Web Application Firewall plus Application Delivery Controller Combination takes Security to New Levels
Last Update: Sunday, April 13, 2014 : 12:12 (+4GMT)
Author: Glen Ogden, Regional Sales Director, Middle East at A10 Networks
Although conventional network firewalls serve us well, significant changes in application delivery are allowing new vulnerabilities to emerge. These demand more specialized application security proxies such as the web application firewall (WAF), an appliance, server plugin, or filter that applies a set of rules to an HTTP conversation.
As more applications are migrated to the Web, the role of the WAF combined and integrated with an application delivery controller (ADC) is becoming increasingly important. Information professionals are realizing the security benefits this potent combination can deliver.
These include deep packet inspection, DDoS protection and SSL Offload capabilities as part of richer, multi-layered security architecture that enhances security while reducing cost and operational complexity. With the WAF becoming mandatory in securing today’s Internet and its best practice for deployment, the WAF-plus-ADC combination is taking security to new levels.
Web application threats
Network firewalls are part of an IT security landscape that is becoming increasingly specialized and smarter. They are unable to inspect traffic content, focusing primarily on the networking aspect of traffic. They remain relatively unintelligent with respect to high level application behavior and context, and unable to cope with threats to Web application deployments such as the top 10 risks complied by the Open Web Application Security Project (OWASP). Examples follow:
•Injection: SQL Injection Attacks use a Web form or other exchange mechanism to insert SQL commands or commands containing SQL special characters. By sending these SQL commands, the attacker can trigger the backend SQL database to execute the injected commands and allow unauthorized users to obtain sensitive information from the database.
•Cross-Site Scripting (XSS): XSS attacks exploit a Web server that does not validate data coming from another site. XSS can enable the attacker to obtain sensitive information, or to compromise a Web server.
•Sensitive Data Exposure: If Web applications do not protect sensitive data such as credit card numbers or Social Security Numbers (SSN), attackers are able to conduct identity theft, credit card fraud, or other crimes.
•Cross-Site Request Forgery (CSRF): CSRF attacks forge a user to send an HTTP request, including the victim’s session cookie, to a vulnerable Web application. To the vulnerable Web application, this appears to be a legitimate request coming from the victim.
What is WAF?
The concept of a ‘firewall’ has been gradually supplemented by a bewildering array of security ‘point solutions’. These include proxy firewalls, stateful firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), fraud-detection systems, anti-virus (AV), and emerging next generation firewalls.
As a next generation firewall, a WAF filters all application access, inspecting both the traffic towards the Web application and the response traffic from the application. By securing both the application infrastructure as well as the application user, a WAF complements traditional network firewalls, which are not designed to protect at this granular level.
Below are use cases of attack mitigation:
•The WAF can prevent buffer overflow attacks by setting accepted maximum thresholds for aspects of HTTP requests, and blocking requests that exceed the configured limits.
•The WAF can strip HTTP response headers to ‘cloak’ server information that can equip a hacker to target an attack on your Web servers. For example, the WAF can cloak an HTTP response header to hide the operating system that is running on your servers. Exposed HTTP headers can enable a hacker to more narrowly target your servers with attacks that are specific to the servers’ operating systems.
Best practice WAF deployment
Not just deployed as a point solution to address a certain type of security risk, a WAF now appears increasingly as an integrated component, either within conventional firewalls, as server-based solutions, or on high performance Web aggregation points such as Application Delivery Controllers (ADCs). This also reflects the enterprise’s desire to improve ROI from network security by consolidating multiple devices and reducing deployment and troubleshooting time and cost.
An ADC by definition must implicitly understand Web traffic and the associated security contexts, thus is a natural place to include a WAF module as part of a service chain. This is especially so when considering complementary features such as SSL Offload – utilizing the ADC to terminate encrypted SSL transactions, to simplify certificate management, and offload the CPU intensive encryption/decryption setup from the Web server farm.
Since an application delivery firewall (ADF) is inherently fluent in application protocols, it can monitor and act on behavior, both forensically, and at scale. The ADF inspects a full spectrum of message envelopes, from IPv4, IPv6, TCP, HTTP, SIP, DNS, SMTP, FTP, through to Diameter and RADIUS, enabling sophisticated deep packet analysis based on protocol as well as the payload.
