Web application firewall integration into network appliances

WO2026170116A1PCT designated stage Publication Date: 2026-08-13IVANTI INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-09
Publication Date
2026-08-13

Smart Images

  • Figure 00000038_0000
    Figure 00000038_0000
  • Figure 00000039_0000
    Figure 00000039_0000
  • Figure 00000040_0000
    Figure 00000040_0000
Patent Text Reader

Abstract

An embodiment includes a method of network appliance security. The method includes receiving, at an external interface of a network appliance, a request. The network data request is received from a computing device of a public network and is directed to an appliance application. Before the request is communicated to appliance application, the method includes forwarding the request to a web application firewall (WAF). The WAF analyzes the request according to WAF rules that identify and block attack patterns in requests. Responsive to an analysis indicating the request is malicious, the method includes forwarding an error message to the computing device via the external interface. Responsive to the analysis indicating the network data request is non-malicious, the method includes communicating the request to the appliance application.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] WEB APPLICATION FIREWALL INTEGRATION INTO NETWORK APPLIANCES CROSS-REFERENCE TO RELATED APPLICATION

[0002] This application claims priority to and the benefit of Indian Provisional Patent Application No. 202511010594, filed February 7, 2025.

[0003] FIELD

[0004] The embodiments described in this disclosure are related to secured network access. In particular, the disclosed embodiments relate to web application firewall (WAF) integration into network appliances for secured appliance data traffic communication.

[0005] BACKGROUND

[0006] Some enterprises implement a private network to host private resources such as secure data and enterprise software applications. Remote network access to the private network may be controlled to ensure computing devices accessing the private resources have authorization. The enterprises may utilize network appliances to ensure secure access to the private resources. The network appliance may be positioned at the edge of the private network such that computing devices in a public network route network traffic through the network appliance. The public network exposes the private network to vulnerabilities.

[0007] Some network appliances include appliance applications. The appliance applications may receive request from applications in the public network such as user authentication, rewriter services, etc. The appliance applications are exposed to the public network similarly to the private network. For instance, a vulnerability in one or more of the appliance applications may be exploited which may undermine the security of the network appliance and may enable unauthorized access to resources of the private network. Accordingly, there is a need to improve security of the appliance applications in network appliances to improve network security of the network appliance and the private network.

[0008] The subject matter claimed herein is not limited to embodiments that solve any disadvantages or that operate only in environments such as those described. Rather, this background is only provided to illustrate one example technology area where some embodiments described herein may be practiced.

[0009] BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Example embodiments will be described and explained with additional specificity and detail through the use of the accompanying drawings in which:

[0011] Figure 1 depicts a block diagram of an example operating environment in which some embodiments described in the present disclosure may be implemented;

[0012] Figures 2A and 2B are block diagrams of an example application traffic analysis process that may be implemented in the operating environment of Figure 1;Figures 3A and 3B are block diagrams of example WAF rules and network appliance that may be implemented in the operating environment of Figure 1;

[0013] Figure 4 illustrates an example computer system configured for network appliance security; Figure 5 is a sequence diagram of an example secure network appliance traffic analysis that may be implemented in the operating environment of Figure 1;

[0014] Figures 6A-6B are a flowchart of an example method of network appliance security; and Figure 7 is a flowchart of an example method of updating network appliances integrating a WAF,

[0015] all according to at least one embodiment described in the present disclosure.

[0016] DESCRIPTION OF SOME EXAMPLE EMBODIMENTS

[0017] The embodiments described in this disclosure are related to secured network access. In particular, the disclosed embodiments relate to web application firewall (WAF) integration into network appliances for secured network access.

[0018] These and other embodiments are described with reference to the appended Figures in which like item number indicates like function and structure unless described otherwise. The configurations of the present systems and methods, as generally described and illustrated in the Figures herein, may be arranged and designed in different configurations. Thus, the following detailed description of the Figures is not intended to limit the scope of the systems and methods, as claimed, but is merely representative of example configurations of the systems and methods.

[0019] Figure 1 is a block diagram of an example operating environment 100 in which some examples of the present disclosure can be implemented. The operating environment 100 may be configured to evaluate appliance traffic that is communicated within a network appliance 102A and 102B (generally, network appliance 102 or network appliances 102). The appliance traffic may be communicated between a computing device 106 A or 106B (generally, computing device 106 or computing devices 106) of a public network 114 and an appliance application 124A or 124B (generally, appliance application 124 or appliance applications 124). Additionally, the appliance traffic may include some network traffic directed to the appliance application 124 and to private resources 110A and HOB (generally, private resource 110 or private resources 110) of private networks 112 A and 112B (generally, private network 112 or private networks 112).

[0020] In embodiments of the present disclosure, the network appliances 102 implement web application firewalls (WAFs) 128A and 128B. The WAFs 128A and 128B (generally, WAF 128 or WAFs 128) perform an analysis of the appliance traffic received by the network appliances 102 from the public network 114 and the appliance traffic transmitted to the public network 114 from the appliance application 124. The WAFs 128 apply a WAF rules to the appliance traffic to determine whether received appliance traffic is malicious or non-malicious and whethertransmitted appliance traffic is valid or invalid. The WAF rules applied by the WAFs 128 are configurable and can be updated to apply various levels of security.

[0021] Integration of the WAFs 128 into the network appliances 102 improve security of the network appliances 102 when compared to conventional network appliances. For instance, the network appliances 102 of Figure 1 analyze appliance application data request (hereinafter, “request”) received by the network appliance 102 prior to the request being forwarded to the appliance application 124. Malicious requests that may be harmful to the appliance application 124 are dropped instead of the being received and processed by the appliance application 124, which prevents or reduces malicious attacks on the appliance applications 124 and may reduce unauthorized access to the private resources 110. Additionally, the WAFs 128 analyze internal data traffic (hereinafter, “responses”) transmitted by the appliance application 124, which may originate at the appliance application 124 or the private servers 104A and 104B. The responses are analyzed to determine whether the responses include secure or private data or an amount of secure or private data above a particular threshold.

[0022] Moreover, integration of the WAFs 128 enables improved responses to security vulnerabilities. For instance, the WAF rules implemented by the WAFs 128 during the analyses can be updated independently of AWMs 126A and 126B (hereinafter AWM 126 or AWMs 126) and independently of the appliance application 124. Accordingly, the WAF rules may be updated to mitigate an exploited vulnerability while patches and updates are developed for the AWMs 126 and / or the appliance applications 124. Damaged imposed by the exploited vulnerability (e.g., unauthorized access to the private resources) may be prevented or reduced, and then patches to the AWMs 126 and the appliance applications 124 may be deployed to patch the vulnerability.

[0023] For example, in some conventional systems without the WAFs, multiple network appliances may be implemented with different versions of AWM. In circumstances in which the AWM includes a vulnerability that is actively exploited, each version of the AWM requires a patch, which needs to be developed, tested, and deployed. Accordingly, mitigating the exploitation might involve generating, testing, and deploying a first patch, followed by a second patch, etc. During the generation, testing, and deployment of each patch a malicious actor is actively exploiting private networks.

[0024] In contrast, a first network appliance 102 A may implement a first version of the AWM 126 A and a second network appliance 102B may implement a second version of the AWM 126B. Both the first and second network appliances 102 are implementing the WAF 128. In circumstances of an active exploit of both AWMs 126, the WAF rules may be updated on the WAF 128 to mitigate the active exploit while patches are developed for the AWMs 126.Moreover, inclusion of the WAF 128 in the network appliance 102 maintains security of the network appliance 102. For instance, the appliance traffic is often encrypted. Positioning the WAF 128 inside the network appliance 102 enables the AWM 126 to decrypt the appliance traffic while securely managing certificates and / or keys used in the decryption.

[0025] The embodiments of the present disclosure are directed to a computer-centric problem and are implemented in a computer-centric environment. For instance, the examples of the present disclosure are directed systems and methods configured to improve security of appliance traffic through integration of the WAF 128 into the network appliance 102. Computing processes occurring in the operating environment 100 include communication and real time analysis of appliance traffic. Communications during the processes described in this present disclosure involve the communication of data in electronic and optical forms via a network 120 and also involve the electrical and optical interpretation of the data and information.

[0026] The operating environment 100 may include the public network 114 in which the computing devices 106 are located. The operating environment 100 further includes an administrative device 108 (hereinafter, admin device 108), the network appliances 102, and private servers 104 A and 104B (private server 104 or private servers 104). The private servers 104 are located in the private networks 112. The components of the operating environment 100 are configured to communicate data and information via the network 120 to perform analysis of appliance traffic as described in the present disclosure. Each of these components are described in the following paragraphs.

[0027] The network 120 may include any communication network configured for communication of signals between the components (e.g., 106, 102, 108, and 104) of the operating environment 100. The network 120 may be wired or wireless. The network 120 may have configurations including a star configuration, a token ring configuration, or another suitable configuration. Furthermore, the network 120 may include a local area network (LAN), a wide area network (WAN) (e.g., the Internet), and / or other interconnected data paths across which multiple devices may communicate. In some examples, the network 120 may include a peer-to-peer network. The network 120 may also be coupled to or include portions of a telecommunications network that may enable communication of data in a variety of different communication protocols.

[0028] In some examples, the network 120 includes or is configured to include a BLUETOOTH® communication network, a Z-Wave® communication network, an Insteon® communication network, an EnOcean® communication network, a Wi-Fi communication network, a ZigBee communication network, a representative state transfer application protocol interface (REST API) communication network, an extensible messaging and presence protocol (XMPP) communication network, a cellular communications network, any similar communication networks, or any combination thereof for sending and receiving data. The data communicated in the network 120may include data communicated via short messaging service (SMS), multimedia messaging service (MMS), hypertext transfer protocol (HTTP), direct data connection, wireless application protocol (WAP), or any other protocol that may be implemented in the components of the operating environment 100.

