Web App Scanning: F5 Distributed Cloud
Key Concepts:
- Web App Scanning
- Inventory Discovery (Recon Module)
- Vulnerability Scanning (Scan Module)
- Application Portfolio Security
- API Discovery
- Security Score
- OWASP Top 10
- SAS-based deployment
- On-premises deployment
Challenges Addressed
Web App Scanning addresses two primary challenges:
- Difficulty in Establishing an Inventory of Exposed Assets: Many organizations struggle to identify all their applications and APIs exposed to the internet.
- Logistic Burden of Securing Large-Scale Application Portfolios: Manually securing a large number of applications, especially those requiring authentication, is resource-intensive and often infeasible.
Inventory Discovery (Recon Module)
- Purpose: Creates accurate and complete application and API inventories in an automated fashion.
- Functionality:
- Requires only a domain name to start.
- Discovers network address blocks, servers, and services associated with the domain.
- Identifies potential issues like dangling CNAME records.
- Process:
- Add a domain to the Recon module.
- Specify automatic domain discovery (optional).
- Optionally disable automated service scanning for manual selection.
- Review the discovered inventory, grouped by network address block, server software, and service.
- Export the inventory for further analysis.
- Export identified issues (e.g., dangling CNAME records).
Vulnerability Scanning (Scan Module)
- Purpose: Discovers vulnerabilities in applications and APIs.
- Functionality:
- Automated process suitable for large-scale portfolios.
- Can be scheduled for recurrent testing.
- Performs service-specific vulnerability scans.
- Performs API discovery.
- Process:
- Select a service from the inventory discovered by the Recon module.
- Create a new scan for the selected service.
- The Scan module automatically creates an application entry.
- Monitor the scan status in the Scan module dashboard.
- Review the scan results, including:
- Overall security score.
- Found issues grouped by severity (tabular and graphical format).
- Test report.
Interface and Reporting
- Dashboard: Displays a list of domains and discovered assets (network address blocks, servers, services).
- Issues Details: Provides information on each vulnerability, including:
- Mapping.
- Status.
- Detailed description.
- Explanation provided by a generative AI assistant, including context and recommended mitigation.
- API Endpoints: Displays discovered API endpoints, including request/response pairs and number of occurrences.
- Scan Report:
- Maps vulnerabilities to the OWASP Top 10.
- Includes a video recording of the actions taken by the Scan module (useful for audit purposes).
- Generates customizable PDF reports for presenting test results.
Deployment Model
- SAS-based: The default deployment model.
- On-premises: Can be installed on-premises for security or regulatory compliance reasons.
Conclusion
Web App Scanning in F5's Distributed Cloud offers a comprehensive solution for discovering and securing web applications and APIs. By automating inventory discovery and vulnerability scanning, it addresses the challenges of managing large-scale application portfolios. The platform provides detailed reports, AI-powered explanations, and flexible deployment options, making it a valuable tool for organizations seeking to improve their web application security posture.
AI summaries can miss context or contain errors. Check important details against the original video.





