My main use case for Atomic ModSecurity Rules is in my research, which tries to make websites secure against web attacks like SQL injection and XSS attacks. On one side, I try to generate some obfuscated attacks that are able to bypass ModSecurity and the current CRS rules. On the other side, I try to update ModSecurity because it's an open-source WAF with new rules that are able to bypass the new generated obfuscated attacks.
What is our primary use case?
What is most valuable?
The best feature Atomic ModSecurity Rules offers is the open source aspect. I believe that because it's open source, all of the developers, programmers, and security experts are able to update this WAF and provide more rules, creating a more secure WAF for all of the clients and customers around the world.
By accessing Atomic ModSecurity Rules, it has helped me significantly. Because of this open source feature, I am able to generate new rules and update the WAF and use this WAF in my research and also give it to other clients and customers to use the updated WAF. All of this is done just because of the open-source feature, because it can be updated.
What needs improvement?
Atomic ModSecurity Rules can be improved by first studying and reading the structure of new obfuscated attacks, then trying to generate more specific and better rules to block these attacks, and then updating ModSecurity.
In order to improve Atomic ModSecurity Rules, one thing that can be used extensively is AI. AI can help especially the security experts to accomplish this as soon as possible with more quality.
For how long have I used the solution?
I have been using Atomic ModSecurity Rules for nearly two and a half years.
What do I think about the stability of the solution?
Atomic ModSecurity Rules is stable.
What do I think about the scalability of the solution?
The scalability of Atomic ModSecurity Rules is acceptable and proper because, as I mentioned earlier, it's open source and can be updated with new rules. This means we can scale it and its scalability is acceptable.
How are customer service and support?
The support provided for customers and clients through Atomic ModSecurity Rules involves updating ModSecurity with new rules. In the first place, ModSecurity will be updated with new rules. Then this will be published and provided as a new updated WAF for customers.
Which solution did I use previously and why did I switch?
I have not used any solution before Atomic ModSecurity Rules. When I started two and a half years ago, I started directly from ModSecurity.
In the first step of my research, I used both WAFs. One of them was Atomic ModSecurity Rules and the other one was AWS WAF. After that, I left AWS WAF because I could not improve or modify it, as AWS WAF is not open source like ModSecurity. Every vulnerability it has can only be solved and improved by Amazon. I could not do anything with that, so I left it and continued with ModSecurity.
How was the initial setup?
My experience with Atomic ModSecurity Rules regarding pricing, setup cost, and licensing is good because I have not paid anything for it. As I mentioned earlier, ModSecurity is open source, and I can deploy or implement it on my system without any price and any cost. Then I can use this in my research.
What was our ROI?
I have seen a return on investment with Atomic ModSecurity Rules because of AI. Everything can be more secure, and also fewer employees will be needed in the company. Everything can save money and funds because of AI.
What other advice do I have?
I would rate Atomic ModSecurity Rules nine out of ten.
I chose nine out of ten because I have not studied other WAFs. I know that ModSecurity is the only open source WAF, but I believe that the other WAFs could be studied more. Additionally, I know that ModSecurity can block only SQL injection and XSS attacks, no more types of attacks.
Atomic ModSecurity Rules's governance and security is absolutely important because, on one side, as I mentioned earlier, AI can be used to generate more obfuscated and dangerous attacks, more attacks that are valid and able to bypass the current ModSecurity. This can be done in just a couple of minutes, which can be very dangerous. But on the other side, we can also use AI to generate more rules and update the WAF against these attacks.
Regarding Atomic ModSecurity Rules's accuracy and reliability of output, I cannot tell anything with one hundred percent certainty. AI can make mistakes. After every step, everything should be checked in terms of validation, accuracy, precision, recall, false positive, and other factors. We can improve the accuracy of results and the reliability of output, but everything should be managed and checked subsequently in terms of validation and other metrics.
My advice to others looking into using Atomic ModSecurity Rules is to use this as one of the main WAFs if the area being worked in is web application firewalls. Because it's open source and can be modified and updated with new rules, it can be one of the main options in the security area, especially for web security attacks like SQL injection and XSS attacks. My overall rating for Atomic ModSecurity Rules is nine out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other

