hyperguard 30 Tage testen?


Cloud AppSec

Cloud computing was not designed for security, although organizations such as Cloud Security Alliance (CSA) and Open Web Application Security Project (OWASP) are making great strides in helping the industry solve the myriad security problems confronting cloud computing. The benchmark guidelines established by the CSA in the document, Guidance for Critical Areas of Focus in Cloud Computing, is a great first step. This white paper is intended to pick up where the CSA guide left off in terms of defining what a distributed web application firewall (dWAF) should look like in order to meet the standards set within the CSA document.

 

Get the Cloud AppSec Whitepaper here

Home  Products  hyperguard  Security features

Security features

 

Security Features License
  Basic Premium Proxy Enterprise
Web-based user interface OK OK OK OK
Basic mode and Expert mode for simple and advanced configuration tasks OK OK OK OK
Ready-made rulesets for baseline protection and common security measures OK OK OK OK
Configuration is assisted by intelligent learning algorithms that analyse log files and propose automatically generated application-specific rules   OK OK OK
Automatic configuration for protecting Microsoft Outlook Web Access (OWA)   OK OK OK
Direct import of ModSecurity rulesets   OK OK OK
Central administration of clustered installations   OK OK OK
Role based management of multiple Web applications   OK OK OK
Complete configuration history and audit log OK OK OK OK
LDAP, Active Directory Admin Authorisation   OK OK OK
Prefixes for separately handling special file types and directories OK OK OK OK
Preconditions to simplify configuring the rules for individual prefixes   OK OK OK
Object-orientated inheritance mechanisms to quickly create sophisticated rule configurations OK OK OK OK
Integrated version management: earlier versions can be re-edited and activated at any time OK OK OK OK
Export and import functions for easy migration of rules from test to live systems OK OK OK OK
Bi-directional HTTP request analysis   OK OK OK
Protection level can be customised to the risk level of the Web applications being protected   OK OK OK
Protection against all common attack patterns OK OK OK OK
Regular updates mean that the protection is continually and automatically updated OK OK OK OK
Web Services Security Gateway (XML/SOAP)   OK OK OK
White/Black-listing in Realtime OK OK OK OK
Grey-listing in Realtime   OK OK OK
Proactive protection including
  • Secure session management
  • Form field protection
  • URL encryption
  • Site usage enforcement
  • Deep linking prevention
  OK OK OK
Checks run on syntactic validity of HTTP requests OK OK OK OK
Validity of XML data against specified given DTD   OK OK OK
Additional measures:
  • Request throtteling
  • Access restricted to particular days and times of day
  • IP address restriction
  OK OK OK
Separate rulesets for enforcement and monitoring can be used simultaneously (protection ruleset / detection ruleset)   OK OK OK
Clusterfunctionality
  • Statistics
  • Monitoring
  • Reporting
  • Log file analysis
  • Statistics to give an overview of the load and status of all the cluster slaves
  OK OK OK
Configurable alarm systems when certain events occur OK OK OK OK
Notification e.g. by email, post request, snmp trap or as an entry in a separate log file OK OK OK OK
Log files with host specific logs of all internal system events and error messages OK OK OK OK
Default error log with events that affect no specific application and thus affect no specific host (e.g. invalid requests) OK OK OK OK
Audit log recording all administrators' individual actions OK OK OK OK
Licensed per CPU core     OK  
Licensed per machine instance OK OK    
Licensed per application       OK
Reverse/Forward proxy operation     OK