[0029] The public network 114 includes the computing devices 106. The public network 114 includes network locations outside the private networks 112 and the network appliances 102. The computing devices 106 of the public network 114 may access the network 120 via a public internet connection. The public network 114 is accessible to essentially any computing device with minimal restrictions. Accordingly, the computing devices 106 may not need to be authorized to communicate in the public network 114.

[0030] The computing devices 106 may include hardware-based computer systems that are configured to communicate with the other components of the operating environment 100 via the network 120. The computing devices 106 may include any computer device that can communicate appliance traffic with the network appliances 102 and / or the private servers 104. Generally, the computing devices 106 may include devices that are operated by the personnel and systems of an enterprise (e.g., 116A and 116B described below) or store data of the enterprise. The computing devices 106 might include workstations of an enterprise, servers, data storage systems, printers, telephones, internet of things (IOT) devices, smart watches, etc. The computing devices 106 may also include virtual machines, which may include a portion of a single processing unit or one or more portions of multiple processing units, which may be included in multiple machines.

[0031] The computing devices 106 may be associated with the users 115A and 115B (generally, user 115 or users 115). The phrase “associated with” when describing the relationship between the computing devices 106 and the users 115 indicates that the users 115 generally or regularly operate the computing devices 106. A first user 115A may be an authorized user. For instance, the first user 115A may be an employee of a first or a second enterprise 116A or 116B. The first user 115A operates a first computing device 106 A. Accordingly, appliance traffic communicated between the first computing device 106 A and the network appliance 102 may be non-malicious and valid. A second user 115B may not be an authorized user. For instance, the second user 115B may be an unauthorized user (e.g., a former employee or employee without sufficient credentials) or malicious actor. The second user 115B operates a second computing device 106B. Accordingly, appliance traffic communicated between the second computing device 106B and the network appliance 102 may be malicious and invalid.

[0032] The admin device 108 includes a hardware-based computer device or collection thereof configured to communicate with the other components of the operating environment 100 via the network 120. For instance, the admin device 108 is configured to communicate management datawith the network appliances 102. Some examples of the management data may include WAF rules, modifications to WAF rules, updates to the AWMs 126 and the appliance applications 124, security level selections, other management data, or combinations thereof. As described elsewhere in the present disclosure, the admin device 108 may communicate updates to the WAF rules that may modify the analysis of the appliance traffic. The updates to the WAF rules may be communicated responsive to discovery of a new or previously unknown attack pattern, ineffective or inefficient analysis of the appliance traffic, an active exploitation of the appliance applications 124, an active exploitation of one or both of the private servers 104, other triggers or combinations thereof. Additionally, the admin device 108 may communicate security level selections to the network appliances 102. The security level selections may activate or deactivate sets of the WAF rules.

[0033] The admin device 108 may also be configured to receive data and information from the network appliances 102. For instance, the WAFs 128 may be configured to communicate log entries to the admin device 108. The log entries may indicate results of analyses of appliance traffic. For instance, the log entries might indicate which requests are determined to be malicious, which responses are invalid, etc. The admin device 108 may use the log entries to determine whether the WAF rules are effective and efficient. For instance, presence of false positives (e.g., non-malicious request determined to be malicious) may indicate the WAF rules are inefficient.

[0034] The admin device 108 may be associated with an administrator 117. The administrator 117 may be an individual, a set of individuals, or a system that interfaces with the admin device 108. In some examples, the administrator 117 may provide input such as admin input to the admin device 108. The input provided by the administrator 117 may form data and information used to define the WAF rules, the security level selections, updates, and the like.

[0035] The admin device 108 may be included in one or both of the private networks 112 or in the public network 114. For instance, in some embodiments, the admin device 108 may be included in the public network 114. In these embodiments, the communication of data and information may be via the network appliance 102 and be received at an external interface 130. Alternatively, the admin device 108 may be located within one of the private networks 112, which is generally indicated by dashed arrow 168. In these embodiments, the data and information communicated by the admin device 108 originates within the private network 112 and received at the network appliance 102 via the internal interface 122.

[0036] In addition, in some embodiments, the network appliances 102 may include an admin interface 174 A or 174B (generally, admin interface 174 or admin interfaces 174). The admin interface 174 is used for management of the network appliances 102. For instance, in these and other embodiments, the admin device 108 may control and managed the network appliances 102and the WAF 128 by communicating commands, instructions, and data to the network appliances 102 via the admin interface 174. The commands, instructions, and data may be communicated using an administrative user interface, a representational state transfer application programming interface (REST API), a simple network management protocol (SNMP), a desktop management interface (DMI), another suitable communication framework, or combinations thereof.

[0037] In some embodiments, the admin device 108 may communicate with a portion of the network appliances 102 via the external interface 130 and another portion of the network appliances 102 via the internal interface 122 or the admin interface 174A. Alternatively, in some embodiments all of the network appliances 102 may communicate with the admin device 108 via the admin interface 174, the external interface 130, or the internal interface 122.

[0038] The private networks 112 are isolated from the public network 114. The private network 112 is used to connect and secure the private servers 104. Within the private network 112 access to the private resources 110 is controlled. For instance, access to the private resources 110 is prevented by unauthorized users (e.g., the second user 115B) and unauthorized software applications. Access to the private resources 110 is allowed from authorized users (e.g., the first user 115A) and authorized software applications. The private networks 112 may include a secured environment.

[0039] The private networks 112 may be associated with an enterprise 116A or 116B. For instance, a first enterprise 116A may establish a first private network 112A to secure access to a first private resource 110A and a second enterprise 116B may establish a second private network 112B to secure access to a second private resource HOB. In this example the first private resource 110A may include an email system of the first enterprise 116A, client information of the first enterprise 116A, corporate secrets (e.g., credentials, sales figures, security codes, etc.) of the first enterprise 116A. Additionally, the first private resource 110A may include a software application generated for the first enterprise 116A. The second private resource HOB may include similar types of resources of the second enterprise 116B.

[0040] In the depicted embodiment, the first enterprise 116A is different from the second enterprise 116B. Accordingly, the first private network 112A is separate from the second private network 112B. In some embodiments, an enterprise (e.g., 116A or 116B) may include multiple private networks 112 and / or multiple network appliances 102.

[0041] The network appliance 102 includes a hardware-based computer device or collection thereof that is configured to communicate with the other components of the operating environment 100 via the network 120. In the depicted embodiment, the network appliance 102 is a virtual private network (VPN) appliance that provides VPN services to enable secure, encrypted connections between the computing devices 106 and the private networks 112.The network appliances 102 may include an external interface 130A or 13 OB (generally external interface 130), an internal interface 122 A or 122B (generally, internal interface 122), the WAF 128, the AWM 126, and the appliance application 124. In the depicted embodiment, the external interface 130, the internal interface 122, the AWM 126, the appliance application 124, and the WAF 128 are included in a single device. In other embodiments, one or more of the WAF 128, the AWM 126, the appliance application 124 may be located remotely. For instance, the WAF 128 may be located in a remote location relative to the network appliance 102 and communicate via a connection with the AWM 126.

[0042] The external interface 130 receives appliance traffic from the computing devices 106 and is an interface between the public network 114 and the network appliance 102. Additionally, responses are communicated from the network appliance 102 to the computing devices 106 via the external interface 130. The internal interface 122 receives appliance traffic from the private server 104 of the private network 112 and communicates the appliance traffic to the appliance application 124 or the AWM 126. Additionally, non-malicious appliance traffic may be communicated from the network appliance 102 to the private server 104 via the internal interface 122. Some additional details and examples of the interfaces 130 and 122 are provided with reference to Figure 4.

[0043] The appliance application 124 is configured to perform one or more services related to operations of the network appliance 102. Additionally, appliance traffic routed through the network appliances 102 may be processed by the appliance application 124 prior to communication to the private network 112. For instance, the appliance application 124 may include one or more or a combination of a secure and a security assertion markup language (SAML) service, a common gateway interface (CGI) service (e.g., for user interface (UI) applications (admin and / or end user)), other UI applications (e.g., PHP, JAVA™, Python™), a representational state transfer application programming interface (REST-API) service, authentication services, analytics services, proxy services, tunnelling services, terminal services, virtual desktop services, a rewriter service, another suitable network data service, or some combination thereof.

[0044] The AWM 126 is configured to route appliance traffic between the public network 114 and the WAF 128. The AWM 126 forwards appliance traffic to the WAF 128 where an analysis of the appliance traffic is performed using WAF rules. The AWM 126 forwards received appliance traffic (e.g., requests) to the WAF 128 prior to receipt by the appliance application 124. Additionally, the AWM 126 forwards transmitted appliance traffic (e.g., responses) to the WAF 128 prior to the responses being communicated to the computing devices 106. Responsive to the analyses by the WAF 128, the appliance traffic is either blocked or forwarded.The WAF 128 is configured to perform analyses of the requests and the responses. The analyses conducted by the WAF 128 determine whether the requests are malicious or non-malicious. Additionally, the analyses conducted by the WAF 128 determine whether responses are valid or invalid.

[0045] In some embodiments, the WAF 128 is able to operate in an enforcement mode and in a monitor mode. When configured in the monitor mode, the WAF 128 detects the malicious requests and the invalid responses. The WAF 128 does not drop or take corrective actions responsive to the detection of the malicious requests and invalid responses. Instead, the WAF 128 might only log the malicious requests and invalid responses. When configured in the enforcement mode, the WAF 128 detects the detects the malicious requests and the invalid responses and performs operations (as described elsewhere herein) to block the malicious requests and the invalid responses. In both operational modes, the WAF 128 is performing the analyses of the appliance traffic.

[0046] For example, one of the users 115 inputs a request to the computing device 106. The request may be an access request for information or data of the private network 112. The computing device 106 communicates the request or some derivative thereof to the AWM 126 of the network appliance 102 via the external interface 130. The AWM 126 forwards the request to the WAF 128. The WAF 128 analyzes the request using WAF rules to determine whether the request is malicious or non-malicious.

