Cloud computing was not designed for security, although organizations such as Cloud Security Alliance (CSA) and Open Web Application Security Project (OWASP) are making great strides in helping the industry solve the myriad security problems confronting cloud computing. The benchmark guidelines established by the CSA in the document, Guidance for Critical Areas of Focus in Cloud Computing, is a great first step. This white paper is intended to pick up where the CSA guide left off in terms of defining what a distributed web application firewall (dWAF) should look like in order to meet the standards set within the CSA document.
Web application security in a cloud has to be scalable, flexible, virtual and easy to manage.
A WAF must escape hardware limitations and be able to dynamically scale across CPU, computer, server rack and datacenter boundaries, customized to the demands of individual customers. Resource consumption of this new distributed WAF must be minimal and remain tied to detection / prevention use instances rather than consuming increasingly high levels of CPU resources. Clouds come in all sizes and shapes, so WAFs must as well.
The dWAF must be able to live in a wide variety of components to be effective without adding undue complexity for cloud service providers. Today’s providers are using a variety of traditional and virtual technologies to operate their clouds, so the ideal dWAF should accommodate this mixed environment and be available as a virtual software appliance, a plugâ€in, SaaS or be able to integrate with existing hardware. Flexibility with minimal disruption to the existing network is central. A webâ€based user interface must allow customers to easily administrate their applications.
Art of defence’s patent-pending dWAF technology hyperguard and its multi-tenant software architecture solve the main limitations traditional WAF’s face securing cloud applications. The distributed software-only solution is rapidly scalable and ideal for leveraging virtualized resources on its own. A hyperguard customer is able to manage all functionality like ruleset-configuration or attack analysis via a easy to use management interface. The dWAF hyperguard from art of defence is the ideal solution for cloud provider.