--- title: "Christian Folini -- CRS and an Abstraction Layer" url: https://appsecpodcast.com/christian-folini-crs-and-an-abstraction-layer/ date: 2018-08-07 duration_seconds: 1521 guests: ["Christian Folini"] topics: ["OWASP Projects"] audio: https://www.buzzsprout.com/1730684/episodes/8122678-christian-folini-crs-and-an-abstraction-layer.mp3 transcript: true --- # Christian Folini -- CRS and an Abstraction Layer *August 7, 2018 · 25 min* with [Christian Folini](https://appsecpodcast.com/guests/christian-folini/) on [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122678-christian-folini-crs-and-an-abstraction-layer.mp3) ## Show notes How can one open-source rule set protect applications across competing products and very different architectures? Christian Folini explains the relationship between the ModSecurity engine and the OWASP Core Rule Set, including the attacks generic rules can detect and the limits of a web application firewall. Recorded at AppSec Europe, the conversation explores a gathering of vendors and contributors working to improve compatibility, feedback, and the project’s future. Christian describes the proposed abstraction layer that could separate security rules from a particular engine and bring detection closer to application code. He also discusses funding, testing, false positives, and integrating protection into continuous delivery. The result is a practical look at both the engineering and community work behind widely deployed open-source defenses. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Christian Folini: → [Christian Folini on LinkedIn](https://www.linkedin.com/in/christian-folini-588ba278/) → [Christian Folini’s website](https://www.christian-folini.ch/) Mentioned in this episode: → [OWASP Core Rule Set](https://coreruleset.org/) → [ModSecurity](https://owasp.org/www-project-modsecurity/) Chapters: 00:00 Christian Folini and the Core Rule Set 01:38 From medieval history to application security 02:39 How CRS fits with the ModSecurity engine 03:42 Attack coverage and a WAF’s limits 06:06 Bringing vendors together at AppSec Europe 08:39 A common abstraction layer for security rules 12:57 Funding and contributing to open source 15:30 More outcomes from the CRS gathering 17:46 CRS in continuous integration and runtime protection 19:42 Could CRS run inside an application runtime? 20:40 Moving security decisions closer to the code 23:50 Where to learn more and contribute ## Transcript *4,022 words · assemblyai* **0:01 Chris Romeo:** Hey folks, season 4, episode 2 of the Application Security Podcast. On this episode, I'm joined by Christian Fellini, who is a project lead on the OWASP Core Rule Set project for ModSecurity. Christian explains to us what the Core Rule Set is, how it fits together with ModSecurity, and also shares some of the output from a session they had at AppSecEU where a bunch of vendors and people that are into this project got together and discussed how to make Core Ruleset even better for the future. So we hope you enjoy. The Application Security Podcast. Here we go. We are coming to you from AppSecEU once again, and the topic for this particular session is, amongst other things, mod_security and CRS, but we'll get to that in a second. I'm joined by Christian, and Christian, if you would please tell Tell us a little bit about your security origin story first. If there was a comic book, what would episode 1 in the Christian story of security, what would that entail? How did you get into this? **1:38 Christian Folini:** The prequel, or the first chapter, would be Christian Fellini attending university studying medieval history. And in his spare time, running around medieval castles in Europe doing historical reenactment. And when I finished my PhD, I would apply at different museums to get a job, but actually I landed in a Unix service company. However that happened. And from there was a natural evolvement to get more and more into security and start volunteering, working on open source products and projects, and become a security engineer over time. **2:16** Okay. **2:17 Chris Romeo:** And I must tell the audience that as we were preparing for the interview, Kristjan was trying to plug his laptop in and was using some type of electronic gear, which I thought was maybe anti-hacking or something. You were concerned about some malware in the power plugs or something, but turns out you were just looking for the right voltage, right? **2:35 Christian Folini:** Yeah, probably true. Usually works, didn't this time. **2:39 Chris Romeo:** So what OWASP projects do you focus your time on? **2:45 Christian Folini:** I'm working mostly on the Corel set. So we're like the OWASP project with the longest name, we're the OWASP mod_security core ruleset. And if we're picking up where Tim Sauer finished his interview with you, mod_security is an engine running in a web server making it a fully featured WAF, but that is only the engine. On top of it, you will need the rules, and this is where the OWASP mod_security core ruleset comes in. That's this core set of rules which give you a base level of security. Base level in the sense that we like to think ourselves of covering 80-90% of web attacks by default with a very low percentage of false positives. And then you can tune and reconfigure it to bring the 80-90% to far beyond 95%, up to 99%. **3:42 