[0047] In response to the request being identified as malicious, the WAF 128 may communicate an error message or a result indicating that the request is malicious to the AWM 126. The AWM 126 may then communicate the received error message from the WAF 128 to the computing device 106 or may generate in response to the result the error message and forward the error message to the computing device 106. The error message may include a 403 forbidden notice or another suitable error message. The WAF 128 and the AWM 126 then drop the request such that it is not communicated to the appliance application 124 or the private network 112.

[0048] Otherwise, in response to the request being non-malicious, the WAF 128 may communicate the request (which is determined to be non-malicious) to the AWM 126 or communicate a result to the AWM 126 indicating that the request is non-malicious. The AWM 126 then communicates the request to the appliance application 124. The appliance application 124 processes the request according to the service(s) it performs. Additionally, the appliance application 124 may communicate the request or some derivative of the request to the private network 112 via the internal interface 122.

[0049] A response to the non-malicious request may be generated from the private server 104 based on the private resource 110 or may be generated by the appliance application 124. For instance, the request may be user authorization information associated with one of the users 115. Theappliance application 124 may accordingly generate the response that includes the user authorization information. The appliance application 124 may then communicate the response to the AWM 126. The AWM 126 forwards the response to the WAF 128 prior to the communication of the response to the computing device 106. The WAF 128 receives the response and analyzes it using the WAF rules. The analysis of the response determines whether the response is valid or invalid according to the WAF rules.

[0050] In response to the response being invalid, the WAF 128 communicates the error message or a result indicating the response is invalid to the AWM 126. The AWM 126 communicates the error message to the computing device 106 or generates and communicates the error message to the computing device 106. The AWM 126 and / or the WAF 128 drop the response. Alternatively, in response to the response being valid, the WAF 128 communicates the response to the AWM 126. The AWM 126 then communicates the response to the computing devices 106.

[0051] The embodiment immediately above describes a secured network access operation performed by a VPN appliance. In the VPN appliance, the WAF 128 the WAF rules, the AWM 126, and the appliance application 124 are physically located in a single device, apparatus, or hardware component. In some embodiments, the network appliance 102 or some portion thereof may be implemented virtually (e.g., running on a hypervisor) or a cloud appliance, which maybe implemented as a service on a cloud-computing platform (e.g., Microsoft™ Azure™, AWS™, etc.). Additionally or alternatively, in some embodiments, the network appliance 102 might include another type of network appliance such as a router, a load balancer, a proxy server, and the like. In these embodiments, the WAF 128 may be integrated into the appliance traffic communication flow to perform analyses of appliance traffic based on WAF rules.

[0052] The WAF 128, the AWM 126, the appliance application, the private resource 110, and components thereof may be implemented using hardware including a processor, a microprocessor (e.g., to perform or control performance of one or more operations), a field-programmable gate array (FPGA), or an application-specific integrated circuit (ASIC). In some other instances, WAF 128, the AWM 126, the appliance application, the private resource 110, and components thereof may be implemented using a combination of hardware and software. Implementation in software may include rapid activation and deactivation of one or more transistors or transistor elements such as may be included in hardware of a computing system (e.g., the network appliances 102, the private server 104, or the computing device 106 of Figure 1). Additionally, software defined instructions may operate on information within transistor elements. Implementation of software instructions may at least temporarily reconfigure electronic pathways and transform computing hardware.Modifications, additions, or omissions may be made to the operating environment 100 without departing from the scope of the present disclosure. For example, the operating environment 100 may include one or more computing devices 106, one or more network appliances 102, one or more private servers 104, one or more admin devices 108, one or more networks 120, or any combination thereof. Moreover, the separation of various components and devices in the examples described herein is not meant to indicate that the separation occurs in all examples. For instance, the WAF 128 and the AWM 126 may include a single module. Moreover, it may be understood with the benefit of this disclosure that the described components and servers may generally be integrated together in a single component or server or separated into multiple components or servers.

[0053] Figures 2A and 2B are block diagrams of an example application traffic analysis process (analysis process) 200 that may be implemented in the operating environment 100 of Figure 1 or another suitable operating environment. Figures 2 A and 2B include multiple components (e.g., 108, 102, 126, 124, 122, 130, 106, 104, 110, 112, 114, etc.) described with reference to Figure 1. Although not depicted in Figures 2A and 2B, data and information (e.g., logs 224, request 222, etc.) may be communicated via the network 120 or another suitable communication network.

[0054] The analysis process 200 is separated between a first portion 201 A of Figure 2A and a second portion 201B of Figure 2B. The first portion 201A is directed to processing of a request 222 received at the network appliance 102. The second portion 20 IB is directed to processing of a response 242. At least some of the operations of the analysis process 200 are also described with reference to Figure 5 of the present disclosure.

[0055] Referring to Figures 2A and 2B, the WAF 128 includes WAF rules (in Figures 2A-3B, “rules”) 226. The WAF 128 uses the WAF rules 226 to monitor and analyze appliance traffic such as the request 222 and the response 242 that are communicated between the public network 114 and the network appliance 102. The WAF rules 226 are a configurable set of rules that identify the request 222 as malicious or non-malicious and to identify the response 242 as either valid or invalid. The WAF rules 226 are used as a basis of an analysis conducted by the WAF 128 on the appliance traffic. The WAF 128 returns results of the analysis to the AWM 126 to block or forward the request 222 or the response 242.

[0056] The WAF rules 226 include one or more hypertext transfer protocol (HTTP) traffic monitoring rules, one or more logging rules, one or more real-time traffic analysis rules, or some combination thereof. In some embodiments, the WAF rules might include open source WAF rules 226 such as OWASP rules, which are available at https: / / www.modsecurity.org. Another set of WAF rules 226 may include CRS rules that are available at https: / / coreruleset.org / . Additionally, the WAF rules 226 may include custom rules that are developed and deployed by the admin device108. For instance, the admin device 108 may utilize some of the OWASP rules as well as develop some specific WAF rules 226 that are applicable to the private resource 110, the appliance application 124, or a policy of an enterprise associated with the private network 112. Additionally, the custom rules may include refinements of one or more of the WAF rules 226 to enhance the security of the appliance application 124 and / or to reduce false positives.

[0057] The admin device 108 may communicate a security level selection (in Figures 2A and 2B, “level selection”) 225. The security level selection 225 is operable to select a level or degree of security implemented by WAF rules 226 implemented at the WAF 128. For instance, there might be multiple security levels implemented at the network appliance 102. A higher security level may result in identification and blocking of more requests 222 and responses 242 as malicious while a lower security level may result in identification and blocking of fewer of the requests 222 and responses 242 as malicious. Additionally, the higher security level may result in larger number of false positives in which non-malicious requests 222 and responses 242 are identified as malicious. The security level selection 225 may be based on a type of the private network 112 or enterprise (e.g., 116 of Figure 1), the particular services 210A-210C of the appliance application 124, location, governmental policies, other characteristics of the operating environment, or some combination thereof. For instance, a general corporation such as a product vendor may implement a lower security level, a banking corporation may implement a medium or a medium-high security level, and a military or secret enterprise may implement a high security level.

[0058] The security level selection 225 may be received at the WAF 128. Based on the security level selection 225, the WAF 128 may implement a particular number or type of WAF rules 226 during analysis of the requests 222 and the responses 242. During the analysis process 200 multiple security level selections 225 may be received and implemented at the WAF 128. Accordingly, different subsets of the WAF rules 226 may be implemented and the WAF rules 226 may be modified based on security level selections 225. In some embodiments, the WAF rules 226 may include a default security level, which may include a default set of the WAF rules 226. In these and other embodiments, the security level selection 225 may not be received prior to analysis of the request 222 or the response 242.

[0059] In addition to the level selection 225, the admin device 108 may communicate other management instructions to the WAF 128, some of which are described with reference to Figures 2A-3B. For instance, the admin device 108 may change configurations of the WAF 128 to enable or disable the WAF 128, to change a mode of the WAF 128 (e.g., from an enforcement mode to a monitor mode), update WAF rules 226, exclude a set of the WAF rules 226, etc.

[0060] Referring to Figure 2A, the computing device 106 communicates the request 222 to the external interface 130. The computing device 106 is located in the public network 114.Accordingly, the computing device 106 may be associated with a user with authorization to access the private resource 110 or may be associated with a malicious actor who attempts to obtain access to the private resource 110 or the network appliance 102. The request 222 is received at the external interface 130 and is forwarded to the AWM 126. The request 222 may be encrypted in embodiments in which the network appliance 102 provides VPN services between the computing device 106 and the private network 112.

[0061] In some embodiments, the request 222 is encrypted when it is received at the external interface 130. For instance, the request 222 may be encrypted when the request 222 is communicated over a VPN, when the request 222 originates at a proprietary application on the computing device 106, or when the request 222 is directed to the private server 104 of the private network 112. In embodiments in which the request 222 is encrypted, the request 222 may be decrypted, which is described below. Alternatively, in some circumstances, the request 222 is not encrypted. Accordingly, the plaintext version of the request 222 may be communicated to the WAF 128 and analyzed according to the WAF rules 226.

[0062] The AWM 126 includes a decryption module 206. In circumstances in which the request 222 is encrypted, the decryption module 206 decrypts the request 222 to generate the decrypted request 202. For instance, The decryption module 206 may store or access certificates and / or keys sufficient to decrypt the request 222. The request 222 may be decrypted before the request 222 is communicated to appliance application 124 and the WAF 128. Decryption of the request 222 enables the analysis by the WAF 128 in a plaintext format. The AWM 126 forwards a decrypted request 202 (e.g., a plaintext version of the request 222) to the WAF 128.

[0063] The AWM 126 forwards the decrypted request 202 to the WAF 128 before it is communicated to the appliance application 124. The routing of the decrypted request 202 to the WAF 128 before communication to the appliance application 124 is different from conventional systems. For instance, in some conventional systems, analysis of a request 222 is performed by an external WAF or not analyzed, which may enable malicious requests or a higher number of malicious requests to proceed to the appliance application 124. The inclusion of the WAF 128, which provides an analysis prior to the request 222 entering the appliance application 124 may reduce a number of malicious requests from entering the private network 112. It further enables decryption of the request 222, which may enable analysis of the plaintext version of the request 222.

