|
hyperguard as a Server-Plug-in:
hyperguard is installed into your existing Web server as a software Plug-In. Incoming and outgoing requests are checked based on the various security policies. When a ruleset is activated and the policy is infringed, the query is rejected and not passed to the Web application on the Web server.
With separated admin:
The hyperguard admin can be installed into a separate server.
Cluster-Administration:
If it is installed in a cluster, hyperguard is scaled to the number of Web servers. A master XML server runs on the master. It receives the commands from the Administration interface and takes care of the administration of the slaves. This particularly includes querying the availability of the slaves and updating the slaves with new configurations. A slave XML server runs on the slaves, which receives control information and new configurations from the master. Similarly, there is a Decider that runs on each slave to evaluate each request.
Cluster-Administration distributed to several data centers:
If the IP addresses of the Cluster-Nodes from the respective data centers are known, it is still possible to administrate them from one Admin Node - no matter how many data centers are used to distriubte the Cluster Nodes.
You detect attacks on your Web applications
While providing protection against attempted attacks, hyperguard also serves as an intrusion detection system (IDS).
You satisfy compliance requirements
With hyperguard, you can continually assess and document which attempted attacks have actually been made on your Web application and which security measures are countering them.
This is also useful as evidence of your compliance with legal obligations, industry standards and service level agreements. Examples of this include the German Data Protection Act, Germany's Control and Transparency Act (KonTraG) and Basel II, Payment Card Industry (PCI) Data Security Standard and VISA's Cardholder Information Security Program (CISP), non-compliance can be bound up with very heavy fines.
You also eliminate unwanted traffic
As well as the protection against explicit attacks, hyperguard can also eliminate all other types of unwanted traffic on your Web application. Examples include deep linking, access via certain referers, access from specific regions, at specific times, by specific robots and by your competitors. Your access to your application does not always have to be blocked completely. You can also simply restrict access to individual parts of your application, deliberately generate certain HTTP error messages or re-route to a particular page.
Interaction with hypersource:
You can use hypersource to analyse your Web application's source code for vulnerabilities. Then import the result to hyperguard as an XML file that automatically proposes the rules required to safeguard the vulnerabilities found.
This procedure can also be automated, so it can be integrated as a fixed part of your workflow.
|