{"id":8344,"date":"2020-12-28T09:12:15","date_gmt":"2020-12-28T09:12:15","guid":{"rendered":"https:\/\/hosteko.com\/blog\/?p=8344"},"modified":"2020-12-28T09:12:15","modified_gmt":"2020-12-28T09:12:15","slug":"mengenal-web-application-firewall","status":"publish","type":"post","link":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall","title":{"rendered":"Mengenal Web Application Firewall"},"content":{"rendered":"<h1><strong>Pengertian WAF<\/strong><\/h1>\n<p><strong>WAF (Web Application Firewall)<\/strong> adalah sebuah susunan filter yang berfungsi untuk menyaring, memonitor dan melakukan blocking terhadap data yang berasal dari client ke sebuah webserver. Web Application Firewall menganalisa lalu lintas HTTP untuk memutuskan apakah traffic yang masuk valid dan berupaya untuk mencegah serangan web seperti serangan DDoS, cross-site scripting (XSS) dan SQL Injection. Biasanya sering di anggap sebagai reverse proxy.<\/p>\n<p>Web Application Firewall difokuskan pada layer ke-7; Application layer dari OSI Model. Access Control diimplementasikan dengan menggunakan Access Control Lists sebagai rules untuk mengizinkan atau menolak traffic. WAF bisa datang dalam bentuk alat, server plugin, atau filter, dan mungkin disesuaikan dengan aplikasi. Upaya untuk melakukan kustomasi ini dapat menjadi signifikan dan perlu dijaga karena aplikasi tersebut di modifikasi.<\/p>\n<p>Meskipun nama untuk mode operasi ini mungkin berbeda, WAF pada dasarnya digunakan secara inline dalam tiga cara yang berbeda. Menurut NSS Labs, opsi penggunaan seperti transparent bridge, transparent reverse proxy, dan reverse proxy.<\/p>\n<p>&#8220;Transparent&#8221; mengacu pada fakta bahwa traffice HTTP dikirim langsung ke aplikasi web, oleh karena itu WAF transparan antara klien dan server. Hal ini berbeda dengan reverse proxy, dimana WAF bertindak sebagai proxy dan traffic klien dikirim langsung ke WAF. WAF kemudian secara terpisah mengirimkan traffic yang telah disaring ke aplikasi web. Hal ini bisa memberikan manfaat tambahan seperti masking IP namun juga bisa membawa kelemahan seperti latensi kinerja.<\/p>\n<h1><strong><span id=\"History\" class=\"mw-headline\">Sejarah WAF<\/span><\/strong><\/h1>\n<p><span>Firewall aplikasi web khusus memasuki pasar pada akhir 1990-an pada saat serangan server web <\/span><span>menjadi lebih umum.<\/span><\/p>\n<p><span>Versi awal WAF dikembangkan oleh Perfecto Technologies dengan produk AppShield yang berfokus<\/span><span>\u00a0pada pasar e-niaga dan dilindungi dari entri karakter halaman web ilegal.\u00a0Pada tahun 2002, proyek open source ModSecurity<\/span><span>\u00a0dibentuk untuk membuat teknologi WAF lebih mudah diakses.\u00a0Mereka menyelesaikan aturan inti yang ditetapkan untuk melindungi aplikasi web, berdasarkan pekerjaan kerentanan Komite Teknis Keamanan Aplikasi Web (WAS TC) OASIS.\u00a0Pada tahun 2003, mereka memperluas dan menstandarkan aturan melalui Proyek Keamanan Aplikasi Web Terbuka <\/span><span>Daftar 10 Teratas (OWASP), peringkat tahunan untuk kerentanan keamanan web.\u00a0Daftar ini akan menjadi standar industri untuk kepatuhan keamanan aplikasi web.<\/span><sup id=\"cite_ref-5\" class=\"reference\"><\/sup><\/p>\n<p><span>Sejak saat itu, pasar terus tumbuh dan berkembang, terutama berfokus pada\u00a0pencegahan penipuan kartu kredit. <\/span><span>Dengan pengembangan Standar Keamanan Data Industri Kartu Pembayaran <\/span><span>(PCI DSS), sebuah standarisasi kontrol atas data pemegang kartu, keamanan menjadi lebih diatur di sektor ini.\u00a0Menurut Majalah CISO, pasar WAF diharapkan tumbuh menjadi $ 5,48 miliar pada tahun 2022.<\/span><\/p>\n<h1><strong>Vendor WAF Commercial<\/strong><\/h1>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8356 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/How-do-we-keep-up_.png\" alt=\"\" width=\"1920\" height=\"1080\" srcset=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/How-do-we-keep-up_.png 1920w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/How-do-we-keep-up_-1024x576.png 1024w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/How-do-we-keep-up_-768x432.png 768w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/How-do-we-keep-up_-1536x864.png 1536w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/How-do-we-keep-up_-640x360.png 640w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/How-do-we-keep-up_-400x225.png 400w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/p>\n<p>Banyak penyedia WAF komersil yang menawarkan fitur-fitur yang hampir sama, tetapi memiliki perbedaan dasar seperti user interface, deployment option, atau kebutuhan didalam lingkungan yang spesifik.