Chris Romeo:** So when you say 80-90% of web attacks, If we were to look through the OWASP Top 10, what, what is Core Ruleset trying to knock out? I mean, cross-site scripting, SQL injection, what else? **3:55 Christian Folini:** It's the big ones. If you really push a Burp on steroids to take all out of the attack scanner, he's no longer able to push an SQL injection through the Core Ruleset, meaning recovering all the generic attacks, the script kiddie stuff, and it takes a dedicated well-advanced attacker to bypass the core ruleset. I'm not claiming that it's impossible, but a standard scanner is no longer capable of doing that if you configure it correctly. **4:26 Chris Romeo:** Yeah. **4:27 Christian Folini:** And yes, it's the basic— it's the injection stuff, it's the cross-site scripting, it's remote command execution, it's PHP code injection. And one of the newest features going to release is Java injections. So all these Java serialization attacks we've seen in the last 1 or 2 years, we bring a big set or group of rules which are addressing these threats. **4:54 Chris Romeo:** Okay, what about XXE? **4:56 Christian Folini:** That is an option. There is a feature we're bringing, but not security. So the base engine is not very strong on this. **5:05** Okay. **5:06 Christian Folini:** And And we're definitely limited by the capabilities of the engine underneath. **5:10 Chris Romeo:** Okay. **5:11 Christian Folini:** And that goes on to say we're only a first line of defense. Putting a well-functioning WAF in front of your application doesn't mean that's the end of your security problem. **5:22 Chris Romeo:** Yep. **5:23 Christian Folini:** No, that is a second safety net when you have bugs in your software, which you're likely having. And this will mean we protect you as a second safety net. **5:34 Chris Romeo:** Okay, okay, so MOD Security is not— is that an OWASP project as well? No, it's not. That's an industry open source? **5:45 Christian Folini:** It's an industry open source project run by Trustwave. **5:48 Chris Romeo:** Okay, and then, but the core rule set is in the OWASP universe? **5:53 Christian Folini:** Exactly, so the 2 projects are really distinct and separate. There's some people working on both projects, but It's basically one is the engine, that's the C code, and the other is the rule language. **6:06 Chris Romeo:** Okay, and I know you, or I've heard that you had a kind of a big meeting or event here at AppSecEU in London. What can you tell us a little bit about what's happened with the Core Ruleset project in the last couple of days here at the conference? **6:23 Christian Folini:** We've set up Core Ruleset Community Summit. Summit yesterday. So we used the AppSec EU conference to bring together our community, to have the developers actually talk to the big integrators. The point about mod_security, and Karol said, is it's not necessarily individual users using it on their local website, but it's the big content delivery networks or commercial products who are basing their offerings on our stuff. **6:53 Chris Romeo:** Okay. **6:54 Christian Folini:** And we've heard yesterday there are content delivery networks using our rules on 50 terabits per second of bandwidth. So there are millions or hundreds of millions of sites which are protected by our stuff, and we're just a tiny open source project. And yesterday, for the first time, we took all these people into the same room and we had very good feedback. of people actually coming in, flying in from all over the world to talk to us for the first time and get to talk to one another, because a lot of the people in the room have been competitors. **7:28** Yeah. **7:29 Christian Folini:** And they usually don't talk to one another, but there you had tech people realizing, look, we have the same kind of problem here and this is our solution. What are you guys doing? And maybe we should work on a common standard, or maybe we should do this, do that. So it was a networking event to a very large extent where we got people in touch with one another and forming small groups of task forces to tackle certain problems, come up with solutions, or helping the projects with their unique resources. Because for us as a small project, we're the developers and we have a very limited insight on web traffic. Obviously, just the sites we're running ourselves. While the big content delivery networks, they have a huge amount of traffic and they see all the false positives. They get the complaints from their users. And it would help us a lot if they would forward this feedback to us. And we've made good inroads yesterday organizing that. **8:29 Chris Romeo:** So, I mean, first, congratulations for building a product that can handle 50 terabits per second of bandwidth. I mean, that's— **8:37 Christian Folini:** I guess they're using a couple of servers to achieve that. **8:39 Chris Romeo:** Maybe a few. It's not just one, maybe. But still. to have a project that's created by— in the OWASP universe and that has that amount of impact on protecting the internet in general, that's just really cool. I'm impressed by that. I think that's very cool. Based on the summit that you had here, what do you think are the top 3 things that are going to come out of this summit that users and people that are fans of Core Ruleset and and that use the