Guardians of the Enterprise — Insights from leading cyber experts.

Listen Now →

WAF Solution To Prevent Exploitation Through Browser Based Plugin

ABSTRACT :

It is one of the organizations which has web-based forms on their website for users to input the data for registration and sign up. Application is designed to enroll the users and provides an appointment scheduling platform wherein the Applicant logs in to their web portal and book an appointment for specific use case.

KEY CHALLENGES:

The problem statement reported by the customer illustrates that some malicious users were performing dummy registrations and booking dummy appointments constantly which is impacting the business use case as genuine users are not able to get the online benefit.

As a first level of defense customer has applied the IP based rate limiting rules which helps them to get protection up to some extend against the attackers which were sending the requests more than the threshold value configured.

STRATEGY & RECOMMENDED SOLUTION:

To get a success, we strategize to enable Advance logging at WAF level and understand the malicious traffic pattern. With this, we were successfully able to capture below details.

RESULTS :

The custom WAF policy was built, simulated by our Security experts, and was activated in the production. It was concluded that all such bad traffic was blocked successfully, and genuine users were able to signup and book the appointments. This helped the customer to retain the brand reputation with online business.

Indusface
Indusface

Indusface is a leading application security SaaS company that secures critical Web, Mobile, and API applications of 6,500+ global customers using its award-winning fully managed platform that integrates web application scanner, web application firewall, DDoS & BOT Mitigation, CDN, and threat intelligence engine.

APPTRANA WAAP

Web apps, APIs, and AI systems. Protected from day one. Autonomously.

OWASP Top 10 protection from day one. Zero false positives, guaranteed. Vulnerabilities discovered and patched at the edge. Experts verify enforcement before policies go live. 24x7 managed services included.

✓ Gartner Customers' Choice 4 years running 100% customer recommendation rate

No credit card required