<\/p>\n<ul>\n<li>\n<h3><strong>Appliance<\/strong><\/h3>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Radware \u2013 AppWall<\/li>\n<li>Monitorapp AIWAF<\/li>\n<li>Barracuda Networks WAF<\/li>\n<li>Citrix Netscaler Application Firewall<\/li>\n<li>F5 Big-IP Application Security Manager<\/li>\n<li>Penta Security WAPPLES<\/li>\n<li>Imperva SecureSphere<\/li>\n<li>Fortinet FortiWeb<\/li>\n<li>Positive Technologies, PT Application Firewall<\/li>\n<\/ul>\n<\/li>\n<li>\n<h3><strong>Cloud<\/strong><\/h3>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Akamai Technologies Kona<\/li>\n<li>Alibaba Cloud<\/li>\n<li>Amazon Web Services AWS WAF<\/li>\n<li>Barracuda Networks CloudGen WAF and WAF-as-a-Service<\/li>\n<li>CDNetworks<\/li>\n<li>Cloudbric<\/li>\n<li>Cloudflare<\/li>\n<li>Fortinet FortiWeb<\/li>\n<li>F5 Silverline<\/li>\n<li>Fastly<\/li>\n<li>IBM Cloud Internet Services WAF<\/li>\n<li>Imperva Incapsula<\/li>\n<li>Microsoft Azure Application Gateway with WAF<\/li>\n<li>Oracle Cloud Infrastructure WAF<\/li>\n<li>Qualys WAF<\/li>\n<li>Radware<\/li>\n<li>Rohde &amp; Schwarz Cybersecurity WAF<\/li>\n<li>Sucuri Firewall<\/li>\n<li>VMware NSX Advanced Load Balancer (formerly Avi Vantage)<\/li>\n<\/ul>\n<\/li>\n<li>\n<h3><strong>Pilihan Open Source<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Solusi open source tersedia bagi publik untuk penggunaan umum.<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>ModSecurity<\/li>\n<li>NAXSI<\/li>\n<li>OctupusWAF<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h1 class=\"header-post-title-class entry-title\"><span style=\"color: #000000;\"><strong>Konfigurasi Dasar WAF<\/strong><\/span><\/h1>\n<p>Konfigurasi awal untuk ModSecurity yang berfungsi sebagai WAF ini adalah :<\/p>\n<ul>\n<li>\n<h3><strong>SecRuleEngine<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Setting pada SecRuleEngine ini akan menentukan apakah rule engine akan On, atau Off atau DetecionOnly.<\/p>\n<ul>\n<li>\n<h3><strong>SecDefaultAction<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Pada SecDefaultAction ini biasanya 403 (Forbidden). Pada ModSecurity\u00a0 memiliki lima fase dalam memproses permintaan.<br \/>\nLama fase dalam pemrosesan permintaan pada ModSecurity ini adalah :<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Setelah Apache membaca header dari HTTP request.<\/li>\n<li>Setelah membaca request body.<\/li>\n<li>Sebelum response header dikirim ke client.<\/li>\n<li>Sebelum response body dikirim ke client.<\/li>\n<li>Sebelum proses logging.<\/li>\n<\/ul>\n<\/li>\n<li>\n<h3><strong>SecRequestBodyAccess<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Dengan di setting On maka akan memproses HTTP request bodies.<\/p>\n<ul>\n<li>\n<h3><strong>SecDebugLog<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Pada setting SecDebugLog akan memberikan setting file log untuk debug.<\/p>\n<ul>\n<li>\n<h3><strong>SecDebugLogLevel<\/strong><\/h3>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Pada SecDebugLogLevel ini akan menentukan tingkatan dalam merekam ke file log.<\/p>\n<h1><strong>Alasan Membutuhkan Aturan ModSecurity<\/strong><\/h1>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8358 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Alasan-Membutuhkan-Aturan-ModSecurity.png\" alt=\"\" width=\"1920\" height=\"1080\" srcset=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Alasan-Membutuhkan-Aturan-ModSecurity.png 1920w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Alasan-Membutuhkan-Aturan-ModSecurity-1024x576.png 1024w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Alasan-Membutuhkan-Aturan-ModSecurity-768x432.png 768w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Alasan-Membutuhkan-Aturan-ModSecurity-1536x864.png 1536w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Alasan-Membutuhkan-Aturan-ModSecurity-640x360.png 640w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Alasan-Membutuhkan-Aturan-ModSecurity-400x225.png 400w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><\/p>\n<p>Berikut ini beberapa alasan membutuhkan aturan ModSecurity, yaitu :<\/p>\n<h3 class=\"rules-title\"><strong>1. Laboraturium antivirus comodo<\/strong><\/h3>\n<p><span>Satu-satunya\u00a0aturan\u00a0<\/span><strong><span>ModSecurity gratis<\/span><\/strong><span>\u00a0yang berasal dari perusahaan dengan\u00a0lab antivirus<\/span><span> terkenal secara internasional.\u00a0Melihat ancaman di setiap level di seluruh dunia dan berdedikasi untuk mengubah pengetahuan itu menjadi solusi keamanan.<\/span><\/p>\n<h3><strong>2. Kategorisasi aturan\u00a0<\/strong><\/h3>\n<p><span>Satu-satunya\u00a0aturan\u00a0<strong><i>ModSecurity<\/i><\/strong><\/span><strong><span>\u00a0gratis<\/span><i><\/i><\/strong><span>\u00a0yang memungkinkan kategorisasi aturan, menggunakan teknologi yang menunggu paten.\u00a0Hanya menjalankan aturan yang diperlukan, daripada membuang-buang siklus CPU yang berharga untuk mencari aturan yang tidak perlu.<\/span><\/p>\n<h3><strong>3. Kinerja yang unggul<\/strong><\/h3>\n<p>Untuk keamanan asalkan mendapatkan kinerja sistem terbaik dari pemasok aturan pihak ketiga, termasuk dari mereka yang membebankan biaya berlangganan yang besar.<\/p>\n<h3><strong>4. Dukungan teknis gratis<\/strong><\/h3>\n<p>Insinyur dan pakar keamanan Comodo siap membantu sekitar 24\/7 di seluruh dunia.<\/p>\n<h3><strong>5. Diperbaharui dengan kecepatan kilat<\/strong><\/h3>\n<p>Pembaruan aturan cepat, sering dan mudah dikelola.<\/p>\n<h3><strong>6. Inovasi tanpa henti<\/strong><\/h3>\n<p>Comodo berdedikasi untuk terus meningkatkan dan meningkatkan keamanan.<\/p>\n<h1 class=\"header-post-title-class entry-title\"><span style=\"color: #000000;\"><strong>Penerapan SecRule pada WAF<\/strong><\/span><\/h1>\n<p>Berikut ini merupakan penerapan SecRule pada WAF, yaitu :<\/p>\n<ul>\n<li>Misalkan memiliki sebuah file rahasia.html.<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8348 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/file-rahasia-html.png\" alt=\"\" width=\"439\" height=\"91\" srcset=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/file-rahasia-html.png 439w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/file-rahasia-html-400x83.png 400w\" sizes=\"auto, (max-width: 439px) 100vw, 439px\" \/><\/p>\n<ul>\n<li>Kemudian akan membuat rule yang menghalangi akses untuk file yang mengandung kata rahasia. Maka akan mengedit pada modsecurity.conf seperti di bawah ini :<\/li>\n<\/ul>\n<div class=\"line number1 index0 alt2\" style=\"padding-left: 40px;\"><code class=\"php plain\">SecRuleEngine On<\/code><\/div>\n<div class=\"line number2 index1 alt1\" style=\"padding-left: 40px;\"><code class=\"php plain\">SecDefaultAction <\/code><code class=\"php string\">\"phase:2,deny,log,status:403\"<\/code><\/div>\n<div class=\"line number3 index2 alt2\" style=\"padding-left: 40px;\"><\/div>\n<div class=\"line number4 index3 alt1\" style=\"padding-left: 40px;\"><code class=\"php plain\"># Block all requests that have the string <\/code><code class=\"php string\">\"rahasia\"<\/code> <code class=\"php plain\">in the URI<\/code><\/div>\n<div class=\"line number5 index4 alt2\" style=\"padding-left: 40px;\"><code class=\"php plain\">SecRule REQUEST_URI <\/code><code class=\"php string\">\"rahasia\"<\/code><\/div>\n<ul>\n<li>Hasilnya adalah seperti gambar berikut ini :<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8349 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/apply.png\" alt=\"\" width=\"545\" height=\"160\" srcset=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/apply.png 545w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/apply-400x117.png 400w\" sizes=\"auto, (max-width: 545px) 100vw, 545px\" \/><\/p>\n<h1><strong>Cara Install Rule Set Pada WAF Comodo<\/strong><\/h1>\n<p>Aturan perlindungan Comodo ModSecurity sekarang terintegrasi dalam cPanel dan dapat diaktifkan dari &#8220;Pusat Keamanan&#8221;.<\/p>\n<ul>\n<li>Masuk ke akun cPanel.<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8350 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel_login.png\" alt=\"\" width=\"347\" height=\"321\" \/><\/p>\n<p style=\"padding-left: 40px;\"><b>Catatan Penting :<\/b> Vendor ModSecurity cPanel tidak kompatibel dengan plugin CWAF. Jadi tidak dapat menggunakan keduanya secara paralel untuk pengelolaan aturan perlindungan.<\/p>\n<p style=\"padding-left: 40px;\">Jangan aktifkan kedua Set Aturan Comodo untuk Apache dan LiteSpeed \u200b\u200bsecara bersamaan untuk menghindari konflik.<\/p>\n<ul>\n<li>Klik tab &#8220;<strong>Security Center<\/strong>&#8221; dari menu sebelah kiri, lalu &#8220;<strong>ModSecurity Vendors<\/strong>&#8220;.<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8351 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel1_sec_center.png\" alt=\"\" width=\"700\" height=\"360\" srcset=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel1_sec_center.png 700w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel1_sec_center-640x329.png 640w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel1_sec_center-400x206.png 400w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel1_sec_center-450x231.png 450w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/p>\n<ul>\n<li>Klik &#8220;<strong>Tambah Vendor<\/strong>&#8221; di layar &#8220;<strong>ModSecurity Vendor Manager<\/strong>&#8220;.<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8352 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_add_vendor.png\" alt=\"\" width=\"700\" height=\"259\" srcset=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_add_vendor.png 700w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_add_vendor-640x237.png 640w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_add_vendor-400x148.png 400w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/p>\n<p style=\"padding-left: 40px;\">Di halaman &#8220;<strong>Tambahkan Vendor<\/strong>&#8220;, masukkan URL konfigurasi vendor tergantung pada jenis server web.<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><span>Untuk Comodo ModSecurity Apache Rule Set <\/span><a href=\"https:\/\/waf.comodo.com\/doc\/meta_comodo_apache.yaml\"><span>https:\/\/waf.comodo.com\/doc\/meta_comodo_apache.yaml<\/span><\/a><\/li>\n<li><span>Untuk Comodo ModSecurity LiteSpeed \u200b\u200bRule Set <\/span><a href=\"https:\/\/waf.comodo.com\/doc\/meta_comodo_litespeed.yaml\"><span>https:\/\/waf.comodo.com\/doc\/meta_comodo_litespeed.yaml<\/span><\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8353 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel3_vendor_url.png\" alt=\"\" width=\"380\" height=\"596\" \/><\/p>\n<ul>\n<li>Masukkan URL yang sesuai di bidang &#8220;<strong>Vendor Configuration URL<\/strong>&#8221; dan klik &#8220;<strong>Muat<\/strong>&#8220;.<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\">Detail vendor akan diambil dan diisi secara otomatis di bidang.<\/p>\n<ul>\n<li>Klik tombol &#8220;<strong>Simpan<\/strong>&#8220;.<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-8354 aligncenter\" src=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_vendor_added.png\" alt=\"\" width=\"700\" height=\"313\" srcset=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_vendor_added.png 700w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_vendor_added-640x286.png 640w, https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/cpanel2_vendor_added-400x179.png 400w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/p>\n\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom\"\n    data-payload='{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;8344&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;2&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;0&quot;,&quot;greet&quot;:&quot;Jadilah yang pertama untuk memberi nilai&quot;,&quot;legend&quot;:&quot;5\\\/5 - (2 votes)&quot;,&quot;size&quot;:&quot;22&quot;,&quot;title&quot;:&quot;Mengenal Web Application Firewall&quot;,&quot;width&quot;:&quot;110&quot;,&quot;_legend&quot;:&quot;{score}\\\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 110px;\">\n            <div class=\"kksr-star\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 0px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 22px; height: 22px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 17.6px;\">\n            5\/5 - (2 votes)    <\/div>\n    <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Pengertian WAF WAF (Web Application Firewall) adalah sebuah susunan filter yang berfungsi untuk menyaring, memonitor dan melakukan blocking terhadap data yang berasal dari client ke sebuah webserver. Web Application Firewall menganalisa lalu lintas HTTP untuk memutuskan apakah traffic yang masuk valid dan berupaya untuk mencegah serangan web seperti serangan DDoS, cross-site scripting (XSS) dan SQL [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":8357,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":{"twitter_2392824914_2392824914":""},"rop_publish_now_history":[],"rop_publish_now_status":"pending","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"enabled":false},"version":2}},"categories":[3],"tags":[2649,2651,2648,2650,2645,2646,2647],"class_list":["post-8344","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-alasan-membutuhkan-aturan-modsecurity","tag-cara-install-rule-set-pada-web-application-firewall-comodo","tag-konfigurasi-dasar-web-application-firewall","tag-penerapan-secrule-pada-web-application-firewall","tag-pengertian-web-application-firewall","tag-sejarah-web-application-firewall","tag-vendor-web-application-firewall-commercial"],"featured_image_src":{"landsacpe":["https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall-1140x445.gif",1140,445,true],"list":["https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall-463x348.gif",463,348,true],"medium":["https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif",300,169,false],"full":["https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif",1440,810,false]},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Mengenal Web Application Firewall - Hosteko Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mengenal Web Application Firewall - Hosteko Blog\" \/>\n<meta property=\"og:description\" content=\"Pengertian WAF WAF (Web Application Firewall) adalah sebuah susunan filter yang berfungsi untuk menyaring, memonitor dan melakukan blocking terhadap data yang berasal dari client ke sebuah webserver. Web Application Firewall menganalisa lalu lintas HTTP untuk memutuskan apakah traffic yang masuk valid dan berupaya untuk mencegah serangan web seperti serangan DDoS, cross-site scripting (XSS) dan SQL [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall\" \/>\n<meta property=\"og:site_name\" content=\"Hosteko Blog\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-28T09:12:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif\" \/>\n\t<meta property=\"og:image:width\" content=\"1440\" \/>\n\t<meta property=\"og:image:height\" content=\"810\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/gif\" \/>\n<meta name=\"author\" content=\"Risa Y\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Risa Y\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#article\",\"isPartOf\":{\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall\"},\"author\":{\"name\":\"Risa Y\",\"@id\":\"https:\/\/hosteko.com\/blog\/#\/schema\/person\/c1d3dbd7c27bd3574f8c7042165a660b\"},\"headline\":\"Mengenal Web Application Firewall\",\"datePublished\":\"2020-12-28T09:12:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall\"},\"wordCount\":963,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/hosteko.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage\"},\"thumbnailUrl\":\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif\",\"keywords\":[\"alasan membutuhkan aturan modsecurity\",\"cara install rule set pada web application firewall comodo\",\"konfigurasi dasar web application firewall\",\"penerapan secrule pada web application firewall\",\"pengertian Web Application Firewall\",\"sejarah web application firewall\",\"vendor web application firewall commercial\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall\",\"url\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall\",\"name\":\"Mengenal Web Application Firewall - Hosteko Blog\",\"isPartOf\":{\"@id\":\"https:\/\/hosteko.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage\"},\"image\":{\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage\"},\"thumbnailUrl\":\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif\",\"datePublished\":\"2020-12-28T09:12:15+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage\",\"url\":\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif\",\"contentUrl\":\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif\",\"width\":1440,\"height\":810},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/hosteko.com\/blog\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mengenal Web Application Firewall\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/hosteko.com\/blog\/#website\",\"url\":\"https:\/\/hosteko.com\/blog\/\",\"name\":\"Hosteko Blog\",\"description\":\"Berita &amp; Informasi Dunia IT\",\"publisher\":{\"@id\":\"https:\/\/hosteko.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/hosteko.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/hosteko.com\/blog\/#organization\",\"name\":\"HOSTEKO\",\"url\":\"https:\/\/hosteko.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/hosteko.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2019\/04\/logo-hosteko.png\",\"contentUrl\":\"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2019\/04\/logo-hosteko.png\",\"width\":195,\"height\":57,\"caption\":\"HOSTEKO\"},\"image\":{\"@id\":\"https:\/\/hosteko.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/hosteko.com\/blog\/#\/schema\/person\/c1d3dbd7c27bd3574f8c7042165a660b\",\"name\":\"Risa Y\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/hosteko.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7eac241dffbc583c56ba1ff19703f5623dab2b6a88bbb0583e815230564dac5e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7eac241dffbc583c56ba1ff19703f5623dab2b6a88bbb0583e815230564dac5e?s=96&d=mm&r=g\",\"caption\":\"Risa Y\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mengenal Web Application Firewall - Hosteko Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall","og_locale":"en_US","og_type":"article","og_title":"Mengenal Web Application Firewall - Hosteko Blog","og_description":"Pengertian WAF WAF (Web Application Firewall) adalah sebuah susunan filter yang berfungsi untuk menyaring, memonitor dan melakukan blocking terhadap data yang berasal dari client ke sebuah webserver. Web Application Firewall menganalisa