Barracuda Web Application Firewall decide in just few minutes
Use Cases and Deployment Scope
-Barracuda Web Application Firewall is being used to protect all our on prem applications -It protects against all layer 7 web attacks like SQL injection, XSS, etc -It provides protection against top ten Owasp as well -It provides protection against bot attacks -It provides protection against Dos attacks, - It mitigates Dos attacks as well, - It has a content updates as well that provides mitigates against zero day attacks, - the URL and Parameter profile has a very granularity to mitigate false positives, -learning if the traffic also provides easy to make an application ready to enforce in blocking
Pros
- Attack patterns are regularly updates through contents via Barracuda Web Application Firewall update servers
- Bot Protection has a good line feature to verify between the genuine clients like browsers and bots
- Dos Protection also good level of protection to mitigate Layer 7 attacks
- Allow Deny Rules provides a lot of granular controls to allow and deny the traffic
- URL profiles has a very granular control to mitigate false positives
- Parameter profiles has a very granular control to mitigate false positives
- Risk score feature for the clients to mitigate attacks is also very good feature
- Client fingerprint module can be used against malicious user to enhance security
- Separate XML and JSOn profile for all the URL profiles of the application is plus
- API security is very much effective and shadow API can also be identified
Cons
- STM crashes sometimes happen due to unusual traffic pattern
- Obfuscation on the client side user credentials which appears in the developer tools of browser
- URL Profiles redundancy during the learning of traffic needs to be fixed
- Dos Protection should be more granular like escalation period to throw JS challenge, Captcha and rate limit when escalation period hits until the WAF stops the attack
- Client Fingerprinting should work as expected when verifying the clients as in rare some scenarios, it creates issues
Likelihood to Recommend
-Companies have to focus on budget like their budget is very strict -Companies have less number application to protect and they want performance rather than protection of numerous number of applications -Where load balancing is less priority and application security is the only focus -Companies doesn’t want to spend too much on WAF engineer to handle it and require an admin with less knowledge as it provides very easy interface to handle it - It is best where companies need to stay away from additional charges from using Dos, Bot, client fingerprinting, rate limiting, risk scoring featues