project, what are the top 3 things they're going to see over the next year as a result of the summit? **9:15 Christian Folini:** I think the project is going to profit from more input, more feedback, faster feedback loops resulting in a shorter release cycle. So we want to react quicker on new threats, maybe write new rules or push the new rules out faster to the users, maybe via a set of beta rules or testing rules that are not yet enforced, but you already get to see the alerts, stuff like that. **9:43 Chris Romeo:** Okay. **9:43 Christian Folini:** Because the big companies, the big integrators can help us with that. What we're also going to see is a new abstraction level because now we're tightly coupled with this mod_security engine, which it has to be admitted works on a quite awkward rule language that is really hard to read for most people. I usually say that I'm suffering from Stockholm syndrome. I read the rule language like the newspapers. But that is— for most people in the world, that's really painful. **10:16** Yeah. **10:17 Christian Folini:** And we built a group yesterday where we want to develop a meta-rule language, and then the mod security would just be an output for that. **10:28** filter. **10:28 Chris Romeo:** Ah, okay. **10:29 Christian Folini:** So we would compile or process the meta-language into mod_security speak, and this would allow us to do a different output filter for other WAF products, commercial, non-commercial offerings. Or let's do a Python output filter, and then people can use our knowledge into their input validation right in the application. And the same with Java, Ruby, or into the frameworks. So this will certainly widen the audience for our knowledge, which is built into the rules. And, and there is like 15 years of experience into these rules, and so far that's fairly limited to mod_security. **11:09 Chris Romeo:** After the break, Christian continues educating us about the future of the core rule set. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Christian picks back up answering the question about the timeline for a new input validation abstraction layer in mod security with core ruleset? Christian? **11:56 Christian Folini:** Don't hold your breath on this, but we have done good inroads in cleaning up our rulebase. So this was primordial for this new adventure because now when we generate the rules, we compare it to the original rules. **12:13 Chris Romeo:** Okay. **12:14 Christian Folini:** And this helps a lot because before that it was historically driven, it'd grown a lot, and awkward things in it and things we didn't understand ourselves because it's been so long time. I think so the base is laid now and we already have a proposal, written down proposal, how this could look like. **12:30 Chris Romeo:** Okay. **12:31 Christian Folini:** With example rules in it. But still, we need to develop that standard. There are now multiple commercial companies who formed like a committee yesterday who want to work on this. **12:41 Chris Romeo:** Okay. **12:41 Christian Folini:** So I'm confident then in the next couple of months we're going to see a valid proposal who can cover the whole ruleset and then maybe develop it. I wouldn't be surprised if it would take at least a year or maybe more, but that's kind of the horizon. **12:57 Chris Romeo:** Are any of these— is there like a commercial support or anything that happens in this type of project? Like if you have all these big companies that are using Core Ruleset, are they contributing to the project itself to kind of help move the project forward? **13:15 Christian Folini:** Okay, so we're like 10 people with commit rights on the project. And we have, like most of us have commercial backgrounds from companies who profit from a working core ruleset. And then we have a bit of sponsors. So Trustwave is actually dedicating 2 people to us who work on and off on our project, and they also developed the mod store. security engine. And our biggest sponsor right now is AV Networks, so they hand money to the project via OWASP. But we'll certainly welcome more commercial integrators dedicating resources to the project or helping us out, helping us with marketing. And one thing that we're really lacking is like success stories. So we know there are a lot of people using this. **14:02 Chris Romeo:** So you need that, you need that CDN story that was told. **14:05 Christian Folini:** That is so interesting. **14:06 Chris Romeo:** You need to get that on the website. And this makes me think of OpenSSL, kind of what happened with OpenSSL over the last number of years. Everybody was using it and nobody was contributing to it. And then all of a sudden, a lot of people got called on the carpet about it to say, you're building your products on this and you're not contributing to it. And then everybody, all the vendors kind of said, okay, you're right. And they formed the, you know, I think they do a lot of— **14:30 Christian Folini:** Foundation. Linux Software Foundation stepped in and channeling the money. **14:36 Chris Romeo:** They channel, yeah, yeah. **14:37 Christian Folini:** So they can get real people working it full-time. Yeah, so beneficial. And it seems like in this case it is a similar situation on a smaller scale. Yeah, I think not as many people use our stuff as OpenSSL. Yeah, and we're not