[0064] The decrypted request 202 is forwarded to the WAF 128 via a connector 264. The connector is a connection point between the WAF 128 and the AWM 126. The connector 264 provides a communication channel that is configured for the communication of the decrypted request 202 from the AWM 126 to the WAF 128 and a result of an analysis conducted by the WAF 128. Anexample of the connector 264 may include a modsecurity-nginx connector, which operates as a nginx module and serves as a layer of communication between the AWM 126 and the WAF 128.

[0065] The WAF 128 analyzes the decrypted request 202 according to the WAF rules 226. The analysis of the decrypted request 202 identifies and blocks attack patterns that may be included in the requests 222. For instance, the WAF rules 226 may be configured to identify malicious web traffic and application-layer attacks. In some embodiments, the WAF rules 226 might be configured to identify and block cross-site scripting XSS, cross-site forgery, file inclusion, DDoS, SQL injection, cookie manipulation (cookie poisoning), injection attacks, broken authentication, security misconfigurations, insecure deserialization, sensitive data exposure, broken access control, and the like. In some embodiments, the WAF 128 performs the analysis of each request 222 received by the network appliance 102 and each response 242 transmitted by the network appliance 102 (as discussed with reference to Figure 2B).

[0066] The analysis conducted by the WAF 128 identifies the decrypted request 202 as either malicious or non-malicious. The WAF 128 communicates a result 204 to the AWM 126. The result 204 includes an indication of whether the decrypted request 202 is either malicious or non-malicious. Additionally or alternatively, in some embodiments, the result 204 may include an error message 220 that is associated with requests identified as malicious.

[0067] In addition, in some embodiments, the WAF 128 is further configured to generate a log entry 224. The log entry 224 records the results 204 of the analysis of the decrypted request 202. The log entry 224 indicates a number and type of the requests 222 that are being identified as malicious and non-malicious. In some cases, the log entry 224 enables analysis by the admin device 108 of the WAF rules 226. For instance, the log entry 224 may indicate that some non-malicious requests are being identified as malicious, which is referred to as a “false positive.” Based on the log entry 224, updates and modifications to the WAF rules 226 may be performed as described in Figures 3 A and 3B.

[0068] The AWM 126 receives the result 204 of the analysis from the WAF 128. In response to the result 204 indicating the decrypted request 202 is malicious (e.g., the result 204 including an error message 220), the AWM 126 and the WAF 128 drops the request 222. Accordingly, the request 222 is not communicated to the appliance application 124. In addition, the AWM 126 forwards an error message 220 to the computing device 106 via the external interface 130. The error message 220 may include a 403 forbidden error message.

[0069] Accordingly, in circumstances in which a malicious actor is in use of the computing device 106, the request 222 is communicated to the private network 112 via the network appliance 102 to attempt to access data or information of the appliance application 124. The request 222 is identified as malicious and dropped such that the appliance application 124 and the private server104 never receive the request 222. The malicious actor receives the error message 220 and the log entry 224 is recorded of the attempted access.

[0070] In response to the result 204 indicating that the decrypted request 202 is non-malicious, the AWM 126 forwards a non-malicious request 208 to the appliance application 124 or one or more services 210A-210C included therein. The services 210A-210C may include a SAML service, a CGI service, other UI applications, a REST-API service, authentication services, analytics services, proxy services, tunnelling services, terminal services, virtual desktop services, a rewriter service, another suitable network data service, or some combination thereof. Each of the services 210A-210C may further process the non-malicious request 208 and generate a response (e.g., the response 242), or further process the non-malicious request 208 and forward the non-malicious request 208 to the private server 104 via the internal interface 122.

[0071] With combined reference to Figures 2A and 2B, the second portion 20 IB of the analysis process 200 is directed to communication of the response 242 to the computing device 106 from the appliance application 124. For example, the non-malicious request 208 may request particular data and information of the appliance application 124. The non-malicious request 208 is received and fulfilled by the appliance application 124. The appliance application 124 generates the response 242 that includes the particular data and information. The second portion 20 IB provides an additional security measure. For instance, the analysis conducted by the WAF 128 may have identified the request 222 as non-malicious. Nevertheless, to perform an additional check, the network appliance 102 routes the response 242 back through the WAF 128 to perform the additional check of the response 242.

[0072] For example, referring to Figure 2B, the response 242 is an example of internal data traffic that is generated in response to requests. Figure 2B describes analysis of the response 242. However, any internal appliance traffic may be processed according to the second portion 20 IB of the analysis process 200.

[0073] The response 242 may be generated by the appliance application 124 in some circumstances. The response 242 is then communicated to the AWM 126. Alternatively, the response 242 may be generated by the private server 104. In these circumstances, the response 242 is received at the internal interface 122 from the private server 104. The services 210A-210C or some combination or subset thereof may process the response 242. The response 242 is then communicated to the AWM 126.

[0074] In some embodiments, the response 242 might be encrypted. The AWM 126 may have stored certificates and / or keys that enable the decryption of the response 242. For instance, the response 242 might originate at a proprietary application of the private network 112. In these and other circumstances, the decrypt module 206 of the AWM 126 might have stored thereon the certificateand / or keys that enable decryption of the response 242. However, in some other circumstances, the response 242 might originate at a third-party application (e.g., a third-party application operating at least partially in the private network 112). Accordingly, the decrypt module 206 may not have the certificate and / or keys suitable to decrypt the response 242. When the decrypt module 206 has the certificates and / or keys, the decrypt module 206 decrypts the response 242 prior to communication to the WAF 128. However, when the decrypt module 206 does not have the certificates and / or keys, the WAF 128 may analyze plaintext portions of the encrypted response 242 such as headers, source / destination addresses or applications, etc.

[0075] Before the response 242 is communicated to the computing device 106, the AWM 126 forwards the response 242 to the WAF 128 via the connector 264. The WAF 128 analyzes the response 242 according to the WAF rules 226. In the second portion 20 IB of the analysis process 200, the particular WAF rules 226 applied to the response 242 might be different from those applied during the first portion 201A of Figure 2A. For instance, the analysis of the response 242 is configured to whether the response 242 is valid or invalid. The WAF rules 226 enable definition of “valid” and “invalid” by the admin device 108. For instance, a valid response in some embodiments does not include sensitive or protected information. In other embodiments, a valid response does not include an amount of sensitive or protected information above a particular threshold. In yet other embodiments, the valid response does not include any data of a first type and might include any amount of data of a second type. In contrast, an invalid response might include sensitive or protected information or might include an amount of sensitive or protected information above the particular threshold, etc. Additionally, the WAF rules 226 applied to the response 242 may be configured to analyze plaintext versions of an encrypted response such as a header, destination / source addresses, etc.

[0076] As described with reference to Figure 2A, the WAF 128 is further configured to generate the log entry 224. The log entry 224 records the results 234 of the analysis of the response 242. The log entry 224 indicates a number and type of the response 242 that are being identified as valid and invalid. The log entry 224 enables analysis by the admin device 108 of the WAF rules 226 related to analysis of the response 242 as well as updates and modifications to the WAF rules 226.

[0077] The WAF 128 communicates a result 234 of the analysis performed on the response 242. The result 234 indicates whether the response 242 is valid or invalid. Additionally or alternatively, the result 234 might include an error message 220. The result 234 is communicated to the AWM 126. In response to the result 234 indicating an invalid response, the AWM 126 drops the response 242 such that the computing device 106 does not receive the response 242. Instead, the AWM 126 forwards the error message 220 to the computing device 106 via the external interface 130. Inresponse to the result 234 indicating the response 242 is a valid response, the AWM 126 communicates a valid response 230 to the computing device 106 via the external interface 130.

[0078] Accordingly, in circumstances in which a malicious actor is in use of the computing device 106, the request 222 is communicated to the network appliance 102 to attempt to access secured information of the appliance application 124. The request 222 is erroneously identified as non-malicious and communicated to the appliance application 124. The appliance application 124 generates the response 242 that addresses the request 222. The response 242 is forwarded back through the WAF 128, which identifies the response 242 as invalid. The response 242 is dropped such that the computing device 106 does receive the response 242. The malicious actor receives the error message 220 and the log entry 224 is recorded of the attempted access.

[0079] Figures 3 A and 3B are block diagrams of example WAF rules and network appliance update processes 300 A and 300B (update processes 300 A and 300B) that may be implemented in the operating environment 100 of Figure 1 or another suitable operating environment. Figures 3A and 3B include multiple components (e.g., 108, 126, 128, 124, 122, 106, 104, 110, 112, etc.) that are previously described in Figures 1-2B. Although not depicted in Figures 3 A and 3B, data and information may be communicated via the network 120 or another suitable communication network.

[0080] In some embodiments, the network appliances 102 may be shipped or initially updated with a default WAF rules 226. The update processes 300A and 300B may be conducted responsive to one or more stimuli or triggering events to change, update, or modify the WAF rules 226, which may include the default WAF rules 226 or a subsequently updated WAF rules 226 that are implemented in the network appliances 102. For instance, Figure 3 A depicts a first update process 300A in which the WAF rules 226 of the network appliance 102 are updated individually. Figure 3B depicts a second update process 300B in which the WAF rules 226 of multiple network appliances 102 are updated concurrently. The update processes 300A and 300B may occur responsive to conditions and circumstances outside the private network 112. For instance, one or more conditions may occur that create a reason to change or modify the WAF rules 226. Updates the WAF rules 226 might mitigate or address some conditions. Additionally, the updates to the WAF rules 226 may occur prior to other updates to the AWM 126 or the appliance application 124. The update to the WAF rules 226 according to the update processes 300A and 300B might improve a speed at which a mitigation occurs. As an example, the AWM 126 may suffer from a zero-day vulnerability that enables unauthorized access to the private network 112. An update to the AWM 126 may depend on identifying the vulnerability, generating a patch that corrects the vulnerability, testing the patch, and deploying the patch to the AWM 126. Additionally, in some cases, deployment of the patch or publication of the patch might escalate malicious operations bya malicious actor. In these and other circumstances, an update to the WAF rules 226 to identify and block a particular attack pattern associated with the vulnerability may mitigate the vulnerability while the patch is developed and deployed. Moreover, the update to the WAF rules 226 may occur without the publication and open deployment of the patch, which may reduce the likelihood of the escalation of the malicious activity.