This allows the ADF to detect anomalies indicating an attack in progress and to take appropriate action. For example, the ADF can detect the number of Layer 7 connections per second, per client, and impose various rate-limiting schemes that have proven effective in mitigating Layer 3, Layer 4 and Layer 7 resource attacks, such as DDoS protection.
When a WAF is implemented within an ADC the benefits are obvious by virtue of where the ADC resides. ADCs sit at the border between data centers serving Web applications and the wider Internet, effectively acting as a load balancing proxy and intelligent cache for application transactions and content.
ADCs get a complete view of the whole messaging stack (L2-L7) and are routinely involved in packet manipulation such as IP address, port mapping and URL rewrite. While the most obvious use of the ADC is for load balancing, high availability (HA) and content caching across applications servers, this privileged position of trust and oversight in the network topology means it is becoming increasingly common for ADCs to provide value-added security at scale, reducing risk and improving both information security and availability.
These security features include pre-authentication, SSL Offload, SSL Intercept, and DDoS mitigation. Typically a high-end ADC will also include custom scripting to enable Deep Packet Inspection (DPI) and manipulation of traffic, endpoint information and even Web content.
In essence, a WAF as part of an ADC is a natural and complementary extension to the core application delivery functions. While conventional firewalls have a key role to play in perimeter security, the ADC typically sits in front of Web application servers as the last stop in the chain of defense. This enables organizations to deal with both internal and external misuse attempts, with the confidence that policy enforcement is being done in the right place, at an appropriate level, and with intimate knowledge of application logic and associated vulnerabilities.
This is particularly important if the organization is deploying virtualization, and wishes to implement different policies for different virtual domains. More importantly, a WAF may be the last word in internal security controls, and important with the increased trend towards BYOD, where mobile technology is increasingly brought inside the workplace, bypassing many of the perimeter controls.
PR Submited on DubaiPrNetwork.com
- Bridal Season Is Officialy Open with Benefit Cosmetics!... [2473-Views]
- Dubai Summer Surprises 2026 Unveils an Action-Packed Calendar of Shopping, Din... [2018-Views]
- Joyalukkas Strengthens US Footprint with 8th Showroom in Iselin, New Jersey... [1994-Views]
- Malabar Gold & Diamonds continues its expansion in North America: Launches 8th... [1812-Views]
- Mercato Takes Media on a Magical Summer Journey with The Grand Comedy Circus a... [1585-Views]
- Hamdan bin Zayed chairs 2nd Environment Agency – Abu Dhabi board meeting in 20... [1484-Views]
- Group-IB launches Purple Teaming service to close the gap between security inv... [1192-Views]
- First winner of 'Win Your Home in Dubai' initiative announced as citywide home... [1128-Views]
- Dubai Gears Up for a Spectacular Start to 29th Dubai Summer Surprises with Liv... [1091-Views]
- Government of Fujairah Signs Agreement to Purchase Gasoline Production from Et... [951-Views]
- Global Talent Attraction and Retention Committee Convenes Tenth Meeting to Rev... [920-Views]
- MAIR Group and Makani Real Estate Announce Mall of Al Ain Redevelopment and Ex... [894-Views]
- Schneider Electric joins the World Economic Forum Lighthouse Operating System ... [888-Views]
- EGA wins the AI Vision and Strategy Award at the 2026 Manufacturing Leadership... [882-Views]
- EGA inaugurates UAE's largest aluminium recycling plant... [828-Views]
- Kia introduces PV5 as its first Platform Beyond Vehicle (PBV) model in Middle ... [822-Views]
- G-SHOCK MTG-B4000BD-1A: A New Language of Structural Beauty... [817-Views]
- The New SHEGLAM Lashlighter Root-Up Lash Primer Gets to the Root of the Matter... [805-Views]
- Dubai Summer Surprises: Shop, Save, and Win as the Great Dubai Summer Sale Arr... [802-Views]
- New economic licences in Abu Dhabi increase 21% in Q1 2026... [796-Views]




![Botim and BDO Unibank [SA1] Advance Financial Readiness for UAE-Bound Filipinos](/citylife/press_images/192940.jpg)
