Web Application Security Products
for the entire life cycle
  hyperguard 30 Tage testen?

PCI Compliance

Our Solutions support you to comply with PCI DSS V.1.2

  • Web Application Protection (6.6)
  • Source Code Reviews (6.3.7)
  • Penetration Testing (11.3.2)

more Infos...

 

hyperguard Produktblatt hyperguard Factsheet

 

hyperguard as a Server-Plug-in:

hyperguard 

hyperguard is installed into your existing Web server as a software Plug-in. Incoming and outgoing requests are checked based on the various security policies. When a ruleset is activated and the policy is infringed, the query is rejected and not passed to the Web application on the Web server.

 

With separated admin:

hyperguard 

The hyperguard admin can be installed into a separate server.

 

Cluster-Administration:

hyperguard 

When it is installed in a cluster, hyperguard is scaled according to the number of Web servers. A master XML server runs on the master. It receives the commands from the Administration interface and takes care of administering the slaves. This particularly includes querying the availability of the slaves and updating the slaves with new configurations. A slave XML server runs on the slaves, which receive control information and new configurations from the master. Similarly, there is a Decider that runs on each slave to evaluate each request.

 

Cluster-Administration distributed to several data centers:

hyperguard 

If the IP addresses of the Cluster-Nodes from the respective data centers are known, it is still possible to administrate them from one Admin Node - no matter how many data centers are used to distriubte the Cluster Nodes.

You detect attacks on your Web applications

While providing protection against attempted attacks, hyperguard also serves as an intrusion detection system (IDS).

You satisfy compliance requirements

With hyperguard, you can continually assess and document which attempted attacks have actually been made on your Web application and which security measures are countering them.

This is also useful as evidence of your compliance with legal obligations, industry standards and service level agreements. Examples of this include the German Data Protection Act, Germany's Control and Transparency Act (KonTraG) and Basel II, Payment Card Industry (PCI) Data Security Standard and VISA's Cardholder Information Security Program (CISP), non-compliance with which can be bound up with very heavy fines.

You also eliminate other unwanted traffic

With hyperguard, as well as protecting against explicit attacks, you can also eliminate all other types of unwanted traffic on your Web application. Examples include deep linking, access via certain referers, access from specific regions, at specific times, by specific robots and by your competitors. Not always does your access to your application have to be completely blocked. You can also simply restrict access to individual parts of your application, deliberately generate certain HTTP error messages, or re-route to a particular page.

 

Interaction with hypersource and hyperscan:

hyperscan
hyperguard
hypersource

You can either use hypersource to analyse your Web application's source code or you use hyperscan  to scan your Web application for vulnerabilities. You then import the result to hyperguard as an XML file that automatically proposes the rules required to safeguard the vulnerabilities found.

This procedure can also be automated, so it can be integrated as a fixed part of your workflow.