FortiWeb for ISP. Web Application Firewall. Copyright Fortinet Inc. All rights reserved.



Similar documents
FortiWeb 5.0, Web Application Firewall Course #251

FortiWeb TM. Web Application Firewall. Unmatched Protection for Web Applications. Emerging Threats Create New Challenges

Contemporary Web Application Attacks. Ivan Pang Senior Consultant Edvance Limited

FortiWeb. Web Application Firewall. Unmatched Protection for Web Applications. Emerging Threats Create New Challenges. FortiWeb DATA SHEET

Arrow ECS University 2015 Radware Hybrid Cloud WAF Service. 9 Ottobre 2015

Protecting against DoS/DDoS Attacks with FortiWeb Web Application Firewall

Web Application Security. Radovan Gibala Senior Field Systems Engineer F5 Networks

REAL-TIME WEB APPLICATION PROTECTION. AWF SERIES DATASHEET WEB APPLICATION FIREWALL

WHITE PAPER. FortiWeb and the OWASP Top 10 Mitigating the most dangerous application security threats

NSFOCUS Web Application Firewall

STOPPING LAYER 7 ATTACKS with F5 ASM. Sven Müller Security Solution Architect

Load Balancing Security Gateways WHITE PAPER

Disaster Recovery with Global Server. Load Balancing

WEB APPLICATION FIREWALLS: DO WE NEED THEM?

10 Things Every Web Application Firewall Should Provide Share this ebook

FortiDDoS. DDoS Attack Mitigation Appliances. Copyright Fortinet Inc. All rights reserved.

FortiDDos Size isn t everything

White Paper A10 Thunder and AX Series Load Balancing Security Gateways

FortiWeb. Web Application Firewalls. Industry-Leading Web Application Firewall Performance. Web Applications are an Easy Target

THE SMARTEST WAY TO PROTECT WEBSITES AND WEB APPS FROM ATTACKS

The Hillstone and Trend Micro Joint Solution

Game changing Technology für Ihre Kunden. Thomas Bürgis System Engineering Manager CEE

Networking and High Availability

IBM Advanced Threat Protection Solution

SHARE THIS WHITEPAPER. Top Selection Criteria for an Anti-DDoS Solution Whitepaper

Powered by. Incapsula Cloud WAF

NSFOCUS Web Application Firewall White Paper

Networking and High Availability

Protect the data that drives our customers business. Data Security. Imperva s mission is simple:

Secure Cloud-Ready Data Centers Juniper Networks

Radware s Attack Mitigation Solution On-line Business Protection

Move over, TMG! Replacing TMG with Sophos UTM

Barracuda Web Application Firewall vs. Intrusion Prevention Systems (IPS) Whitepaper

Mingyu Web Application Firewall (DAS- WAF) All transparent deployment for Web application gateway

McAfee Web Gateway Administration Intel Security Education Services Administration Course Training

Zscaler Internet Security Frequently Asked Questions

Swordfish

Introduction: 1. Daily 360 Website Scanning for Malware

Equalizer DATASHEET AND PRODUCT GUIDE FEATURES

Radware Attack Mitigation Solution (AMS) Protect Online Businesses and Data Centers Against Emerging Application & Network Threats - Whitepaper

WildFire. Preparing for Modern Network Attacks

IJMIE Volume 2, Issue 9 ISSN:

Where every interaction matters.

Out of the Fire - Adding Layers of Protection When Deploying Oracle EBS to the Internet

Akamai to Incapsula Migration Guide

Introducing FortiDDoS. Mar, 2013

WHITE PAPER FORTIWEB WEB APPLICATION FIREWALL. Ensuring Compliance for PCI DSS 6.5 and 6.6

Web Application Firewalls: When Are They Useful? OWASP AppSec Europe May The OWASP Foundation

Cisco Small Business ISA500 Series Integrated Security Appliances

Unified Threat Management, Managed Security, and the Cloud Services Model

ZEN LOAD BALANCER EE v3.04 DATASHEET The Load Balancing made easy

Gateway Security at Stateful Inspection/Application Proxy

Content Scanning for secure transactions using Radware s SecureFlow and AppXcel together with Aladdin s esafe Gateway

Cyberoam Next-Generation Security. 11 de Setembro de 2015

Network Security Platform 7.5

How To Protect A Web Application From Attack From A Trusted Environment

APV9650. Application Delivery Controller

Fighting Advanced Threats

Networking for Caribbean Development

INTRODUCTION TO FIREWALL SECURITY

Huawei Eudemon200E-N Next-Generation Firewall

NetScaler: A comprehensive replacement for Microsoft Forefront Threat Management Gateway

HOW TO PROTECT YOUR VIRTUAL DESKTOPS AND SERVERS? Security for Virtual and Cloud Environments

Cyan Networks Secure Web vs. Websense Security Gateway Battle card

Protection against DDoS and WEB attacks. Michael Soukonnik Radware Ltd

McAfee Network Security Platform

Astaro Gateway Software Applications

Aplikacija novi vladar poslovanja. Dino Novak F5 Networks

Veranderende bedreigingen Security in het virtuele datacenter

WHITE PAPER. FortiGate DoS Protection Block Malicious Traffic Before It Affects Critical Applications and Systems