[0081] Some other conditions that might trigger the update processes 300 A and 300B include a new or previously unknown attack pattern in the AWM 126, the appliance application 124, the private server, or some combination thereof; an analysis of the logs (e.g., log 224 of Figures 2A and 2B) that indicate current WAF rules 226 are generating a number of false positives above a particular threshold; an indication of a exploited vulnerability; a change in enterprise policy (e.g., changes to specific data designated as secure); a change to governmental policy (e.g., an update to privacy governance); a change to authorization level associated with the computing device 106; or some combination thereof.

[0082] In some embodiments, the WAF rules 226 or updated WAF rule 302 may include one or both of version numbers and signatures. The version numbers may be sequentially assigned to the WAF rules 226 and the updated WAF rule 302 to assist in administration. For instance, the WAF rules 226 may be version 1 and the updated WAF rules 302 may be version 2. An additional or subsequent updated WAF rules may be version 3.

[0083] In addition, the WAF rules 226 and the updated WAF rules 302 might include a signature. The signature may be a cryptographic signature of the admin device 108 or the source of the WAF rules 226 or updated WAF rules 302. The signature may be used by the WAF 128 to authenticate the WAF rules 226 and the updated WAF rules 302. Accordingly, before the updated WAF rules 302 are implemented at the WAF 128, the WAF 128 may verify the signature of the updated WAF rules 302.

[0084] In some embodiments, (e.g., embodiments in which the network appliance 102 is a hardware apparatus), the WAF rules 226 may be installed prior to distribution. The WAF rules 226 that are initially installed might not be signed. The updated WAF rules 302 in these embodiments may include a signature, which is used to authenticate the updated WAF rules 302. Additional or subsequent updated WAF rules 302 may include an additional or different signature.

[0085] Referring to Figure 3A, the admin device 108 may generate the update WAF rules 302 (in Figures 3 A and 3B “updated rules”). The admin device 108 may communicate the updated WAF rules 302 to the WAF 128. The update WAF rules 302 may be communicated to the WAF 128 such that the updated WAF rules 302 are substituted in for the WAF rules 226 implemented at the WAF 128. Alternatively, the updated WAF rules 302 may include an additional WAF rule that isappended into the WAF rules 226 or may include instructions or commands that disable or enable a subset of the WAF rules 226.

[0086] In addition, in some embodiments the admin device 108 may generate one or both of an updated AWM 304 and an updated appliance application 306. The updated AWM 304 includes changes and modifications to the AWM 126. The updated appliance application 306 includes changes and modifications to the appliance application 124. Examples of the changes and modifications may include improvements, additional features, and vulnerability mitigations. The updated AWM 304 and the updated appliance application 306 may be communicated to the AWM 126 and the appliance application 124. In some embodiments, the updated AWM 304 and the updated appliance application 306 may be communicated to the network appliance 102 via the external interface 130 or the internal interface 122. Additionally, in some embodiments, the updated AWM 304 and the updated appliance application 306 may be communicated to the network appliance 102 from a third-party server.

[0087] The updated WAF rules 302 may be communicated independently of the updated AWM 304 and the updated appliance application 306. For instance, the updated WAF rules 302 may be communicated prior to the updated AWM 304 and the updated appliance application 306. Alternatively, the updated WAF rules 302 may be communicated and the updated AWM 304 and the updated appliance application 306 may not be communicated. For instance, the updated WAF rules 302 may resolve or sufficiently resolve the condition prompting the update to the WAF rules 226. In these circumstances, the update WAF rules 302 may be communicated to the WAF 128, however, the updated appliance web module 304 and the updated appliance application 306 may not be communicated to the network appliance 102.

[0088] In addition, in some embodiments, the appliance application 124 may include the multiple services 210. In these and other embodiments, the updated appliance application 306 may include multiple updates that correspond to the services 210. Accordingly, a portion of the updated appliance application 306 may be communicated, followed by the updated WAF rules 302, followed by the remaining portions of the updated appliance application 306. The updated WAF rules 302 may provide a temporary resolution while the remaining portions of the updated appliance application 306 are developed or tested.

[0089] Referring to Figure 3B, a second update process 300B is depicted. The second update process 300B is similar to the first update process 300A. The second update process 300B includes an update to the WAFs 128 of multiple network appliances 102 A and 102B. In the depicted embodiment, the network appliances 102 are implemented in two enterprises 116A and 116B and may include different or separate private networks (e.g., 112 of Figures 1-3 A). Additionally, one or both of the AWM 126 A and the appliance application 124 A of the first network appliance 102 Amay be different or a different version of the AWM 126B and the appliance application 124B of the second network appliance 102B. For instance, the first network appliance 102A may include a first version of the AWM 126 A and the appliance application 124 A and the second network appliance 102B may include a second version of the AWM 126B and the appliance application 124B.

[0090] In these embodiments, the variation between the AWMs 126 and the appliance applications 124 may introduce additional delays in updating the AWM 126 and / or the appliance applications 124. For instance, the first version of the AWM 126A might need a different patch from the second version AWM 126B even if a similar or the same vulnerability is being exploited at both the first and second versions. During the time involved in generating the updates (e.g., 308A, 308B, 310A, and 31 OB), the exploit might enable a malicious actor to access the first and the second private networks or the network appliances 102.

[0091] Accordingly, in the second update process 300B, the updated WAF rules 302 may be communicated to the WAFs 128A and 128B of multiple network appliances 102. The updated WAF rules 302 may be communicated to the multiple network appliances 102 simultaneously or substantially simultaneously (e.g., without material delay between network appliances 102), which may at least temporarily resolve an active exploit. For instance, the updated WAF rules 302 might include WAF rules that are configured to mitigate an exploited vulnerability prior to the generation and distribution of module / application updates 308A, 308B, 310A, and 310B. Thus, the module / application updates 308A, 308B, 310A, and 310B may be distributed as they are developed independently of one another and independently of the updated WAF rules 302.

[0092] As the module / application updates 308A, 308B, 310A, and 310B are developed and distributed, additional updated WAF rules 302 may be generated and communicated as necessary until the vulnerability is mitigated.

[0093] For example, the enterprises 116A and 116B may be actively exploited because of a vulnerability in the AWMs 126 A and 126B. The AWMs 126 A and 126B may be different versions, requiring a first updated AWM 308A to be different from a second updated AWM 308B. The updated WAF rules 302 may be communicated to the WAFs 128A and 128B and might include one or more WAF rules that protect the enterprises 116A and 116B against the actively exploited vulnerability of the AWMs 126 A and 126B. The updated WAF rules 302 may be communicated to both the network appliances 102 at the same time, which may provide some mitigation to the actively exploited vulnerability. The first updated AWM 308A may then be developed and tested and deployed to the first network appliance 102 A. Later, the second updated AWM 308B may be developed tested and deployed to the second network appliance 102B. Afterthe first and second updated AWM 308A and 308B are deployed, subsequent updated WAF rules 302 may be communicated to the network appliances 102 to remove mitigation WAF rules.

[0094] In the embodiment of Figures 3 A and 3B, the updated WAF rules 302 are communicated from the admin device 108. In these embodiments, the admin device 108 might host an admin user interface portal that enables the generation and distribution of the updated WAF rules 302. Alternatively, the updated WAF rules 302 may be implemented via a network appliance management service, which may be a cloud-based SAAS management service. In other embodiments in which the network appliance 102 is virtual or a cloud appliance, the updated WAF rules 302 may be implemented via a REST API or an import functionality.

[0095] In some embodiments, the updates to the network appliances 102 described with reference to Figures 3 A and 3B may result in multiple sets of WAF rules existing on the network appliances 102. For instance, the network appliances 102 may include a current version, a rollback version, and a default version. The network appliances 102 might store at least temporarily these versions to enable rollback operations responsive to a current or most recent version causing functionality issues at the network appliances 102. For instance, the updated WAF rules 302 might introduce a malfunction into the network appliances 102. In response, the admin device 108 may implement a rollback operation to pull the updated WAF rules 302 and re-install the WAF rules 226.

[0096] Figure 4 illustrates an example computer system 400 configured for network appliance security, according to at least one embodiment of the present disclosure. The computer system 400 may be implemented in the operating environment 100 Figure 1, for instance. Examples of the computer system 400 may include the network appliance 102, the private server 104, the computing devices 106, or some combination thereof. The computer system 400 may include one or more processors 410, a memory 412, a communication unit 414, a user interface device 416, and a data storage 404 that includes one or more or a combination of the WAF 128, the AWM 126, the appliance application 124, the WAF rules 226, and the private resource 110 (collectively, system modules 450).

[0097] The processor 410 may include any suitable special-purpose or general -purpose computer, computing entity, or processing device including various computer hardware or software modules and may be configured to execute instructions stored on any applicable computer-readable storage media. For example, the processor 410 may include a microprocessor, a microcontroller, a digital signal processor (DSP), an ASIC, an FPGA, or any other digital or analog circuitry configured to interpret and / or to execute program instructions and / or to process data. Although illustrated as a single processor in Figure 4, the processor 410 may more generally include any number of processors configured to perform individually or collectively any number of operations described in the present disclosure. Additionally, one or more of the processors 410 may be present on oneor more different electronic devices or computing systems. In some embodiments, the processor 410 may interpret and / or execute program instructions and / or process data stored in the memory 412, the data storage 404, or the memory 412 and the data storage 404. In some embodiments, the processor 410 may fetch program instructions from the data storage 404 and load the program instructions in the memory 412. After the program instructions are loaded into the memory 412, the processor 410 may execute the program instructions.

