Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Christian Folini -- CRS and an Abstraction Layer

25 min7 augusti 2018

Om avsnittet

How can one open-source rule set protect applications across competing products and very different architectures? Christian Folini explains the relationship between the ModSecurity engine and the OWASP Core Rule Set, including the attacks generic rules can detect and the limits of a web application firewall. Recorded at AppSec Europe, the conversation explores a gathering of vendors and contributors working to improve compatibility, feedback, and the project’s future. Christian describes the proposed abstraction layer that could separate security rules from a particular engine and bring detection closer to application code. He also discusses funding, testing, false positives, and integrating protection into continuous delivery. The result is a practical look at both the engineering and community work behind widely deployed open-source defenses.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Christian Folini:
Christian Folini on LinkedIn
Christian Folini’s website

Mentioned in this episode:
OWASP Core Rule Set
ModSecurity

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Christian Folini and the Core Rule Set
01:38 From medieval history to application security
02:39 How CRS fits with the ModSecurity engine
03:42 Attack coverage and a WAF’s limits
06:06 Bringing vendors together at AppSec Europe
08:39 A common abstraction layer for security rules
12:57 Funding and contributing to open source
15:30 More outcomes from the CRS gathering
17:46 CRS in continuous integration and runtime protection
19:42 Could CRS run inside an application runtime?
20:40 Moving security decisions closer to the code
23:50 Where to learn more and contribute

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.