Open-source WAF Virtualization Solutions Comparison Using the OWASP Framework


Abstract:

In this manuscript a testing laboratory setup is implemented for ModSecurity WAF solutions that operate on virtual machine and container scenarios. The aim of this implementation is to evaluate effectiveness against vulnerabilities reported by OWASP Top Ten. The setup for the testing laboratory is presented together with the experimental design. Results are presented after a statistical analysis that contemplates Levene test, standard t-test, and Welch's t-test, carried out in order to determine the effectiveness of the ModSecurity WAF Solution utilized as proxy reverse. It is determined that in 41.6% of cases both solutions have the same statistical processing time mean value, 36.1% of cases the virtual machine environment shows to have lesser statistical processing time mean value, and 22.3% of cases the container environment shows to have lesser statistical processing time mean value.

Año de publicación:

2024

Keywords:

  • Docker Container
  • ModSecurity
  • OWASP
  • Virtual machine
  • WAF

Fuente:

scopusscopus

Tipo de documento:

Other

Estado:

Acceso restringido

Áreas de conocimiento:

  • Software
  • Software
  • Tecnologías de la información y la comunicación

Áreas temáticas de Dewey:

  • Programación informática, programas, datos, seguridad
  • Ciencias de la computación
  • Métodos informáticos especiales
Procesado con IAProcesado con IA

Objetivos de Desarrollo Sostenible:

  • ODS 17: Alianzas para lograr los objetivos
  • ODS 12: Producción y consumo responsables
  • ODS 16: Paz, justicia e instituciones sólidas
Procesado con IAProcesado con IA