[0098] The memory 412 and the data storage 404 may include computer-readable storage media for carrying or having computer-executable instructions or data structures stored thereon. Such computer-readable storage media may include any available media that may be accessed by a general -purpose or special-purpose computer, such as the processor 410. By way of example, and not limitation, such computer-readable storage media may include tangible or non-transitory computer-readable storage media including RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, flash memory devices (e.g., solid state memory devices), or any other storage medium which may be used to carry or store desired program code in the form of computer-executable instructions or data structures and that may be accessed by a general-purpose or special-purpose computer. Combinations of the above may also be included within the scope of computer-readable storage media. Computer-executable instructions may include, for example, instructions and data configured to cause the processor 410 to perform a certain operation or group of operations.

[0099] The communication unit 414 may include one or more pieces of hardware configured to receive and send communications. In some embodiments, the communication unit 414 may include one or more of an antenna, a wired port, and modulation / demodulation hardware, among other communication hardware devices. In particular, the communication unit 414 may be configured to receive a communication from outside the computer system 400 and to present the communication to the processor 410 or to send a communication from the processor 410 to another device or network (e.g., the network 120 of Figure 1). Some examples of the communication unit 414 may include the internal interface 122 and the external interface 130.

[0100] The user interface device 416 may include one or more pieces of hardware configured to receive input from and / or provide output to a user. In some embodiments, the user interface device 416 may include one or more of a speaker, a microphone, a display, a keyboard, a touch screen, or a holographic projection, among other hardware devices.

[0101] The system modules 450 may include program instructions stored in the data storage 404. The processor 410 may be configured to load the system modules 450 into the memory 412 and execute the system modules 450. Alternatively, the processor 410 may execute the system modules 450 line-by-line from the data storage 404 without loading them into the memory 412. Whenexecuting the system modules 450, the processor 410 may be configured to perform one or more processes or operations described elsewhere in this disclosure.

[0102] Modifications, additions, or omissions may be made to the computer system 400 without departing from the scope of the present disclosure. For example, in some embodiments, the computer system 400 may not include the user interface device 416. In some embodiments, the different components of the computer system 400 may be physically separate and may be communicatively coupled via any suitable mechanism. For example, the data storage 404 may be part of a storage device that is separate from a device, which includes the processor 410, the memory 412, and the communication unit 414, that is communicatively coupled to the storage device. The embodiments described herein may include the use of a special-purpose or general-purpose computer including various computer hardware or software modules, as discussed in greater detail below.

[0103] Figure 5 is a sequence diagram of an example secure network appliance traffic analysis process (analysis process) 500 that may be implemented in the operating environment 100 of Figure 1 or another suitable environment. The analysis process 500 may be implemented by the user 115, the computing device 106, and the AWM 126, WAF 128, and appliance application 124 of the network appliance 102 described with reference to Figures 1-3B.

[0104] The analysis process 500 may begin by the user 115 inputting (502) a request to the computing device 106. The computing device 106 may communicate (504) the request or some derivative thereof to the AWM 126 of the network appliance 102. In some embodiments, the request may be communicated to the AWM 126 via an external interface such as the external interface 130. The AWM 126 may forward (506) the request to the WAF 128. The AWM 126 may forward the request via a connector, which is described elsewhere in the present disclosure. The WAF 128 may evaluate or analyze (508) the request using WAF rules. The WAF 128 analyzes the request to determine whether the request is malicious or non-malicious.

[0105] The analysis process 500 proceeds to operations 510 and 512 of a dashed box 548 labelled “alt” in response to the request being identified as malicious. For instance, the WAF 128 may communicate (510) an error message such as a 403 forbidden message to the AWM 126. The AWM 126 may then communicate (512) the error message to the computing device 106.

[0106] Otherwise, in response to the request being non-malicious, the analysis process 500 proceeds to the operations 514, 516, 518, 520, 522, 524, 526, 528, and 530 of box 550. For example, the WAF 128 may communicate (514) the request (which is determined to be non-malicious) to the AWM 126. The AWM 126 may the communicate the request to the appliance application 124. The appliance application 124 may communicate the request to a private network such as the private network 112 or may generate a response to the received request.A response from the private network be received at the appliance application 124 or the response may be generated by the appliance application 124. The appliance application 124 then communicates (518) the response to the AWM 126. The AWM 126 communicates (520) the response to the WAF 128. The response may be communicated via the connector. The WAF 128 receives the response and evaluates or analyzes (522) the response based on the WAF rules. The analysis of the response determines whether the response is valid or invalid according to the WAF rules.

[0107] The analysis process 500 proceeds to operations 524 and 526 of dashed box 546 in response to the response being invalid. The analysis process 500 proceeds to operations 528 and 530 of dashed box 552 in response to the response being valid. For example, the WAF 128 may communicate (524) the error message to the AWM 126 when the response is invalid. The AWM 126 communicates (526) the error message to the computing device 106. Alternatively, when the response is valid, the WAF 128 communicates (528) the response to the AWM 126. The AWM 126 then communicates (530) the response to the computing device 106.

[0108] Figures 6A-6B are a flowchart of an example method 600 of network appliance security. The method 600 may be implemented at least partially by a network appliance that provides and controls network access to a private network. The network appliance may be one of multiple network appliances implemented in the private network or in multiple, separate private networks. In addition, the method 600 may be implemented in other types network appliances that provide security and network traffic inspection operations such as switches, hubs, bridges, routers, gateways, and access points. The method 600 may also be implemented in a cloud-based network appliance.

[0109] The method 600 may begin at block 602, in which a selection of a security level may be received. The security level selection may be received from an administrative device or computing device that operates to manage the network appliance. The security level is indicative of the number and types of WAF rules included in analyses of appliance traffic such as requests and responses as described below. At block 604, a subset of WAF rules may be implemented during the appliance traffic analyses. The subset of WAF rules that are implemented corresponds to the security level selection. In some embodiments, the security level selection may occur prior to remaining operations of the method 600. In other embodiments the security level selection may occur during (e.g., between two or more blocks) the method 600.

[0110] At block 606, a request may be received. The request may be received at an external interface of the network appliance. The request may be received from a computing device of a public network and / or outside a private network that implements the network appliance. The request may be directed to an appliance application.In some embodiments, the request is encrypted when it is received at the external interface. For instance, the request may be encrypted when the request is communicated over a VPN, when the request originates at a proprietary application on the compute device, or when the request is directed to a private server of the private network. In embodiments in which the request is encrypted, the method may include block 608. At block 608, the request may be decrypted. The request may be decrypted by an AWM, which is included in the network appliance. The AWM may store certificates and / or keys sufficient to decrypt the requests. The request may be decrypted before the request is communicated to appliance application and the WAF. In embodiments in which block 608 is performed, the operations of blocks 610, 612, 618, and 620 include communication and analysis of the decrypted request. In embodiments in which block 608 is not performed, the operations of blocks 610, 612, 618, and 620 include communication and analysis of request as it is received at the external interface.

[0111] At block 610, the request may be forwarded to a WAF. The request may be forwarded to the WAF such that the WAF analyzes the request or the decrypted request according to WAF rules. The WAF rules are configured to identify and block attack patterns in requests.

[0112] Some examples of the WAF rules include a hypertext transfer protocol (HTTP) traffic monitoring rule, a logging rule, a real-time traffic analysis rule, or some combination thereof. The WAF rules may include one or more OWASP Core Rules and may include one or more custom WAF rules. As discussed above, in some embodiments, subsets of the WAF rules may be implemented based on the security level selection of blocks 602 and 604. For instance, the security level selection might be based on the security level of the private network. Specifically, an online banking private network may have a medium-high level of security, and a nuclear power plant may have a high level of security. The medium-high level of security may implement a first set of the WAF rules, and the high level of security may implement a second set of the WAF rules. The second set of WAF rules may apply a stricter level of scrutiny to the request than the first set of WAF rules.

[0113] The request may be forwarded to the WAF via a connector. The connector includes a communication channel between the network appliance or the AWM and the WAF that is established specifically for communication of the requests. In some embodiments, the WAF may be further configured to generate a log entry. The log entry records results of the analysis of the request. For instance, each blocked request may be logged with the administrator device, which may enable review of the analysis or results of the analysis.

[0114] The request may be forwarded to the WAF before the request is communicated to appliance application. Accordingly, in these embodiments, the WAF performs an inspection of the request prior to processing by the appliance application. Some examples of the appliance application mayinclude one or more or a combination of a SAML service, a CGI service, other UI applications, a REST-API service, authentication services, analytics services, proxy services, tunnelling services, terminal services, virtual desktop services, a rewriter service, another suitable network data service, or some combination thereof. Accordingly, the request might request a user or application verification or authentication. The analysis performed by the WAF ensures that the request is not malicious.

[0115] At block 612, it may be determined whether the request is malicious. The determination of block 612 is based on the application of the WAF rules to the request. In response to an analysis indicating the request is malicious (“YES” at block 612), the method 600 may proceed to block 614. In response to the analysis indicating the request is non-malicious (“NO” at block 612), the method 600 may proceed to block 618 of Figure 6B.

[0116] At block 614, an error message may be received. The error message may be received from the WAF after the analysis. At block 616, the error message may be forwarded to the computing device via the external interface. The AWM may receive the error message and then forward the error message to the computing device of the public network via the external interface. An example of the error message is a 403 forbidden error message. After the error message is forwarded in block 616, the method 600 may end at block 644. Accordingly, the WAF has identified the request as being malicious. In response, the request is not communicated to the appliance application or to the private network.

[0117] Referring to Figure 6B, at block 618, the request may be received from the WAF. The request may be received via the connector. At block 620, the request may be communicated to the appliance application. Accordingly, the WAF has identified the request as being non-malicious. The request is not block or dropped and is communicated to the appliance application, where it is further analyzed or processed. In some circumstances (e.g., some requests directed to the appliance application and a private server of the private network), the appliance application may then send the request or some derivative of the request to the private network via an internal interface.

