E-Business
Key Considerations in Using a Web Application Firewall

Cyber security specialists are realising more and more the growing danger of application layer threats to a network.
While there is no denying the need to remain aware of distributed denial of service (DDoS) attacks, application layer attacks are very difficult to detect and provide little or no advanced warning before attacking your applications.
This is according to Simon McCullough, major channel account manager at F5, the specialist in application delivery networking and technology for the delivery of web applications, as well as security and network and cloud resources.
McCullough said, “Administrators and security teams are finding it increasingly difficult to keep up-to-date with the latest attacks and protection measures. Applications are the gateway to data and data is what hackers are after. In an attack on applications, traditional network firewalls are not a defence. Here, you need a web application firewall (WAF).
“As we become increasingly aware of the dangers posed by application layer threats, it is useful to revisit the F5 White Paper, ‘Key Considerations in Choosing a Web Application Firewall’, which notes that a robust WAF is a requirement of network security. This has come about in a cyber landscape in which enterprises are extending their businesses by using more web-based and cloud-hosted applications, which in turn are inviting increasingly sophisticated attacks that threaten enterprise data.”
McCullough said the White Paper offers a number of useful considerations in choosing your WAF.
He noted that the first consideration is the choice of WAF deployment model, which includes: hardware WAF appliance to protect critical applications maintained in a traditional data centre; deploying a WAF as a software-based virtual edition (VE), which is a cost-effective option for small-to-medium-size businesses or those wanting to deploy protections closer to the app; and cloud-based WAF (WAF-as-a-Service) to intercept web traffic before it enters the network or reaches the server in the cloud.
He said, “The White Paper distinguishes between initial basic considerations when deploying a WAF, and further advanced considerations.”
Basic considerations when deploying a WAF
Network architecture and application infrastructure
Web application firewalls are designed to watch and respond to HTTP/S traffic. They are most often deployed as appliances in the line of traffic between the requester and the application server, inspecting requests and responses before forwarding them. Inline deployments tend to be most effective in actively blocking malicious traffic based on policies and rules that must be applied judiciously to avoid dropping legitimate traffic. A WAF can also be deployed “out of band”, which allows the WAF to observe traffic from a monitoring port. This non-intrusive “passive” deployment option is ideal for testing the WAF without impacting on traffic, yet still enabling the WAF to block malicious requests.
Security effectiveness and detection techniques
Today’s leading WAFs employ a combination of techniques to ensure accurate detection coverage that does not block legitimate traffic.
Traditionally, the most widely used WAF configuration has been a negative security model, which allows all transactions except those that contain a threat/ attack.
In recent years, positive security models have become popular. This approach blocks all traffic, allowing only those transactions that are known to be valid and safe. The positive approach is based on strict content validation and statistical analysis.
An integrated positive and negative approach can also be implemented.
Performance, high availability and reliability
WAF capabilities should include these features:
- Caching copies of regularly requested web content to reduce repeated requests to back-end servers.
- Automatic content compression to provide for more efficient network transport.
- Hardware-based SSL acceleration to speed SSL processing and reduce the burden on back-end web servers.
- Load balancing web requests across multiple back-end web servers to optimise performance.
- Connection pooling to reduce back-end server TCP overhead by allowing multiple requests to use the same back-end connection.
Virtual patching and scanner integration
Although developers apply best practices in secure coding, and perform adequate security testing of applications, all applications are prone to vulnerabilities. Additional tools are needed to detect, validate and patch software exposures until a new application code is made available.
Virtual patching requires no immediate changes to the software, and it allows organisations to secure applications immediately upon dynamic application testing. Virtual patches are a key component of a strong WAF, often requiring integration with a vulnerability scanner.
PCI DSS compliance
Malicious attacks designed to steal sensitive credit card information are increasing, with more and more security breaches and data thefts occurring daily. The PCI DSS requirements have been revised in an attempt to prevent these types of attacks and keep customer data secure.
Protection against application attacks
With the continued growth of multi-layered attacks, IT managers need a strong WAF solution. A good WAF ensures application security and availability by providing comprehensive geolocation attack protection from layer 7 DDoS, SQL injection, Open Web Application Security Project (OWASP) Top Ten application security risks, cross-site scripting, and zero-day web application attacks. It also can prevent execution of fraudulent transactions, stop in-browser session hijacking, and secure AJAX applications and JSON payloads.
When evaluating a WAF, make sure you understand the full scope of protections it offers to ensure that your business receives the best coverage.
Data classification of protected applications
More and more attackers are encrypting their attacks, therefore your WAF solution needs to be able to understand the application and the data that it is protecting. If that data is encrypted, your WAF must be able to decrypt the information and then classify the data within the apps in order to provide additional protection. A strong WAF can terminate SSL traffic, expose what is inside it, and make security decisions based on the encrypted data.
Visibility and reporting
Reports provide visibility into attack and traffic trends, long-term data aggregation for forensics, acceleration of incident response, and identification of unanticipated threats before exposure occurs. Many WAFs also integrate with database security products to give administrators a real-time view into the operation of their websites, and provide reports on web-based attempts to gain access to sensitive data, subvert the database, or execute denial of service (DoS) attacks against the database.
Advanced considerations when deploying a WAF
McCullough notes further advanced considerations when deploying a WAF, as set out by the F5 White Paper, as follows:
- Automatic attack detection to identify more evasive bot sequences that may escape traditional detection methods, and identify unauthorised, automated attacks upon the first attempt to access an application.
- Device ID and fingerprinting in order to identify a client.
- SSL offload to other network resources, allowing applications to dedicate important CPU resources to other processing tasks, which can improve performance.
- Behavioural analysis to understand volumetric traffic patterns and scan for anomalous behavior, as well as assess average server response time, transactions per second, and sessions that request too much traffic – to use as a baseline for determining whether an attack has commenced.
- Security operations centre: A responsive security team should include experts who analyse threats and malware, and who reverse engineer code to uncover how attacks work and how to mitigate them. The WAF vendor should work with you to mitigate threats as they arise, as well as enhance your organisation’s own security practices.
- Anti-fraud capabilities: More advanced WAF solutions integrate with web fraud detection services to simplify deployment, streamline reporting, and strengthen the overall application security posture by thwarting requests from validated fraudsters.
- Ease of management: You should be able to deploy your WAF with security policies that immediately address common attacks on web applications, including HTTP(S) attacks.
- Scalability and performance: Organisations need to ensure application availability, even when under attack.
- Vendor release cycle: With the threat landscape changing so quickly, vendors that offer more frequent release can help decrease your window of exposure and reduce the risk of your applications becoming compromised by a new or emerging threat.
Anton Jacobsz, managing director at Networks Unlimited, a value-added distributor of F5 in Africa, concludes, “Application attacks have definitely been increasing over the past few years, due to the increasing proliferation of useful web apps which, concomitantly, increase a network’s vulnerability. Web application firewalls detect and block malicious attacks woven into safe-looking website traffic that may have slipped through the traditional security solutions, by examining incoming HTTP requests before they even reach the server.”
E-Business
NPC Opens 131 Births, Deaths Registration Centres in Anambra

