Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /home/zhenxiangba/zhenxiangba.com/public_html/phproxy-improved-master/index.php on line 456
Web Application Firewall Evaluation Criteria - Web Application Security Consortium
[go: Go Back, main page]

 

Contributors

Robert Auger
(SPI Dynamics)

Ryan C. Barnett
(EDS)

Charlie Cano
(F5)

Anton Chuvakin
(netForensics)

Matthieu Estrade
(Bee Ware)

Sagar Golla
(Secureprise)

Jeremiah Grossman
(WhiteHat Security)

Achim Hoffmann
(Individual)

Amit Klein
(Individual)

Mark Kraynak
(Imperva)

Vidyaranya Maddi
(Cisco Systems)

Ofer Maor
(Hacktics)

Cyrill Osterwalder
(Seclutions AG)

Sylvain Maret
(e-Xpert Solutions)

Gunnar Peterson
(Arctec Group)

Pradeep Pillai
(Cisco Systems)

Kurt R. Roemer
(NetContinuum)

Kenneth Salchow
(F5)

Rafael San Miguel
(daVinci Consulting)

Greg Smith
(Citrix Systems)

David Movshovitz
(F5)

Ivan Ristic
(Thinking Stone (ModSecurity) ) [Project Leader]

Ory Segal
(Watchfire)

Ofer Shezaf
(Breach Security)

Andrew Stern
(F5)

Bob Walder
(NSS Group)





Last document update: January 14th, 2006

Complete Document v1.0

[HTML] size 66k (MD5 SUM: b03f5860377c5a769b82602f6f67db39)
[TEXT] size: 42k (MD5 SUM: 3393f8ead346749a5e7f127aad4ec1e7)
[PDF] size: 102k (MD5 SUM: 4d4eda95d3d204f066c8b918b4bd33df )

Resources

WAFEC, or how to choose WAF technology
[PPT size: 6.5M (MD5 SUM: 4cadf27fe0866a701a1f4aa78b32fe56)



Description
Develop the industry standard testing criteria for evaluating the quality of web application firewall solutions.

Web application firewalls (WAF) are a new breed of information security technology designed to protect web sites from attack. WAF solutions are capable of preventing attacks that network firewalls and intrusion detection systems can't, and they do not require modification of application source code. As today's web application attacks expand and their relative level of sophistication increases, it is vitally important to develop a standardized criteria for product evaluation. How else can we accurately compare or measure the performance of a particular solution?

Establishing an evaluation criteria can be a difficult task even for a skilled web security professional. It is unlikely the evaluators have the time or the skills to create comprehensive criteria of their own. This fact makes it very difficult to compare WAF products offered by various different vendors. Therefore creation of any evaluation criteria must include the direct involvement of WAF vendors and the web security community.

The goal of this project is to develop a detailed web application firewall evaluation criteria; a testing methodology that can be used by any reasonably skilled technician to independently assess the quality of a WAF solution.

If you would like to be involved with the project, please contact Ivan Ristic

Search this site
Home :: About Us :: Projects :: Mailing Lists :: Library :: News :: Links :: Contact Us

© Copyright 2005, Web Application Security Consortium. All rights reserved.