[0118] At block 622, internal data traffic may be received. The internal data traffic may be a response to the request analyzed by the WAF. For instance, the request may seek specific data such as keys, APIs, etc. from the appliance application. The internal data traffic may include the specific, secured data that is accessed based on the request from the appliance application. Accordingly, the internal data traffic may be received from the appliance application. Additionally, in circumstances in which the request is directed to the appliance application and ultimately to the private network, the internal data traffic may originate at the private network. In these circumstances, the internal data traffic may be received at the internal interface of the network appliance, directed to the appliance application, and then communicated to the AWM.In some embodiments, the internal network traffic might be encrypted. The AWM may have stored certificates and / or keys that enable the decryption of the internal data traffic. For instance, the internal data traffic might originate at a proprietary application of the private network. In these and other circumstances, the AWM might have stored thereon the certificate and / or keys that enable decryption of the internal data traffic. However, in some other circumstances, the internal data traffic might originate at a third-party application (e.g., a third-party application operating at least partially in the private network). Accordingly, the AWM may not have the certificate and / or keys suitable to decrypt the internal data traffic. When the AWM has the certificates and / or keys, the AWM decrypts the internal network traffic prior to communication to the WAF (e.g., in block 624). Thus, the operations of blocks 624 and 628 include communication and analysis of decrypted internal data traffic. However, when the AWM does not have the certificates and / or keys, the operations of block 624 include communication and analysis of encrypted internal data traffic. The analysis (e.g., of block 626) of the encrypted internal data traffic may include inspection of plaintext portions of the internal data traffic such as headers, source / destination addresses or applications, etc.

[0119] At block 624, the internal data traffic may be forwarded to the WAF. The internal data traffic may be forwarded via the connector. The WAF further analyzes the internal data traffic according to the WAF rules. The internal data traffic is forwarded to the WAF before the internal data traffic is communicated to the computing device. Accordingly, the WAF analyses the internal data traffic before it leaves the private network.

[0120] At block 626, it is determined whether the internal data traffic is an invalid response. The determination is based on application of the WAF rules to the internal data traffic. An invalid response includes sensitive or protected information that is quarantined from the computing device of the public network and / or includes large quantities of protected information such as multiple credit card numbers, privacy data, administrative or user credentials, and the like. In contrast, a valid response does not include sensitive or protected information or includes protected information in a suitable amount for the computing device such as one credit card number, a single or a defined number (e.g., less than (5) five) account numbers, and the like. Definitions of valid and invalid responses are configured according to the WAF rules. For instance, a first WAF rule may limit account numbers to five, a second WAF rule may prevent communication of social security numbers, and a third WAF rule may prevent communication of all plaintext biometric authentication information.

[0121] In response to the analysis of the internal data traffic indicating an invalid response (“YES” at block 626), the method 600 may proceed to block 614. As discussed above, execution of blocks 614, 616, and 644 result in blocking network traffic. Accordingly, the internal data traffic isblocked from the computing device of the public network such that the invalid response is not communicated.

[0122] In response to the analysis of the internal data traffic indicating a valid response (“NO” at block 626), the method 600 may proceed to block 628. At block 628, the internal data traffic may be received from the WAF. The internal data traffic may be received via the connector. At block 630, the internal data traffic may be communicated to the computing device via the external interface. Accordingly, valid responses, as evaluated by the application of the WAF rules to the internal data traffic, are communicated to the computing device of the public network.

[0123] At block 632, the WAF rules may be updated. The update to the WAF rules may occur responsive to conditions outside the private network such as new vulnerabilities or exploits and may occur based on changes made by an enterprise implementing the method 600 such as changes to reduce a number of false positives or to increase a security level. The update to the WAF rules may be related to other updates of the network appliance or may be performed independently of other updates to the network appliance. Some additional examples are described with reference to Figure 7. After the WAF rules are updated, the method may proceed to block 606 and proceed through one or more operations of Figures 6 A and 6B.

[0124] Figure 7 is a flowchart of an example method 700 of updating network appliances integrating a WAF according to at least one embodiment of the present disclosure. The method 700 may be implemented as part of another method such as part of block 632 of Figure 6B. Alternatively, the method 700 may be implemented separately from the method 600 of Figures 6A and 6B and may be implemented to update the WAF rules, which are used in analysis of the requests or the internal data traffic.

[0125] Figure 7 includes blocks 702, 704, 706, 708, 710, 712, 714, and 716. The operations of blocks 702, 704, 706, 708, 710, 712, 714, and 716 describe update operations that may be implemented in the network appliance. The update operations may occur responsive to conditions outside the private network or the network appliance such as new vulnerabilities or exploits and may occur based on changes made by an enterprise implementing the method 600 such as changes to reduce a number of false positives or to increase a security level. Not all operations of blocks 702, 704, 706, 708, 710, 712, 714, and 716 are necessarily performed. For instance, in some circumstances, blocks 702 and 704 may be performed and blocks 706, 708, 710, 712, 714, and 716 may not be performed.

[0126] For instance, at block 702, identification of a new or unknown attack pattern may be received. That is, a previously unknown vulnerability may be identified in the AWM or the appliance application. At block 704, in response to identification of a new or unknown attackpattern, the WAF rules may be updated with an additional WAF rule that identifies and blocks the new or unknown attack pattern. After block 704, the method 700 may proceed to block 716.

[0127] In some embodiments, the WAF rules or the additional WAF rule may include one or both of version numbers and signatures. The version numbers may be sequentially assigned to the WAF rules to assist in administration of the WAF rules and updates thereto. In addition, some WAF rules may be initially installed into a network appliance. This initial version of the WAF rules may not include a signature because these WAF rules are trustworthy. However, updates to the WAF rules may include a signature. The signature may indicate a source of the updated WAF rules, which may be used by the WAF to verify or authenticate the updated WAF rules.

[0128] At block 706, a log may be received. The log indicate that the analysis results such as results of the analysis of the response or the internal traffic data of blocks 626 and 612 of Figures 6A and 6B. For instance the WAF may be configured to generate a log entry that records results of the analyses of the appliance traffic. At block 708, it may be determined whether the analysis resulted in a false positive. False positive results identify a request as malicious that is non-malicious or internal traffic data as invalid that is valid. The determination of block 708 may be based on the log. In response to a determination that the analysis did not result in the false positive (“NO” at block 708), the method 700 may proceed to block 718, where the method 700 ends, the log, the WAF rules may be updated. In response to a determination that the analysis resulted in the false positive (“YES” at block 708), the method 700 may proceed to block 710. At block 710 the WAF rules may be updated. For instance, the WAF rules may be updated by disabling a first WAF rule that is causing the false positive. After block 710, the method 700 may proceed to block 716.

[0129] At block 712, an indication of a detected exploit may be received. The detected exploit may indicate that vulnerability such as a zero-day vulnerability may be being used by a malicious actor to access the appliance application, the private network, or a private resource. At block 714, the WAF rules may be updated. The WAF rules may be updated independently of an update to one or both of the appliance applications and the AWM. The update to the WAF rules may occur in response to the detected exploit. The update to the WAF rules mitigates the detected exploit and secures the network appliance or the private network during a time period between identification of the detected exploit and the update to the appliance applications, the AWM, and the private network. After block 714, the method 700 may proceed to block 716.

[0130] At block 716, one or both of the appliance application and the AWM may be updated. The operations of block 716 are optional. For instance, in some embodiments, the operations of blocks 704, 710, and 714 may occur and the operations of block 716 may not occur. For instance, the update to the WAF rules effectively mitigate an exploit or may resolve the false positives. Accordingly, block 716 may not be performed.The WAF rules may be updated in two or more network appliances. For instance, an example system may include a first network appliance having a first AWM and a first set of appliance applications. The first network appliance may operate in a first private network associated with a first enterprise. The first set of appliance applications and the first AWM may be first versions (e.g., version 1). The system may further include a second network appliance having a second AWM and a second set of appliance applications that are second versions (e.g., version 2), which are different from the first versions. The second network appliance may operate in a second private network associated with a second enterprise.

[0131] Before the detected exploit, the WAF rules are implemented at the first network appliance and the second network appliance. For instance, the first and the second network appliances may implement a WAF with the set of WAF rules.

[0132] In this example system, it may be time consuming to generate updates for both the first versions and the second versions. During the time involved in generating the updates, the exploit might enable a malicious actor to access the first and the second private networks. The set of WAF rules may be updated in both the first network appliance and the second network appliance such that the update to the set of WAF rules mitigates the detected exploit at the first and the second network appliances between the detected exploit and updates to the first and second versions.

[0133] Although illustrated as discrete blocks, one or more blocks in Figures 6A-7 may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the desired implementation. One or more of the methods described in the present disclosure may be performed in a suitable operating environment such as the operating environment 100. The methods 600and 700 may be performed by the network appliance 102 or another computing device (e.g., 400 of Figure 4). In some embodiments, the network appliance 102 or another computing system may include or may be communicatively coupled to a non-transitory computer-readable medium (e.g., the memory 412 of Figure 4) having stored thereon programming code or instructions that are executable by one or more processors (such as the processor 410 of Figure 4) to cause a computing system or the network appliance 102 to perform or control performance of the methods. Additionally or alternatively, the network appliance 102 or another computing device may include the processor 410 described elsewhere in this disclosure that is configured to execute computer instructions to cause the network appliance 102 or another computing systems to perform or control performance of the methods.

[0134] Further, modifications, additions, or omissions may be made to the methods without departing from the scope of the present disclosure. For example, the operations of methods may be implemented in differing orders. Furthermore, the outlined operations and actions are only provided as examples, and some of the operations and actions may be optional, combined intofewer operations and actions, or expanded into additional operations and actions without detracting from the disclosed embodiments.