a one-man-driven shop like OpenSSL used to be. And now I think they're up to 5 or 6 developers, which seems perfectly fine. **14:57 Chris Romeo:** Yeah, it seems like the right amount. On top of all the integration testing and things that happen in the companies and stuff. Yeah, okay. **15:03 Christian Folini:** And with, like, with a lot of development product projects, this is not about only the code. It is about people coming in and testing stuff. Yeah, and people writing blog posts about this. Look, this actually works, or this is our story with it, or giving us feedback, because we're all blind in a sense that this works for us. Where could be the problem? And then people suddenly look on my server, my service doesn't work at all. We need this feedback and we live on that. **15:30 Chris Romeo:** So anything else that you see coming out of the forum or the summit here that's going to be— we talked about more input, faster feedback loops, this new abstraction layer, which I'm pretty pumped about that. Any other big things you see coming out of the forum? **15:51 Christian Folini:** These are the big ones, and then we got people to talk to one another. **15:55 Chris Romeo:** Okay. **15:56 Christian Folini:** And that is very creative. So there was a guy from Uruguay, Rodrigo Martinez, and he was talking about machine learning and mod_security, and we were going, oh, that's impossible to do. And he proposed a talk, and then he presented it yesterday and said, no, actually there is a base. You can actually do machine learning with mod_security, even if it looks a bit limited in the rule language. And you don't need cloud-enabled artificial intelligence, super commercial, very, very expensive product to do this. You can get inroads and can get quite far with mod security with existing open-source technology. **16:31 Chris Romeo:** Hmm, okay. **16:31 Christian Folini:** So that was good fun. **16:32 Chris Romeo:** Yeah, so he's gonna pursue that and go deeper on that? **16:34 Christian Folini:** I think he's going to pursue that, and he raised a lot of interest and people flocking around his presentation. We did a poster session where we had people presented a poster like for 5 minutes, and then people regrouped and rotated throughout the room to get people to talk to one another, move them around. And talking about security Chris for 4 hours can be really boring. **16:55** Okay. **16:56 Christian Folini:** And that was changing the pace a bit and, and got people much more involved. And I saw that people were really interested because it was so surprising that he could present results of his research. **17:09 Chris Romeo:** Yeah, no, that's, that's, yeah, that sounds actually very interesting, and hopefully he'll take that further, and we'll see that in an upcoming AppSec EU or USA conference where he actually makes a big, uh, big deal. **17:19 Christian Folini:** That would be welcome. Yeah, cool. **17:21 Chris Romeo:** So let's, uh, I got one more question for you because, and it's, I'm going to completely switch gears, still focused on mod security and CRS, but I'm curious as to your take on the industry appears to be flocking to more of an IAST and RASP kind of a solution. So interactive application security testing and then runtime application self-protection. **17:45 Christian Folini:** Yes. **17:46 Chris Romeo:** Where do you see mod_security and CRS fitting into where it seems like we're going into the future? Do you see this project being a RASP and becoming something that's, that's Is it going to stay in the WAF kind of perspective, or big picture, where do you see this going? **18:07 Christian Folini:** I think it needs to integrate with agile development, absolutely. And this works. We had a poster yesterday presenting the idea to put it into continuous integration pipeline, right into it. So developers, when they do a pull request, they get immediate feedback if there's going to provoke false positives. By the WAF that's going to be used on the production like in half an hour. Well, a problem we're seeing right now is developers after a continuous integration pipeline, they're completely agile, they push it out and then it breaks. So we need to get closer to the developers and the toolset is all there, the toolchain is there, it's open source, you can very easily integrate it into your process in your company, how you do how you do software. **18:54 Chris Romeo:** Okay. **18:54 Christian Folini:** And with all the containerization, for us it's a lot easier to get into these pipelines than with the big commercial products because they, they've built fences around their products. They've built hardware appliances and stuff like that, and now they're struggling to catch up, while as we're software, we're completely dynamic and you can put us in any environment that you wish to. **19:19 Chris Romeo:** for. **19:19 Christian Folini:** And this is being done actively. **19:21 Chris Romeo:** Okay, yeah, and that's, that's an encouraging poster, kind of the story that you had there about that where they took that and put it into continuous integration and ran it through the test to figure it out, because that's one of the biggest gotchas for this type of technology is everything looks good in development, we rolled into production and everything broke. What do we do? We had to roll