D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

22
The Incapsula WAF: Your Best Line of Defense Against Application Layer Attacks Ehud Cohen Product Manager

Transcript of D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Page 1: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

The Incapsula WAF: Your Best Line of Defense Against Application Layer AttacksEhud Cohen

Product Manager

Page 2: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

BIO

Ehud CohenTwo kids Three years at

Imperva Incapsula

Over 13 years in the

business, in various

different roles such

as application, R&D

and project

management

Continuously

challenge previous

assumptions to

find a better

solution

© 2017 Imperva, Inc. All rights reserved.

Page 3: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

BOTs are coming already here

Page 4: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

BOTs Evolution

Page 5: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Old school technologies:CAPTCHA

SubmitSubmit

© 2017 Imperva, Inc. All rights reserved.

Page 6: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

WAF offering: Cookiechallenge

Page 7: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Hackers response:Save cookie

© 2017 Imperva, Inc. All rights reserved.

Page 8: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

WAF offering: JS challenge

© 2017 Imperva, Inc. All rights reserved.

Page 9: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Hackers response:Browser look alike

© 2017 Imperva, Inc. All rights reserved.

Page 10: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

WAF offering: Header Signatures

© 2017 Imperva, Inc. All rights reserved.

Page 11: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Hackers response:Selenium driver

© 2017 Imperva, Inc. All rights reserved.

Page 12: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

WAF offering: fingerprinting

Page 13: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Hackers response:Piggyback legitimatesessions

© 2017 Imperva, Inc. All rights reserved.

Page 14: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

The IncapsulaWay

Page 15: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

“Session-based, out-of-the-

box WAF with minimal latency”

© 2017 Imperva, Inc. All rights reserved.

Page 16: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

IncapRules

Session based

Single stack

Home grown technology

Page 17: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks
Page 18: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

© 2017 Imperva, Inc. All rights reserved.

Page 19: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Advanced automatic BOT mitigation

High visibility into attacks

© 2017 Imperva, Inc. All rights reserved.

Page 20: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks

Thank you for your time.

© 2017 Imperva, Inc. All rights reserved.

Page 21: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks
Page 22: D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application Layer Attacks