Web Security Device Scanning for WAF Customization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Web Application Firewalls (WAFs) fail to configure a comprehensive and individualized security strategy for Web sites, as they rely on generic protection rules that do not account for site-specific vulnerabilities, leading to inadequate protection against threats like SQL injection attacks.

Innovation Solution

A web security protection method and system that involves a web security device scanning a Web site for security bugs and sending the scan results to a WAF, allowing the WAF to configure a customized security strategy based on the identified vulnerabilities, thereby enhancing the site's protection capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional WAF uses generic protection rules, then device complexity is reduced and ease of operation is improved, but protection effectiveness and adaptability to specific site vulnerabilities deteriorate

Engineering Contradiction:
Improveprotection effectivenessVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary vulnerability scanning of the web site before configuring protection rules. The scanning module automatically identifies security bugs and generates customized protection strategies in advance, eliminating the need for manual configuration and ensuring comprehensive coverage of site-specific vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The WAF system automatically scans its protected web site, identifies vulnerabilities, and configures protection rules without external intervention. The scanning module and rule generation module work autonomously to create individualized security strategies tailored to each site's specific vulnerabilities.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If traditional WAF uses generic protection rules, then ease of operation is improved, but adaptability to individualized security needs deteriorates

Engineering Contradiction:
Improveindividualized protection capabilityVSAvoidconfiguration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The WAF system automatically scans its protected web site, identifies vulnerabilities, and configures protection rules without external intervention. The scanning module and rule generation module work autonomously to create individualized security strategies tailored to each site's specific vulnerabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts protection parameters based on the scanned vulnerability profile of each web site. By changing the security configuration parameters according to detected bugs and threats, the system achieves high adaptability while maintaining ease of operation through automated parameter optimization.

Inventive Principle:
Principle #35Parameter changes

3Speed

If real-time monitoring is implemented, then response speed to security threats is improved, but device complexity and energy consumption increase

Engineering Contradiction:
Improveresponse speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The WAF continuously monitors web traffic and scans for vulnerabilities without interruption, maintaining constant security protection. The real-time scanning and threat detection capabilities ensure immediate response to security threats while the system manages complexity through integrated monitoring functions.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9485261B2Web security protection method, device and system
Publication Date: 2016.11.01 NSFOCUS INFORMATION TECHNOLOGY CO LTD
  • US9485261B2 patent drawing
  • US9485261B2 patent drawing
  • US9485261B2 patent drawing

AI summary

A method, device and system for network security protection comprise: according to a received scan task, a network security device performs a security bug scan of the scan task appointed web site, and when a scan result is obtained, transmits the scan result to a network application firewall, so that the network application firewall can configure a individuality security strategy for the web site according to the received scan result. The problem that it can not he implemented complete individuality security configuration of the web site can be solved in this way.