WAF operation with automated rule generation

Managed service for operating a web application firewall on Citrix NetScaler in the banking sector, since 2020.

Background

The real effort involved in operating a WAF lies not in troubleshooting, but in managing the rules. Each release of the protected application can render rules invalid or require new ones. If this is maintained manually, adjustments take weeks, false positives are corrected during operation, and, when in doubt, security measures are relaxed to avoid blocking business processes.

For a single environment, it is not cost-effective to build up specialized in-house expertise. The necessary depth of expertise can only be achieved through ongoing work across multiple environments.

Solution

ceterion automatically generates the WAF rule set from structured input provided by the application development team. Deployment to production occurs in three stages: setup in a staging environment, testing against the application, and then rollout to production. Automation replaces manual rule creation, not the technical review.

Rule changes can thus be traced back to their source, are reproducible and recoverable, and are not dependent on the knowledge of individual persons. For the operator, this means predictable releases; for auditing, it means a documented derivation of each rule.

Outcome

  • In the Managed Service program since 2020, without interruption
  • Automated rule generation instead of manual maintenance with every release
  • Three-stage production rollout with testing before each release

Operations do not depend on individual people; changes to procedures are documented and can be verified by the internal audit department.