everything back. **19:42 Christian Folini:** Yeah, yeah. **19:42 Chris Romeo:** And then we had to go and and figure out how we turn down the WAF to make it go away. Certainly, yeah, certainly seems like a good perspective. Now, could you take this, could you take the core rule set technology and integrate it? Could it run inside of the Java Virtual Machine? **20:03 Christian Folini:** Oh, absolutely, yeah. We talked about this meta-abstraction language, and then we do, we compile Java code out of it, there will be— once we have that compiling Java code out of it, will be completely feasible. **20:17 Chris Romeo:** So the abstraction layer would open the door for the core rule set to become an IAST testing kind of suite or even a RASP protection solution? **20:29 Christian Folini:** Yeah, and integrate it wherever you want to, where you validate input. you can now add this library on top. **20:38** Okay. **20:39 Christian Folini:** That's the goal. **20:40 Chris Romeo:** And I guess you would just have— I mean, in Core Ruleset's perspective, ModSecurity provides you with the accept and reject, you know, the logical structures that, you know, Core Ruleset is fed into ModSecurity, and then ModSecurity reads the rules and then decides, do I either let this go through or do I drop it on the floor? **20:59 Christian Folini:** Actually, we tell ModSecurity. **21:01 Chris Romeo:** Okay, you tell about security. **21:02 Christian Folini:** And that is leading away now, it's getting very technical. But the decision if this is good or bad and the decision to block it, these are 2 different definitions. First, you have the rule that says, look, this smells like SQL injection. And then you make a decision, yes, and now we're going to block it. But that's 2 distinct things. And I think they want to have the meta language just work on the first one. **21:32 Chris Romeo:** Okay. **21:33 Christian Folini:** And just do indicators. Look, I've seen the following, and then in your code to make the decision. This will allow you to say, look, this smells like a PHP injection, but I don't care because I'm doing C# here. **21:49 Chris Romeo:** Okay. **21:53 Christian Folini:** You get— the decision gets closer to the code. **21:55 Chris Romeo:** Yep. **21:55 Christian Folini:** Right now in the Coralset, this is baked together because it's all about security, and we're agnostic of the backend because that's how it usually works. If you're content delivery networks, you have no idea what programming language the backend is running. But if you do this as input validation, you're completely in the know what is your weakness, what is your threat model, and we're not even doing SQL. heroes. So why would you care about this? **22:21 Chris Romeo:** Yeah, it almost seems to me like mod_security core rule set and mod_security start to decouple more and more in the future, and core rule set could actually feed another project that acts as a RASP in Java or a RASP in .NET or C#.NET. It starts to see like core rule set kind of starts to rise above all the other things that consume it in the lower levels. **22:48 Christian Folini:** That is a perspective, yeah. **22:49 Chris Romeo:** So that's kind of where you're— is that your kind of strategy or where you think the project's going? **22:56 Christian Folini:** Yeah, there is a strategy behind it, that's true, but it's also natural development because we see people, yeah, I'd like to use your stuff, but I'm not using mod_security. And this is a continuous question, and it's not as simple as we have an Apache web server anymore. That's not the world anymore. So people have Nginx and Apache, and some clouds are running IIS, and we're addressing these, but all the other stuff, all these fancy new servers, we're not working on them so far. And we want to push our rules on these technologies as well. **23:34** Yeah. **23:34 Christian Folini:** Because the world is much more diverse now. The internet is dynamic, diverse, many more choices, and there are little alternatives that are as generic as the core ruleset that can apply to all sorts of inputs. **23:50 Chris Romeo:** Yeah, so where would you recommend our listeners go for more information here about mod_security core ruleset, everything else? Where's, where's the best place to go? **24:01 Christian Folini:** The best place to go is to core-ruleset.org. Website of the project. There you have the basic introduction, tutorials, how to get this running, how to integrate it very quickly. There you also have the blog posts about the project to get a feeling what we're actually doing, and from there you can link over to GitHub where you report your false positives, where we help you to weed them out and stuff like that. So it's a project website, it's the most active one. modsecurity.org is important for the engine, but it's less focused on the rules. It's more about the engine. **24:38** Okay. **24:39 Chris Romeo:** All right. Well, Christian, thank you for taking the time today. This was great to get this. I know I learned a lot about core ruleset and things I didn't even realize it could do. So this has been very helpful. And so thanks for taking the time. **24:50 Christian Folini:** Thank you, Chris. It was my pleasure. **24:53** Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/christian-folini-crs-and-an-abstraction-layer/