Home / Companies / Ngrok / Blog / Post Details
Content Deep Dive

How we built ngrok's WAF with OWASP CRS and Coraza

Blog post from Ngrok

Post Details
Company
Date Published
Author
Ben Chan
Word Count
100
Language
English
Hacker News Points
-
Summary

Ben Chan, a software engineer at ngrok, details the process of building ngrok's Web Application Firewall (WAF) by utilizing the OWASP Core Rule Set (CRS) and Coraza. This endeavor involved implementing a robust security framework to protect against common web vulnerabilities. By leveraging the OWASP CRS, which is a set of generic attack detection rules, and integrating it with Coraza, an open-source WAF engine, ngrok enhanced its security measures to safeguard web applications effectively. The approach underscores the importance of employing tested and community-supported security tools to maintain a resilient and secure web infrastructure.