EPISODE · Aug 7, 2018 · 25 MIN
Christian Folini -- CRS and an Abstraction Layer
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How can one open-source rule set protect applications across competing products and very different architectures? Christian Folini explains the relationship between the ModSecurity engine and the OWASP Core Rule Set, including the attacks generic rules can detect and the limits of a web application firewall. Recorded at AppSec Europe, the conversation explores a gathering of vendors and contributors working to improve compatibility, feedback, and the project’s future. Christian describes the proposed abstraction layer that could separate security rules from a particular engine and bring detection closer to application code. He also discusses funding, testing, false positives, and integrating protection into continuous delivery. The result is a practical look at both the engineering and community work behind widely deployed open-source defenses.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Christian Folini:→ Christian Folini on LinkedIn→ Christian Folini’s websiteMentioned in this episode:→ OWASP Core Rule Set→ ModSecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Christian Folini and the Core Rule Set01:38 From medieval history to application security02:39 How CRS fits with the ModSecurity engine03:42 Attack coverage and a WAF’s limits06:06 Bringing vendors together at AppSec Europe08:39 A common abstraction layer for security rules12:57 Funding and contributing to open source15:30 More outcomes from the CRS gathering17:46 CRS in continuous integration and runtime protection19:42 Could CRS run inside an application runtime?20:40 Moving security decisions closer to the code23:50 Where to learn more and contribute
Embed this episode
What this episode covers
How can one open-source rule set protect applications across competing products and very different architectures? Christian Folini explains the relationship between the ModSecurity engine and the OWASP Core Rule Set, including the attacks generic rules can detect and the limits of a web application firewall. Recorded at AppSec Europe, the conversation explores a gathering of vendors and contributors working to improve compatibility, feedback, and the project’s future. Christian describes the ...
Ready to play
Christian Folini -- CRS and an Abstraction Layer
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.