Christian Folini -- CRS and an Abstraction Layer episode artwork

EPISODE · Aug 7, 2018 · 25 MIN

Christian Folini -- CRS and an Abstraction Layer

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How can one open-source rule set protect applications across competing products and very different architectures? Christian Folini explains the relationship between the ModSecurity engine and the OWASP Core Rule Set, including the attacks generic rules can detect and the limits of a web application firewall. Recorded at AppSec Europe, the conversation explores a gathering of vendors and contributors working to improve compatibility, feedback, and the project’s future. Christian describes the proposed abstraction layer that could separate security rules from a particular engine and bring detection closer to application code. He also discusses funding, testing, false positives, and integrating protection into continuous delivery. The result is a practical look at both the engineering and community work behind widely deployed open-source defenses.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Christian Folini:→ Christian Folini on LinkedIn→ Christian Folini’s websiteMentioned in this episode:→ OWASP Core Rule Set→ ModSecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Christian Folini and the Core Rule Set01:38 From medieval history to application security02:39 How CRS fits with the ModSecurity engine03:42 Attack coverage and a WAF’s limits06:06 Bringing vendors together at AppSec Europe08:39 A common abstraction layer for security rules12:57 Funding and contributing to open source15:30 More outcomes from the CRS gathering17:46 CRS in continuous integration and runtime protection19:42 Could CRS run inside an application runtime?20:40 Moving security decisions closer to the code23:50 Where to learn more and contribute

Episode metadata supplied by the publisher feed · Published Aug 7, 2018

Embed this episode

How can one open-source rule set protect applications across competing products and very different architectures? Christian Folini explains the relationship between the ModSecurity engine and the OWASP Core Rule Set, including the attacks generic rules can detect and the limits of a web application firewall. Recorded at AppSec Europe, the conversation explores a gathering of vendors and contributors working to improve compatibility, feedback, and the project’s future. Christian describes the ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Christian Folini -- CRS and an Abstraction Layer

0:00 25:21

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 25 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 7, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!