- Home
- Client-Side Defense
- References
References
Documentation
Section titled “Documentation”- About Client-Side Defense — Concepts and architecture
- Configure Client-Side Defense — Configuration guide
- Client-Side Defense — All CSD documentation
- Enriched Shape API reference — CSD domains, scripts, telemetry, reports, and mitigation
- Enriched Virtual API reference — HTTP load balancers, origin pools, and health checks
Product Resources
Section titled “Product Resources”- F5 Client-Side Defense — Product page and data sheets
- Client-Side Defense Demo — Video walkthrough
PCI DSS
Section titled “PCI DSS”- PCI DSS v4.0 Standard — Full standard document library
- Requirement 6.4.3 — Manage all payment page scripts: maintain inventory, provide written authorization and justification, verify integrity
- Requirement 11.6.1 — Deploy tamper-detection mechanisms on payment pages to alert on unauthorized modifications to HTTP headers and page content
Threat Research
Section titled “Threat Research”- OWASP Top 10 Client-Side Security Risks — Candidate risks for browser-side applications and third-party JavaScript
- Sansec Magecart Research — Magecart groups and digital-skimming campaigns
- British Airways breach (2018) — Magecart Group 6 injected a skimmer into the BA payment page, compromising 380,000 transactions
- Ticketmaster breach (2018) — Supply chain attack via compromised Inbenta chatbot script that skimmed payment card data
Attack Categories & Standards
Section titled “Attack Categories & Standards”- OWASP Clickjacking — UI redressing attack definition and prevention
- OWASP Cross-Site Scripting — Script injection attack taxonomy
- MITRE ATT&CK T1195 Supply Chain Compromise — Supply chain attack framework
- MITRE ATT&CK T1185 Browser Session Hijacking — Adversary access to authenticated browser sessions
- MITRE ATT&CK T1496 Resource Hijacking — Cryptojacking classification
- MITRE ATT&CK TA0010 Exfiltration — Data exfiltration tactic
- Akamai Web Skimming — Digital skimming overview
- Sansec Magecart Research — Magecart groups and campaigns
Privacy & Compliance
Section titled “Privacy & Compliance”- F5 CSD Privacy Statement — What CSD telemetry collects
- F5 CSD PCI DSS v4.0.1 Blog — Official PCI compliance mapping
Industry Standards
Section titled “Industry Standards”- OWASP Top 10 Client-Side Security Risks — Candidate client-side security risks
Origin Server Offerings
Section titled “Origin Server Offerings”- Origin Server documentation — Choose between the Azure full-origin nine-application stack and the separate AWS Juice Shop-only Fargate module
- Deploy
- Verify
- Integrate with F5 Distributed Cloud
- Teardown and recovery
- Vendored AWS module provenance — immutable upstream commit
d6384bb0621c4c1eceb38d55a6b63e7b9cc7083a - Published guidance source PR #697 — merged as
595841996ef7e782870be8200dce4775defb7e80
The AWS offering is Juice Shop only behind an ALB with private Fargate tasks. It is not equivalent to the Azure nine-application full-origin VM offering.