearchSecurity.com)
trigraph  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts