WAFY
HomeReferences › A Global Payments Gateway

A Global Payments Gateway

Part of the F5 Advanced WAF experience behind WAFY, described by business type rather than by name.

Reference

What the work involved.

F5 ASM experience securing a global payments gateway across worldwide sites: full OWASP web and API coverage, DDoS, brute-force and session-theft protection, kept in sync via F5 GTM.

WAFY's F5 ASM experience includes a global payments gateway, a fast-growing startup for whom demonstrable security was a launch-critical selling point. As with several of these engagements there was little internal knowledge to draw on, so the policies were built from the ground up: full attack signatures and fully OWASP-compliant enforcement, delivered through change management. Because it was a payment gateway, a large part of the work was API security to the OWASP API Top 10, alongside the OWASP web Top 10, with heavy emphasis on session-theft protection through cookie protection and JWT handling. The estate spanned multiple sites across the globe, load-balanced with F5 GTM, and the ASM policies had to stay identical everywhere, kept in step across all sites through a custom sync group. Protection also covered brute-force and anonymity and web-scraping detection, and a significant DDoS element.

F5 scope
  • Full attack signatures and fully OWASP-compliant policies, built from the ground up through change management
  • OWASP API Top 10 coverage for the payment-gateway APIs, alongside the web Top 10
  • Session-theft protection: cookie protection and JWT handling
  • Brute-force and anonymity / web-scraping detection, plus a significant DDoS element
  • Multi-site global estate load-balanced with F5 GTM, policies kept in sync across all sites via a custom sync group