National Population Commission (NPC) has announced commencement of full digital registration of births and deaths through the VitalReg platform, which became operational nationwide on July 1, 2026.

Chidi Ezeoke, federal commissioner representing Anambra, disclosed this in Awka during a press conference to announce commencement of full digital birth and death registration under the Electronic Civil Registration and Vital Statistics (E-CRVS) system and the marking of World Population Day commemorated every July 11.
He revealed that a total of 131 registration centres had been opened in the 21 local government headquarters and several communities in the state, adding that more centres would be opened later.
Ezeoke described the initiative as a major milestone in Nigeria’s Civil Registration and Vital Statistics (CRVS) system, to ensure every birth and death in the country was captured through a digitally enabled registration platform.
“It builds on the launch of the E-CRVS system and the inauguration of the National Coordination Committee on Civil Registration and Vital Statistics by President Bola Tinubu on Nov. 8, 2023.
“A total of 4,011 functional registration centres has been established across the 774 LGAs of the federation and the commission iswas working to expand the number to about 8,000.
“In Anambra, 131 registration centres have been opened in the 21 local government headquarters and several communities. More centres had been proposed for the state,” he said.
According to the Commissioner, the VitalReg platform would provide faster registration services, 24-hour online access, digital certificate issuance where applicable, reduced paperwork and waiting time, improved data validation and a more secure national CRVS database.
While noting that the platform would serve as a foundational database to support other national data systems and strengthen interoperability across Nigeria’s digital identity ecosystem, Ezeoke urged Nigerians and other stakeholders to support the initiative by ensuring prompt registration of all births and deaths.
Speaking on the 2026 World Population Day themed, “Realising the Hopes and Aspirations of Young People – Today and for the Future”, the Commissioner called for greater investment in education, healthcare, skills development, decent employment opportunities and youth participation in governance for sustainable national development.
Earlier, Mr Obiakonwa Okagwu, state director, NPC, said the occasion served as a reminder of great opportunities provided to harness young people’s capabilities, which he said would shape the future of the country when adequately harnessed.
He called on residents to take registration of births and deaths as national responsibility, just as he urged the media to take the message on civil registration to all parts of the State.
E-Business
Report Says Cybercriminals Deploy Malware to Hijack Crypto Wallets, Monitor Browsers Telegram

Cybersecurity researchers at Kaspersky have uncovered a sophisticated malware framework, dubbed OkoBot, that is targeting cryptocurrency users by stealing wallet recovery phrases, browser credentials and other sensitive information through a multi-stage attack campaign spanning more than 25 countries.