[0135] The embodiments described herein may include the use of a special purpose or general-purpose computer including various computer hardware or software modules, as discussed in greater detail below.

[0136] Embodiments described herein may be implemented using computer-readable media for carrying or having computer-executable instructions or data structures stored thereon. Such computer-readable media may be any available media that may be accessed by a general purpose or special purpose computer. By way of example, and not limitation, such computer-readable media may include non-transitory computer-readable storage media including Random Access Memory (RAM), Read-Only Memory (ROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Compact Disc Read-Only Memory (CD-ROM) or other optical disk storage, magnetic disk storage or other magnetic storage devices, flash memory devices (e.g., solid state memory devices), or any other storage medium which may be used to carry or store desired program code in the form of computer-executable instructions or data structures and which may be accessed by a general purpose or special purpose computer. Combinations of the above may also be included within the scope of computer-readable media.

[0137] Computer-executable instructions may include, for example, instructions and data, which cause a general-purpose computer, special purpose computer, or special purpose processing device (e.g., one or more processors) to perform a certain function or group of functions. Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

[0138] As used herein, the terms “module” or “component” may refer to specific hardware implementations configured to perform the operations of the module or component and / or software objects or software routines that may be stored on and / or executed by general purpose hardware (e.g., computer-readable media, processing devices, etc.) of the computing system. In some embodiments, the different components, modules, engines, and services described herein may be implemented as objects or processes that execute on the computing system (e.g., as separate threads). While some of the systems and methods described herein are generally described as being implemented in software (stored on and / or executed by general purpose hardware), specific hardware implementations or a combination of software and specific hardware implementations are also possible and contemplated. In this description, a “computing entity” maybe any computing system as previously defined herein, or any module or combination of modulates running on a computing system.

[0139] The various features illustrated in the drawings may not be drawn to scale. The illustrations presented in the present disclosure are not meant to be actual views of any particular apparatus (e.g., device, system, etc.) or method, but are representations employed to describe embodiments of the disclosure. Accordingly, the dimensions of the features may be expanded or reduced for clarity. In addition, some of the drawings may be simplified for clarity. Thus, the drawings may not depict all of the components of a given apparatus (e.g., device) or all operations of a particular method.

[0140] Terms used in the present disclosure and the claims (e.g., bodies of the appended claims) are intended as “open” terms (e.g., the term “including” should be interpreted as “including, but not limited to,” the term “having” should be interpreted as “having at least,” the term “includes” should be interpreted as “includes, but is not limited to,” among others). Additionally, if a specific number of an introduced claim recitation is intended, such an intent will be explicitly recited in the claim, and in the absence of such recitation no such intent is present. For example, as an aid to understanding, the following appended claims may contain usage of the introductory phrases “at least one” and “one or more” to introduce claim recitations.

[0141] In addition, even if a specific number of an introduced claim recitation is explicitly recited, those skilled in the art will recognize that such recitation should be interpreted to mean at least the recited number (e.g., the bare recitation of “two recitations,” without other modifiers, means at least two recitations, or two or more recitations). Furthermore, in instances in which a convention analogous to “at least one of A, B, and C, etc.” or “one or more of A, B, and C, etc.” is used, in general such a construction is intended to include A alone, B alone, C alone, A and B together, A and C together, B and C together, or A, B, and C together, etc. Further, any disjunctive word or phrase presenting two or more alternative terms should be understood to contemplate the possibilities of including one of the terms, either of the terms, or both terms. For example, the phrase “A or B” should be understood to include the possibilities of “A” or “B” or “A and B.” However, the use of such phrases should not be construed to imply that the introduction of a claim recitation by the indefinite articles “a” or “an” limits any particular claim containing such introduced claim recitation to embodiments containing only one such recitation, even when the same claim includes the introductory phrases “one or more” or “at least one” and indefinite articles such as “a” or “an” (e.g., “a” and / or “an” should be interpreted to mean “at least one” or “one or more”); the same holds true for the use of definite articles used to introduce claim recitations.

[0142] The terms “first,” “second,” “third,” etc., are not necessarily used to connote a specific order or number of elements. Generally, the terms “first,” “second,” “third,” etc., are used to distinguishbetween different elements as generic identifiers. Absence a showing that the terms “first,” “second,” “third,” etc., connote a specific order, these terms should not be understood to connote a specific order. Furthermore, absence a showing that the terms “first,” “second,” “third,” etc., connote a specific number of elements, these terms should not be understood to connote a specific number of elements. For example, a first widget may be described as having a first side and a second widget may be described as having a second side. The use of the term “second side” with respect to the second widget may be to distinguish such side of the second widget from the “first side” of the first widget and not to connote that the second widget has two sides.

[0143] All examples and conditional language recited herein are intended for pedagogical objects to aid the reader in understanding the invention and the concepts contributed by the inventor to furthering the art and are to be construed as being without limitation to such specifically recited examples and conditions. Although embodiments of the present inventions have been described in detail, it should be understood that the various changes, substitutions, and alterations could be made hereto without departing from the scope of the invention.

Claims

CLAIMSWhat is claimed is:

1. A method of network appliance security, the method comprising:receiving, at an external interface of a network appliance, a network data request, wherein the network data request is received from a computing device of a public network and is directed to an appliance application;before the network data request is communicated to the appliance application, forwarding the network data request to a web application firewall (WAF) via a connector such that the WAF analyzes the network data request according to WAF rules that identify and block attack patterns in network data request;responsive to an analysis by the WAF indicating the network data request is malicious, receiving from the WAF an error message, and forwarding the error message to the computing device via the external interface; andresponsive to the analysis by the WAF indicating the network data request is non-malicious:receiving, from the WAF, the network data request via the connector; and communicating the network data request to the appliance application.

2. The method of claim 1, wherein:the network data request is encrypted when it is received at the external interface; and the method further comprises decrypting the network data request before the network data request is communicated to the appliance application; anda certificate sufficient to decrypt the network data request is locally stored.

3. The method of claim 1, further comprising:receiving a selection of a security level, wherein the security level is indicative of a number and types of WAF rules included in the analysis; andimplementing a subset of the WAF rules during the analysis based on the selected security level.

4. The method of claim 1, further comprising:receiving, from the appliance application, internal data traffic that is generated and communicated from the appliance application in response to the network data request;before the internal data traffic is communicated to the computing device, forwarding the internal data traffic to the WAF via the connector such that the WAF further analyzes the internal data traffic according to the WAF rules;responsive to the analysis of the internal data traffic indicating an invalid response:receiving, from the WAF, an error message, andforwarding the error message to the computing device via the external interface; andresponsive to the analysis of the internal data traffic indicating a valid response:receiving, from the WAF, the internal data traffic via the connector; and communicating the internal data traffic to the computing device via the external interface,wherein:a valid response does not include sensitive or protected information; and an invalid response includes sensitive or protected information.

5. The method of claim 4, wherein:the internal data traffic is encrypted when the internal data traffic is received; and the method further comprises:responsive to the internal data traffic originating at a proprietary system, accessing a certificate of the proprietary system and decrypting the internal data traffic before forwarding the internal data traffic to the WAF; andresponsive to the internal data traffic originating at a third-party system, forwarding the internal data traffic to the WAF in an encrypted format.

6. The method of claim 1, further comprising in response to identification of a new or unknown attack pattern, updating the WAF rules with an additional rule that identifies and blocks the new or unknown attack pattern, wherein the additional rule includes a WAF signature that is received by the WAF to authenticate the additional rule.

7. The method of claim 1, further comprising:based on a log entry, determining that the analysis resulted in a false positive, wherein the log entry is generated by the WAF and records results of the analysis of the network data request, and the false positive is a result of the analysis indicating the network data request is malicious and the network data request is actually non-malicious; andresponsive to a determination that the analysis resulted in the false positive, updating the WAF rules by disabling a first WAF rule that is causing the false positive.

8. The method of claim 1, wherein:the appliance application includes one or more or a combination of:a security assertion markup language (SAML) service,a common gateway interface (CGI) service,a representational state transfer application programming interface (REST-API) service,a rewriter service;an authentication service;an analytics service;a proxy service;a tunnelling service;a terminal service; anda virtual desktop service; andthe connector includes a communication channel between a network appliance and the WAF.

9. The method of claim 1, further comprising:detecting an exploit of the appliance application; andin response to the detected exploit, updating the WAF rules independently of an update to the appliance application,wherein the update to the WAF rules mitigates the detected exploit and secures the appliance application at least temporarily during a time between identification of the detected exploit and the update to the appliance application.

10. The method of claim 9, wherein:the network appliance is a first network appliance implemented in a first private network, the first network appliance includes a first appliance web module;the appliance application is a first appliance application;the first appliance application and the first appliance web module are first versions; a second network appliance that is implemented in a second private network;the second network appliance includes a second appliance web module and a second appliance application that are second versions that are different from the first versions;before the detected exploit, the WAF rules are implemented at the first network appliance and the second network appliance; andthe update to the WAF rules mitigates the detected exploit at the first and the second network appliances between the detected exploit and updates to the first and second versions.

11. The method of claim 1, wherein the network data request is configured such that after the network data request is received by the appliance application, the network data request is further communicated to a private server of a private network.

12. The method of claim 1, wherein:an appliance web module receives the network data request, forwards the network data request to the WAF, and receives the error message from the WAF;the WAF, the appliance application, and an appliance web module are physically located in one apparatus; orthe WAF, the appliance application, and an appliance web module are integrated in a cloudbased appliance.

13. The method of claim 1, wherein:the WAF rules include:a hypertext transfer protocol (HTTP) traffic monitoring rule,a logging rule, ora real-time traffic analysis rule; andthe error message includes a 403 forbidden error message.

14. A non-transitory computer-readable medium having encoded therein programming code executable by one or more processors to perform or control performance of operations of any one of claims 1-13.

15. A network appliance comprising:one or more processors; andnon-transitory computer-readable medium having encoded therein programming code executable by the one or more processors to perform or control performance of operations of any one of claims 1-13.