Chapter 49. Modern WAF Deployment and Management Paradigms
Raj Badhwar
Given the business need and customer experience–driven digital transformation of our applications and the rapid migration toward the (public) cloud, the WAF is an important tool for CISOs and other cybersecurity professionals to protect these digitally transformed, internet-facing (high-risk) web applications and services. As part of the application security controls, real-time monitoring and blocking of threats becomes crucial. Understanding WAF capability, and deploying and managing it, is a must-have skill set for application security professionals.
This essay talks about the modern way of hosting WAFs and provides the separation of roles and responsibilities between the security team and the cloud providers on how best to operationally manage the WAF infrastructure.
Some of the commonly used WAF deployment architectures are as follows.
On Premises WAF Infrastructure for Hybrid Cloud
In the case of a hybrid (public/private) cloud deployment, one legacy architecture that has been used in the recent past is to use an on premises hosted WAF to protect both on premises and cloud-hosted applications. This is generally done by using Domain Name System (DNS) techniques to redirect any application traffic destined for the cloud-hosted application through the on premises hosted WAF, which is primarily configured ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access