The researchers said the malware, active since April 2025, employs more than 20 malicious payloads and has evolved into an advanced cybercrime platform focused on compromising digital asset holders. According to Kaspersky’s Global Research and Analysis Team (GReAT), the campaign remains active and has already affected hundreds of users worldwide.
Kaspersky disclosed that one of the framework’s most dangerous components, known as SeedHunter, injects malicious code into legitimate cryptocurrency wallet applications, including Ledger Wallet, Ledger Live and Trezor Suite, before displaying fake recovery phrase prompts designed to trick victims into surrendering their seed phrases.
The security firm explained that once attackers obtain a victim’s recovery phrase, they gain complete control over the cryptocurrency wallet, enabling them to transfer digital assets with virtually no chance of recovery.
Commenting on the discovery, Dmitry Galov, security researcher at Kaspersky’s GReAT, said.
“This campaign has been running for more than a year and remains active. OkoBot is not just a single piece of malware but an extensible framework built primarily to compromise cryptocurrency users.”
Galov added that the malware is continuously maintained and enhanced, underscoring the attackers’ long-term focus on financial theft.
According to Kaspersky, victims are typically infected through ClickFix phishing attacks or malicious GitHub repositories masquerading as legitimate software downloads. In one instance, a fake Microsoft SQL Server Management Studio repository secretly installed a trojanized version of the Audacity audio editor embedded with malicious code.
Following the initial compromise, the attackers deploy a PowerShell downloader called TookPS,which establishes an encrypted SSH connection to attacker-controlled infrastructure.
The malware then harvests browser cookies, wallet files, stored credentials and system information before downloading additional malicious modules.
Among the additional payloads is OkoSpyware which monitors more than 100 applications, which includes cryptocurrency wallets and password managers—records user activity and captures keystrokes and video of application windows. Another module silently installs malicious browser extensions capable of stealing financial information and authentication tokens.
However, Kaspersky’s telemetry indicates that the largest concentrations of victims have been recorded in Brazil, Vietnam, Canada, Mexico and Türkiye, although the malware campaign has spread to users across more than 25 countries.
The cybersecurity firm advised cryptocurrency users never to enter wallet recovery phrases into prompts displayed by desktop applications or websites unless they have independently verified their authenticity.
Furthermore,It also urged users to download wallet software exclusively from official sources, enable multi-layered endpoint protection, and remain cautious of software offered through unofficial repositories or phishing websites.
Kaspersky noted that while hardware wallets themselves remain secure, attackers are increasingly exploiting the software that accompanies them, making user awareness a critical line of defence against evolving cryptocurrency-focused cyber threats.
E-Business
HURIWA, CLO Protests Bill Asking Social Media Firms’ to Open Shops Nigeria

Human Rights Writers Association of Nigeria (HURIWA) has opposed a bill seeking to compel major global social media companies to establish physical offices in Nigeria.

The rights advocacy group urged the National Assembly to discard the proposed legislation, warning that it could become a tool for censorship and undermine citizens’ constitutional right to freedom of expression, despite being presented as a measure to strengthen Nigeria’s digital economy and improve corporate accountability.
The position was contained in a presentation submitted yesterday by Emmanuel Onwubiko, national coordinator, HURIWA, to the chairman of the Senate Committee on ICT and Cyber Security.
The bill, sponsored by Senator Ned Munir Nwoko, has already passed second reading in the Senate and is before the committee for further legislative consideration.
HURIWA said it carefully reviewed the proposed legislation and concluded that compelling global technology companies to establish offices in Nigeria was unnecessary and potentially counterproductive.
The organisation argued that while the firms generate substantial revenue from Nigeria’s vast digital market, they already engage Nigerians through existing structures, including paying eligible content creators, working with local technology professionals and participating in legal proceedings whenever required.
According to the group, appointing local representatives where necessary would adequately address concerns about engagement with regulators and users without forcing the companies to maintain physical offices.
It also dismissed claims that mandatory country offices would significantly improve consumer complaint resolution, technology transfer or employment generation.
HURIWA maintained that the platforms already have effective feedback mechanisms for resolving users’ complaints and routinely appear before Nigerian courts through their representatives whenever litigation arises.
The group, however, said its greatest concern was the potential for the proposed law to be used as an instrument for restricting freedom of expression.
It argued that establishing local offices could expose global social media companies to pressure from government authorities to remove online content considered critical of those in power.
According to the rights group, the presence of social media companies in Nigeria could become an avenue for authorities to pressure them into abandoning internationally recognised digital rights standards in favour of politically motivated content moderation.
It recalled previous attempts to regulate social media in Nigeria that generated widespread concerns over possible restrictions on free speech, stressing that any legislation affecting the digital space must contain clear safeguards against abuse.
The organisation warned that the proposed law should never become “a backdoor mechanism for government surveillance, arbitrary content removal or political censorship.
Telecom2 days agoGSMA Supports Abuja Declaration on Meaningful Connectivity for Africa, Joins Partners to Launch ATLAS Umoja
Telecom2 days agoMTN Nigeria Warns Customers Against Fake ‘One Month Free Data’ Promotion
Telecom2 days agoAirtel Secures Another 10-year Spectrum Renewal in Nigeria
News2 days agoNigeria, Israel Strengthen Research, Technology Collaboration
Broadcasting2 days agoGlo Sponsored African Voices to Feature Netflix’s “The Polygamist” Stars
E-Financial2 days agoMoniepoint as a Key Driver in Expanding Financial Access for Businesses in Nigeria
E-Business2 days agoHURIWA, CLO Protests Bill Asking Social Media Firms’ to Open Shops Nigeria
General News2 days agoAnambra Govt Bans Graduation Ceremonies in Anambra Schools














