Production Web Security Hardening
SCComp deployed layered edge and application protections for safer customer access, stronger abuse resistance, and clearer operational visibility.
We completed a production security review of the public SCComp request path and deployed a layered set of defenses without changing customer networking or service workflows.
The public edge now applies verified Host handling, trusted client-address forwarding, bounded request resources, sensitive-file and irrelevant scanner rejection, endpoint-aware abuse controls, and the OWASP Core Rule Set in blocking mode. Security headers are consistent across the public site, and backend software versions are no longer forwarded to visitors.
Public support and sales inquiries now combine CSRF validation, an invisible accessibility-safe bot trap, cryptographically signed form timing, replay and duplicate detection, per-address and per-email limits, strict input validation, and maintainable weighted spam screening. Automated submissions can be discarded without disclosing which signal triggered, while ordinary infrastructure questions remain usable.
That distinction matters for SCComp. Customers routinely paste IP addresses, BGP details, URLs, SQL, shell commands, HTML, logs, and traversal strings while troubleshooting. We tested those realistic support cases and kept narrowly scoped exceptions limited to the message field; headers, identities, uploads, protocol behavior, other fields, and application validation still receive full protection.
A repeatable regression suite now checks public pages and assets, sensitive-path probes, unsupported methods, representative non-destructive attack traffic, required response headers, and a legitimate technical support payload. We also verified oversized headers, paths, and request bodies are rejected, modern TLS remains available, spoofed proxy identity is replaced, and backend services remain healthy after graceful reloads.
Security is an ongoing operational process. Future work includes maintaining distribution security updates, planning a newer CRS generation after compatibility testing, adding centralized security-event alerting, and using a dedicated test account for deeper authenticated regression. The current release materially improves protection against spam, scanners, brute-force traffic, malicious payloads, malformed requests, and resource abuse while preserving legitimate customer workflows.