TDC s perspective on DDoS threats

Deployment Guide July-2014 rev. a. Deploying Array Networks APV Series Application Delivery Controllers with Oracle WebLogic 12c

Coyote Point Equalizer

Superior protection from Internet threats and control over unsafe web usage

Smart Network. Smart Business. Application Delivery Solution Brochure

Simple security is better security Or: How complexity became the biggest security threat

ZEN LOAD BALANCER EE v3.02 DATASHEET The Load Balancing made easy

How To Protect Your Web Applications From Attack From A Malicious Web Application From A Web Attack

FISMA / NIST REVISION 3 COMPLIANCE

Next Generation Firewalls and Sandboxing

JK0 015 CompTIA E2C Security+ (2008 Edition) Exam

Datacenter Transformation

Cyberoam Perspective BFSI Security Guidelines. Overview

APV x600 Series. Application Delivery Controller APV1600, APV2600, APV4600, APV5600, APV6600, APV8600, APV9600

Semantic based Web Application Firewall (SWAF V 1.6) Operations and User Manual. Document Version 1.0

Availability Acceleration Access Virtualization - Consolidation

A Layperson s Guide To DoS Attacks

WHITE PAPER. FortiWeb Web Application Firewall Ensuring Compliance for PCI DSS 6.5 and 6.6

DPtech ADX Application Delivery Platform Series

[Restricted] ONLY for designated groups and individuals Check Point Software Technologies Ltd.

White Paper Secure Reverse Proxy Server and Web Application Firewall

Information Supplement: Requirement 6.6 Code Reviews and Application Firewalls Clarified

Importance of Web Application Firewall Technology for Protecting Web-based Resources

Uncover security risks on your enterprise network

Next Generation Firewall

WHITE PAPER. Enhancing Application Delivery and Load Balancing on Amazon Web Services with Brocade Virtual Traffic Manager

F5 Silverline Web Application Firewall Onboarding: Technical Note

Transcription:

FortiWeb for ISP Web Application Firewall Copyright Fortinet Inc. All rights reserved.

Agenda Introduction to FortiWeb Highlights Main Features Additional FortiWEB Services for the ISP FortiWeb Family 2

Introduction to FortiWeb

Scope/Definition of WAFs Protects web-based applications from code-based attacks» SQL Injection or other injection types» Cross Site Scripting and Request Forgery» Layer 7 DoS/DDoS attacks» Cookie/schema poisoning Protects against application vulnerabilities in custom code and commercial platforms INTERNET Web Application" Servers" SQL Injection, XSS FortiWeb WAF! Understands/learns normal behaviors and stops anomalies» URL parameters, HTTP methods, session IDs, cookies, schema, etc. Can t a Firewall or IPS do this? Firewalls look for network-based attacks IPS Signatures detect only known problems» No protection of SSL traffic» No application or user awareness 4

WAF Drivers/Challenges Protect current and existing applications from code-based vulnerabilities Meet PCI Compliance (5.5 and 6.6) for credit card and healthcare data Address OWASP Top 10 Application Vulnerabilities Identify and address web application vulnerabilities Website publishing for Microsoft and other applications Protect against website defacement Who Needs it? Any organization that processes credit cards and/or has PCI requirements Large internal or external applications Sensitive/proprietary information Mission-critical business applications Who Needs it Most? MSPs/Hosting Companies E-commerce/online services Retail, Food Service, Hospitality Financial services Healthcare 5

FortiWeb Web Application Firewalls 4 models from 100 Mbps to 4 Gbps HTTP throughput Up to 6x GE and models with 2x 10GE SFP+ ports Included vulnerability scanning and antivirus Hardware and VM options (VMware, Hyper-V) Automatic behavior-based scanning Auto setup/learning mode Layer 7 DDoS protection FortiGuard antivirus/ip reputation Transparent, reverse and non-inline deployment options Central Management/ADOMs Advanced real-time reporting SSL offloading/compression SSO/Authentication Layer 7 load balancing NSS recommended Complete WAF Solution 6

FortiWeb Benefits Protect custom and commercial applications with automatic usage profiling Meet PCI Compliance (5.5 and 6.6) with behavior-based attack detection and mitigation Protection against OWASP Top 10 Application Vulnerabilities Identify web application security weaknesses with vulnerability scanning Website publishing with Single Sign On/Authentication Restore website pages from attacks with Anti-Defacement Protection Block botnets and attacks from known rogue and malicious sources with FortiGuard IP Reputation 7

Deployment Options Layer II - Transparent Inspection and True Transparent Proxy Easy deployment - No need to re-architect network, full transparency Fail Open Interface Reverse Proxy Supports content modification for both requests and replies from the server Advanced URL rewriting capabilities HTTPS offloading Enhanced load balancing schemes Non Inline Deployment SPAN port Zero network latency Blocking capabilities using TCP resets Ideal for initial product evaluations, non-intrusive network deployment FortiWeb! FortiWeb! Web Application" Servers" 8

