[Owasp-waf] Egress filtering with ESAPI WAF

Guruvayurappan R guruvayurappan.r at tcs.com
Mon Jun 24 16:43:19 UTC 2013


Folks,

I am trying to implement WAF for achieving egress filtering. During then, 
I found that temp files are getting created. I would like to know more on 
why these are being created. 

- Why is there a need to create temporary files for each output response 
and if there is a way to turn it OFF? I saw someone had reported in a blog 
that he had issue with files not getting closed in some flows and thereby 
causing too many open file descriptors.
- During testing, I found that the files created are of just 0 bytes in 
size. But, still wouldn't it be an issue, if used in large applications, 
where thousands of requests per second is possible.
- Are there any performance benchmarks available with the Egress filtering 
implementation of ESAPI WAF? I would like to know if there are any 
performance concerns with any specific egress filtering rules this WAF is 
implementing.

Appreciate your responses much! Thanks.

Regards
Guru
=====-----=====-----=====
Notice: The information contained in this e-mail
message and/or attachments to it may contain 
confidential or privileged information. If you are 
not the intended recipient, any dissemination, use, 
review, distribution, printing or copying of the 
information contained in this e-mail message 
and/or attachments to it are strictly prohibited. If 
you have received this communication in error, 
please notify us by reply e-mail or telephone and 
immediately and permanently delete the message 
and any attachments. Thank you


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.owasp.org/pipermail/owasp-waf/attachments/20130624/fec5696c/attachment.html>


More information about the Owasp-waf mailing list