NetScaler Web App Firewall (WAF) protects your web applications from malicious attacks such as SQL injection and cross-site scripting. To prevent data breaches and provide the right security protection, you must monitor your traffic for threats and real-time actionable data on attacks. Sometimes, the attacks reported might be false-positive and those need to be provided as an exception.
The Learning engine on NetScaler Console is a repetitive pattern filter that enables WAF to learn the behavior (the normal activities) of your web applications. Based on monitoring, the engine generates a list of suggested rules or exceptions for each security check applied on the HTTP traffic.
It is much easier to deploy relaxation rules using the Learning engine than manually deploy it as necessary relaxations.
The following image explains the high-level information on how the WAF learning in NetScaler Console works:
1 – NetScaler instances with its WAF profiles
2 – Configure a learning profile in NetScaler Console, add the WAF profiles, and select to auto deploy or manually deploy the relaxation rules
3 – Administrator can validate the relaxation rules in NetScaler Console and decide to deploy or skip