Akamai Web Application Firewall
Akamai Web Application Firewall
2
AKAMAI WEB APPLICATION FIREWALL
SNYPR 6.2 Data Source Guide
Contact Information
Securonix, Inc.
14665 Midway Rd. Ste. 100, Addison, TX 75001
www.securonix.com
855.732.6649
Revision History
Page | 2
Copyright © 2018 Securonix, Inc.
SNYPR 6.2 Data Source Guide
Table of Contents
2
Akamai 4
What is Akamai? 4
Akamai Configuration 4
Configure Akamai in SNYPR 4
Supported Collection Methods 8
Functionality 8
Taxonomy 8
Device Event Field Mapping 8
Akamai Mappings to SNYPR Fields 8
References 9
Page | 3
Copyright © 2018 Securonix, Inc.
SNYPR 6.2 Data Source Guide
Akamai
Akamai
This data source guide will provide information on how to integrate Akamai and how the data source events
are parsed, normalized, and categorized to SNYPR fields. In particular, it provides the following:
l Device event field mapping
l Device event severity mapping
l Device event categorization
To download the Akamai parser from the Securonix Threat Library, search Available Resources Types for
Deployment by Vendor name or Functionality. Downloading the resource downloads the parser along with
the applicable policies and threat models.
What is Akamai?
Akamai web application firewall (WAF) provides protection against web application-layer attacks such as
SQL injection, malicious file execution, cross site scripting, etc. that can penetrate and cripple a website,
diminishing performance and exposing an enterprise to data breaches.
Akamai Configuration
Follow the steps below to configure Akamai in SNYPR.
Page | 4
Copyright © 2018 Securonix, Inc.
SNYPR 6.2 Data Source Guide
Akamai
2. Click + in the upper-left corner, then click Create Custom Device Type.
3. Configure the following values to match the fields required in your DEVICE TYPE INFORMATION
section:
a. Vendor: Akamai Technologies
b. Functionality: Firewall
c. Device Type: Akamai Web Application Firewall
d. Resource Type: Key Value Pair
e. Collection Method: Akamai
Page | 5
Copyright © 2018 Securonix, Inc.
SNYPR 6.2 Data Source Guide
Akamai
Page | 6
Copyright © 2018 Securonix, Inc.
SNYPR 6.2 Data Source Guide
Akamai
c. Client Secret
d. Access Token
e. Base URL
f. Config URL
g. Select Start Date/Time
Page | 7
Copyright © 2018 Securonix, Inc.
SNYPR 6.2 Data Source Guide
Akamai
Functionality
The functionality of Akamai is Firewall. See Use Cases by Functionality for a complete list of policies for this
functionality.
Taxonomy
Securonix Open Event Format (OEF) 1.0 is used. OEF is an event interoperability standard/schema. It
provides a set of standardized attributes (fields) for consistent representation of logging output from disparate
security and non-security devices and applications. For additional information, refer to the Data Dictionary
section on the Securonix documentation portal.
httpMessage.start DATETIME
type customstring1
attackData.rules transactionstring1
Page | 8
Copyright © 2018 Securonix, Inc.
SNYPR 6.2 Data Source Guide
Akamai
geo.country transactionstring2
httpMessage.protocol applicationprotocol
httpMessage.method requestmethod
httpMessage.host destinationhostname
httpMessage.port destinationport
httpMessage.status eventoutcome
httpMessage.bytes bytesout
Transaction transactionstring1
IPAddress ipaddress
attackData.clientIP deviceaddress
httpMessage.path filepath
httpMessage.query filetype
References
Akamai SIEM-CEF Connector: https://github.com/akamai/siem-cef-connector
Documentation on SIEM Integration: https://developer.akamai.com/tools/siem-integration/index.html
Collect Logs for Akamai Cloud Monitor: https://help.sumologic.com/Send-Data/Applications-and-Other-
Data-Sources/Akamai-Cloud-Monitor/01-Collect-Logs-for-Akamai-Cloud-Monitor-App
Wikipedia: https://en.wikipedia.org/wiki/Akamai_Technologies
Page | 9
Copyright © 2018 Securonix, Inc.