Get a free application, infrastructure and malware scan report - Scan Your Website Now

Subscribe to our Newsletter
Try AppTrana WAAP (WAF)

Managed WAF

Starts at $99

Guided onboarding, monitoring of latency, false positives, and DDoS attacks, custom rules, and more

Try Free For 14 Days

Why is Tuning a Web Application Firewall (WAF) Challenging?

Posted DateJune 25, 2019
Posted Time 4   min Read

Today, websites and web applications are judged on the basis of user experience, which is directly proportional to the time, hassle, and costs to the users and the level of security and privacy guaranteed. So, web application security and WAF (web application firewall) is not a luxury or ‘good-to-have’ commodities anymore; security is paramount for all organizations and WAF, is an indispensable part of the security process.

Why is it important to tune a WAF?

To understand the importance of tuning a web application firewall, we must first understand how web application firewall works. The WAF is the first line of defense at the edge and protective shield between the application and the web traffic. Its functioning is dependent on the specific set of rules called policies that tell the WAF which vulnerabilities, gaps, attack behaviors to look for, what to do if these are found, how to protect the application, etc.

It is, therefore, important to tune a WAF for the following reasons.

  • Business needs and risk profiles vary widely for different organizations. So, the WAF policies must be customized and tuned to these specific needs and profiles of the organization.
  • Developers make changes to codes and the application features and the WAF needs to be equipped for these fast-paced changes.
  • The threat landscape is fast-changing as the attackers are leveraging technology to fund new and innovative ways to orchestrate attacks.
  • The applications are built on different web development frameworks and each of the frameworks has its strengths and drawbacks. The gaps in the framework will impact the security level of the application itself and the rules of the WAF must be tuned accordingly.
  • Only 41% of the traffic is known to be originating from humans and the rest are bots. Tuning the policies and settings of the WAF is critical to identifying bad bots and improving the security posture of the application. More importantly, WAF should also ensure it does not prevent a good bot (example search engines)

Why is it challenging to tune a web app firewall?

The biggest conundrum with deploying a web application firewall is that it must keep away bad actors, botnets, and malicious traffic from accessing/ snooping the web application but in the process, it must not block legitimate traffic from accessing the website/ web application. If a business has to make a tradeoff between availability and security most likely they will choose availability as without availability securing the website is of no use.  Ensuring the WAF policies are designed to not have any false positives requires special expertise and coordinated working between the application team and the security experts throughout the lifecycle of the application development.

With the fast-changing threat landscape and nature of attacks, if the set of rules aggressively works with the blacklisting model alone, the possible outcome is a high number of false positives – valid requests getting denied. These false positives are adversarial to the very logic and purpose of deploying a web app firewall. Too many false positives indicate that the WAF is doing the same thing that a successful attack will do and is, therefore, counterproductive for the business employing it. The web app firewall and its rules must be custom-built and tuned on a regular basis to ensure zero false positives. AppTrana offers an intelligent WAF which is built with surgical accurate rules written by security experts who work with the application team to ensure Zero WAF false positives…

The next challenge in tuning the web app firewall permeates from the speed at which developers the change code, add and remove features and introduce updates to the application. As mentioned earlier, websites and web applications are judged by users on the basis of the user experience rather than colors and designs. Users expect speed, agility, and security from the applications. Growth-oriented organizations and developers strive to keep their applications and UX on par with or edgier than competitors to drive more traffic and ensure more conversions. So, the policies must be tuned such that it minimizes overhead and performance impact for good traffic

Apart from the known vulnerabilities, there are vulnerabilities that arise from business logic flaws that are specific to every business. The WAF policies need to be configured to tackle these vulnerabilities as well. For this, security experts need to understand how the business operates and how the changes in business policies will affect the application.

Tuning a web application firewall can also be challenging due to a lack of visibility, real-time insights, and security analytics that security personnel can use to tune the rules. Comprehensive solutions like AppTrana which also provides manual Pen testing provides complete visibility into business logic flaws and offer 24×7 visibility of the risk posture along with security analytics and real-time insights which are leveraged by the security experts to tune the WAF on a regular basis to ensure that the security solution is effective. Tuning ensures besides preventing the applications from attacks and exploits, it allows only relevant traffic to be processed by the backend application and they do not have to pay for bandwidth for irrelevant traffic or have noise in their logs with irrelevant data. A fully managed web application firewall with continuous tuning can hence be thought of as providing optimization and agility to the core business on top of ensuring it is protected from attacks.

Stay tuned for more relevant and interesting security articles. Follow Indusface on FacebookTwitter, and LinkedIn.

Web Application Scanning

Vivek Gopalan

Vivekanand Gopalan is a seasoned entrepreneur and currently serves as the Vice President of Products at Indusface. With over 12 years of experience in designing and developing technology products, he has a keen eye for building innovative solutions that solve real-life problems. In his previous role as a Product Manager at Druva, Vivek was instrumental in creating the core endpoint data protection solution which helped over 1500 enterprises protect over a million endpoints. Prior to that, he served as a Product Manager at Zighra, where he played a crucial role in reducing online and offline payment fraud by leveraging mobile telephony, collective intelligence, and implicit user authentication. Vivek is a dynamic leader who enjoys building and commercializing products that bring tangible value to customers. In 2010, before pursuing MBA, he co-founded a technology product company, Warmbluke and created a first-of-its-kind innovative Civil Engineering estimator software called ATLAS. The software was developed for both enterprise and for SaaS users. The product helps in estimating the construction cost using CAD drawings. Vivek did his MBA from Queen's University with Specialization in New Ventures. He also holds a Bachelor of Technology degree in Information Technology from Coimbatore Institute of Technology, Anna University, one of the prestigious universities in India. He is the recipient of the D.D. Monieson MBA Award, Issued by Queen's School of Business, presented to a student team which has embraced the team-learning model and applied the management tools and skills to become a peer exemplar. In his spare time, Vivek likes to go on hikes and read books.

Share Article:

Join 47000+ Security Leaders

Get weekly tips on blocking ransomware, DDoS and bot attacks and Zero-day threats.

We're committed to your privacy. indusface uses the information you provide to us to contact you about our relevant content, products, and services. You may unsubscribe from these communications at any time. For more information, check out our Privacy Policy.

Related Posts

Evaluating WAF Solutions
Evaluating WAF Solutions?

Evaluating the merits and drawbacks of firewalls to pick the right security solution is essential for hardening security posture.

Read More
blocking bots
Blocking Bots: Why We Need Advanced WAF?

Learn why advanced WAF is crucial in blocking bots and protecting your website from malicious activities. Enhance your web security now.

Read More
Managed Cloud WAF
Managed Cloud WAF: A Must-Have to Stop Website Attacks

A managed cloud WAF is software that hosts a web application firewall and is provided as SaaS. Know more on how to stop website attacks.

Read More

AppTrana

Fully Managed SaaS-Based Web Application Security Solution

Get free access to Integrated Application Scanner, Web Application Firewall, DDoS & Bot Mitigation, and CDN for 14 days

Get Started for Free Request a Demo

Gartner

Indusface is the only cloud WAAP (WAF) vendor with 100% Customer Recommendation for 3 consecutive years.

A Customers’ Choice for 2022 and 2023 - Gartner® Peer Insights™

The reviews and ratings are in!