Forum Discussion
strongarm_46960
Nimbostratus
Mar 08, 2008ASM OWASP Top Ten Protection
When the The negative security model implemented on f5, by picking or ticking negative security model within the Enforcement screen of the ASM, I expect it to protect against the OWASP Top Ten vulnerabilities or WebAppSec Threats.
However, this only happens when additional rules from the vast rules supplied are added inorder to create a negative security, the problem is if all the rules are selected then all users request gets blocks.
How goes one know the bases of rules to start from to defend against at least OWASP Top Ten . Since 'the negative security model' (Labelled tab) rules given by F5 ASM simply isn't adequate.
Can you please tell me which of the rules I need to tick or pick in order to have protection against the OWASP Top Ten vulnerabilities. Since it clear that the negative security policy on F5 does not offer this.
Many Thanks
- Nicolas_Menant
Employee
Hi, - strongarm_46960
Nimbostratus
I have tried to answer my own question by doing more research, however, don't think there is one in the Negative security realm on the F5 ASM, my impression is that ASM is more focused on Positive security than Negative, the result I see under the ASM are too generic for Negative security deployment within my firm. - strongarm_46960
Nimbostratus
I think the ASM should have a dedicated forum aswell. be nice to talk about all those signatures, or perhaps re-writing more signature just as you do in irules. - BlurredVision_1
Nimbostratus
jquadri, there has been a new rapid deployment security policy built into ASM v9.4.4 that has helped with our implementations of ASM. It is definately worth checking out.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects