Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
WAF BASICS- Part2
Rating: 4.0 out of 5(210 ratings)
1,801 students

WAF BASICS- Part2

Application Security Manager Basics
Created byVineet Singh
Last updated 12/2020
English
English [Auto],

What you'll learn

  • Candidates will gain intermediate level of knowledge on product solution- ASM

Course content

1 section13 lectures5h 15m total length
  • Positive Security Policy Building- Part 146:56

    Learn to build a positive security policy for web apps by defining explicit file types, URIs, and parameters, with wildcards and learning modes never, always, selective, and come back.

  • Positive Security Policy Building- Part 240:56

    Explore building a positive security policy via enforcement readiness and staging, learning entities from traffic, and refining rules with traffic learning to prevent false positives.

  • Cookie and Other Headers Security45:49

    Learn how cookies and headers are secured through an application security policy, including signed and infused cookies, allowed versus enforced keys, and tamper detection with digests and signatures.

  • Reporting21:39

    Explore Aasim reporting, featuring an overview with customizable graphical reports and a reporting section with filters, widgets, and the ability to export PDFs or send emails.

  • Logging- Part 118:50

    Explore how the WAF logs system and administrative events locally, view logs via GUI or CLI, and configure logging profiles to filter traffic and forward data to a remote server.

  • Logging- Part 210:16

    Configure a logging profile for local and remote UDP logging, attach it to the virtual server's security policy, enable blocking, and verify logs after enabling send content events.

  • Response Logging12:54

    Enable and verify response logging in the F5 WAF by creating a response logging profile, attaching it to a security policy, and testing with application requests to see logged responses.

  • Advanced Parameter Handling- Static Parameter Protection24:15

    Learn to protect static parameters by defining allowed values, applying a security policy, and enforcing blocking for illegal static parameter values in payment parameters.

  • Advanced Parameter Handling- Dynamic Parameter Protection28:15

    Learn how to protect dynamic parameters with extraction rules, dynamic barometer values stored in a DCB frame cookie, and blocking policies that detect tampering and enforce illegal dynamic parameter values.

  • Parameter Levels9:53

    Explore parameter levels in web apps—global, user-level, and flow parameters—and how security policies enforce static, dynamic, and sensitive values from most to least specific.

  • Policy Diff & Security Policy Export-118:55

    Use policy depth to compare two security policies across production and staging, identify differences in language, protocol, and sensitivity, and merge or export changes with copy, original, or make-a-copy modes.

  • Policy Diff & Security Policy Export-214:13

    Compare two security policies, merge differences with automator, export as XML, edit settings (blocking mode, max header length, remove response codes), and re-import as the updated policy.

  • ASM Deployment Types and Sync Considerations22:09

    Explore Aasim deployment types, from standalone appliances to LTM-backed and multi-device clusters, for scalable web application protection. Learn about span monitoring, device groups, and synchronization for reliable policy enforcement.

Requirements

  • VE, Fiddler, Web Server Image
  • You should have gone through Part 1 of the WAF BASICS Series

Description

The  Application Security Manager course gives participants a  functional understanding of how to deploy, tune, and operate   Application Security Manager (ASM) to protect their web applications  from HTTP-based attacks.

The course includes lecture, hands-on labs, and discussion about  different ASM components.

In this course we will be discussing below topics:

  1. Approach towards building a positive security policy.

  2. Securing Cookies and other headers.

  3. Reporting and Logging Functionalities on ASM.

  4. Static and Dynamic Parameter Handling

  5. Comparing Security Policies

  6. ASM deployment types

Who this course is for:

  • This course is intended for security and network administrators who will be responsible for the installation, deployment, tuning, and day-to-day maintenance of the Application Security Manager.