Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
WAF BASICS- Part3
Rating: 4.3 out of 5(180 ratings)
1,831 students

WAF BASICS- Part3

Application Security Manager Basics
Created byVineet Singh
Last updated 12/2020
English
English [Auto],

What you'll learn

  • Candidates will gain knowledge on product solution- ASM

Course content

1 section11 lectures4h 16m total length
  • Application Ready Templates7:12

    Use application ready templates to quickly deploy security policies for popular apps like SharePoint and SAP, selecting a template and reviewing file types, attributes, and parameters to tailor protection.

  • Automatic Policy Building46:05

    Explore automatic policy building in the WAF, using baseline traffic, templates, and thresholds to loosen or tighten security, with learning speeds and trusted IPs guiding enforcement.

  • Web App Vulnerability Scanner Integration18:08

    Integrate web application vulnerability scanners with Asim to identify, classify, and report vulnerabilities, import results, and apply automatic or manual mitigations, including staging, ignore, and retest.

  • Layered Policies23:09

    Learn how layered parent and child policies define base security settings, enforce inheritance rules (mandatory, optional, none), and propagate changes across virtual servers and templates.

  • Login Enforcement28:03

    Enforce login access by configuring a login page on the F5, specifying authentication and access validation, and blocking unauthorized access with cookies and session management.

  • Brute Force Attack Protection-129:41

    Learn to mitigate brute force attacks on web apps by configuring login attempt thresholds, IP whitelists, and mitigation methods. Explore device fingerprinting, CAPTCHA, honeypots, and distributed protection against credential stuffing.

  • Brute Force Attack Protection-29:22

    Configure brute force attack protection for a login page using anomaly detection, with thresholds, alarm and capture actions, and device mitigation, then apply the policy and verify via event logs.

  • Session Tracking24:23

    Enable session tracking to detect suspicious activity, configure a violation detection period and thresholds, and log or block requests by session, username, IP, or device.

  • Web Scraping29:34

    Discover how web scraping works and how to mitigate it using bot detection, session management, fingerprinting, and rate limiting.

  • Geolocation Enforcement18:48

    Learn how geolocation enforcement blocks or allows access by country, manage disallowed and allowed locations, and configure IP address exceptions and whitelists to refine security policies.

  • DOS Protection-121:50

    Identify four dos attack types—volumetric, computational, isometric, and vulnerability-based. Learn how a dos protection profile detects and mitigates them with thresholds and modes.

Requirements

  • VE, Fiddler, Web Server Image

Description

The  Application Security Manager course gives participants a  functional understanding of how to deploy, tune, and operate  Application Security Manager (ASM) to protect their web applications  from HTTP-based attacks.

The course includes lecture, hands-on labs, and discussion about  different ASM components.

In this course we will be discussing below topics:

1. Use of Templates for policy creation.

2. Process of Automatic Policy building.

3. Integration of ASM with Vulnerability Scanners

4. Use of Layered policies.

5. Enforce login and protection of application from Brute Force

6. Details of Session tracking and Web Scraping.

7. Protecting your application against DOS.



Who this course is for:

  • This course is intended for security and network administrators who will be responsible for the installation, deployment, tuning, and day-to-day maintenance of the Application Security Manager.