Friday, April 8, 2011

Qualys Open Source WAF project "IronBee"

IronBee is a new open source project to build a universal web application security sensor.

Qualys is announcing the development of IronBee, a new open source project to build a universal web application security sensor. Our desire is not only to build the code and the rules, but also to focus on building a community around the project. In fact, we believe that building the community is the most important aspect of the project and the only way to ensure that it has a long life

IronBee has been in development for several months now. Qualys have completed the initial design phase and the prototype implementation, and we have the development and collaboration infrastructure ready. Now that we have a meaningful starting point, Qualys is inviting others to join us. At this time, they are looking for early adopters and those who wish to participate in shaping the project:

  • Developers to work on the IronBee core and on the security modules.
  • Application defenders to tell us what they need and to provide feedback on our proposed solutions (e.g., configuration language, signature language)Application security researchers to exchange attack information, write signatures and rules, and design new detection and protection techniques.
  • Web server and proxy developers to help us make IronBee work in their environments
  • Distribution maintainers to package IronBee to run on their systems
  • Infrastructure and cloud providers to help make IronBee effective for embedding into their infrastructures. 

More Details can be found here.