lalu lintas HTTP untuk memutuskan apakah traffic yang masuk valid dan berupaya untuk mencegah serangan web seperti serangan DDoS, cross-site scripting (XSS) dan SQL [&hellip;]","og_url":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall","og_site_name":"Hosteko Blog","article_published_time":"2020-12-28T09:12:15+00:00","og_image":[{"width":1440,"height":810,"url":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif","type":"image\/gif"}],"author":"Risa Y","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Risa Y","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#article","isPartOf":{"@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall"},"author":{"name":"Risa Y","@id":"https:\/\/hosteko.com\/blog\/#\/schema\/person\/c1d3dbd7c27bd3574f8c7042165a660b"},"headline":"Mengenal Web Application Firewall","datePublished":"2020-12-28T09:12:15+00:00","mainEntityOfPage":{"@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall"},"wordCount":963,"commentCount":0,"publisher":{"@id":"https:\/\/hosteko.com\/blog\/#organization"},"image":{"@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage"},"thumbnailUrl":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif","keywords":["alasan membutuhkan aturan modsecurity","cara install rule set pada web application firewall comodo","konfigurasi dasar web application firewall","penerapan secrule pada web application firewall","pengertian Web Application Firewall","sejarah web application firewall","vendor web application firewall commercial"],"articleSection":["Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#respond"]}]},{"@type":"WebPage","@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall","url":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall","name":"Mengenal Web Application Firewall - Hosteko Blog","isPartOf":{"@id":"https:\/\/hosteko.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage"},"image":{"@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage"},"thumbnailUrl":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif","datePublished":"2020-12-28T09:12:15+00:00","breadcrumb":{"@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#primaryimage","url":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif","contentUrl":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif","width":1440,"height":810},{"@type":"BreadcrumbList","@id":"https:\/\/hosteko.com\/blog\/mengenal-web-application-firewall#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/hosteko.com\/blog"},{"@type":"ListItem","position":2,"name":"Mengenal Web Application Firewall"}]},{"@type":"WebSite","@id":"https:\/\/hosteko.com\/blog\/#website","url":"https:\/\/hosteko.com\/blog\/","name":"Hosteko Blog","description":"Berita &amp; Informasi Dunia IT","publisher":{"@id":"https:\/\/hosteko.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/hosteko.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/hosteko.com\/blog\/#organization","name":"HOSTEKO","url":"https:\/\/hosteko.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hosteko.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2019\/04\/logo-hosteko.png","contentUrl":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2019\/04\/logo-hosteko.png","width":195,"height":57,"caption":"HOSTEKO"},"image":{"@id":"https:\/\/hosteko.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/hosteko.com\/blog\/#\/schema\/person\/c1d3dbd7c27bd3574f8c7042165a660b","name":"Risa Y","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hosteko.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7eac241dffbc583c56ba1ff19703f5623dab2b6a88bbb0583e815230564dac5e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7eac241dffbc583c56ba1ff19703f5623dab2b6a88bbb0583e815230564dac5e?s=96&d=mm&r=g","caption":"Risa Y"}}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/hosteko.com\/htk-blog\/wp-content\/uploads\/2020\/12\/Mengenal-Web-Application-Firewall.gif","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/posts\/8344","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/comments?post=8344"}],"version-history":[{"count":3,"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/posts\/8344\/revisions"}],"predecessor-version":[{"id":8359,"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/posts\/8344\/revisions\/8359"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/media\/8357"}],"wp:attachment":[{"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/media?parent=8344"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/categories?post=8344"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hosteko.com\/blog\/wp-json\/wp\/v2\/tags?post=8344"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}