Highlights Main Features

FortiWeb Application Delivery WAF Web Application Firewall - WAF Secures web applications to help customers meet compliance requirements Web Vulnerability Scanner Scans, analyzes and detects web application vulnerabilities Application Delivery Assures availability and accelerates performance of critical web applications Secures Web Applications Scans and Detects Web Vulnerabilities Optimizes Application Delivery 10

FortiWeb Application Delivery WAF Web Application Firewall - WAF Secures web applications to help customers meet compliance requirements Web Vulnerability Scanner Scans, analyzes and detects web application vulnerabilities Application Delivery Assures availability and accelerates performance of critical web applications Secures Web Applications Scans and Detects Web Vulnerabilities Optimizes Application Delivery 11

SSL Offloading & Acceleration SSL Offloading Integrated ASIC based hardware Hardware-based key exchange and bulk encryption Purpose built SSL processing CA Management Full certificate management Advanced certification verification and revocation capabilities TCP Connection Multiplexing FortiASIC CP8 SSL Acceleration Chip ü Offload CPU intensive SSL computing from server to FortiWeb 12

Server Load Balancing Layer 7 Load Balancing Methods: Weighted Round Robin, Round- Robin, Least Connection, HTTP session round robin Connection persistence with timeout value Probes & Health Checks: TCP, HTTP/ HTTPS, PING. Content based health checks ü Intelligent, application aware layer 7 load balancing 13

URL Routing/Rewriting Advanced Routing and Rewriting capabilities Route traffic based on: IP, Host, URL Rewriting and Redirection: Host, URL, Referrers Rewrite Reply Content Rewrite absolute links Any required content Multiple content types supported 14

FortiWeb main features WAF Web Application Firewall - WAF Secures web applications to help customers meet compliance requirements Web Vulnerability Scanner Scans, analyzes and detects web application vulnerabilities Application Delivery Assures availability and accelerates performance of critical web applications Secures Web Applications Scans and Detects Web Vulnerabilities Optimizes Application Delivery 15

Vulnerability Assessment Easily Scan your web applications Common vulnerabilities SQL Injection Cross Site Scripting Source code disclosure OS Commanding Enhanced/Basic Mode Crawling information URLs accepting input External Links Authentication Options Scheduled and on Demand Scanning FortiWeb 16

Vulnerability Assessment Vulnerability Reports Scan summary Vulnerability by severity Vulnerability by categories Application Vulnerabilities Common Vulnerabilities Server Information Crawling information URLs accepting input External Links Provides Recommendations and Graphs Updates via FortiGuard 17

FortiWeb main features WAF Web Application Firewall - WAF Secures web applications to help customers meet compliance requirements Web Vulnerability Scanner Scans, analyzes and detects web application vulnerabilities Application Delivery Assures availability and accelerates performance of critical web applications Secures Web Applications Scans and Detects Web Vulnerabilities Optimizes Application Delivery 18

FortiWeb Protection at all Layers ATTACKS/THREATS BOTNETS, MALICIOUS HOSTS, ANONYMOUS PROXIES, DDOS SOURCES IP REPUTATION APPLICATION LEVEL DDOS ATTACKS IMPROPER HTTP RFC KNOWN APPLICATION ATTACK TYPES VIRUSES, MALWARE, LOSS OF DATA DDOS PROTECTION PROTOCOL VALIDATION ATTACK SIGNATURES ANTIVIRUS/DLP CORRELATION UNKNOWN APPLICATION ATTACKS APPLICATION BEHAVIORAL VALIDATION 19

FortiGuard Ip Reputation Threats DDoS Phishing Botnets Anonymous Proxy access Infected source SPAM hosts IP Reputation Service Daily feed updates Automated downloads Immediate protection Visibility and reporting FortiGuard Techniques FortiGuard historical analysis Honeypots Botnet analysis Anonymous proxies Third party sources FortiGuard IP Reputation Service: Protect against automated attacks and malicious source 20

Bot Identification and Protection Enhanced Bot Identification Known search engines Bad robots (scanners, crawlers, spiders) Protection Accuracy Bypass threshold based policies (DoS, Brute force) for known search engines Bot Analysis Bot dashboard provides overview of all traffic with breakdown for bad robots and known search engines ü Analyze traffic from malicious robots, scanners, crawlers and known search engines 21

Protection Policies Application Layer HTTP request limit per source TCP connections using the same cookie HTTP requests using the same cookie Challenge Response validate whether the user is real or automated Network Layer TCP connections limit per source SYN Cookie SYN flood protection ü Analyze requests originating from different users based on different characteristics such as IP and cookie ü Sophisticated mechanism identifies real users from automated attacks 22

Intrusion Prevention FortiGuard Labs Weekly updates Automatic download Wide coverage Various categories Thousands of signatures Action rules per category Information about each signature Sample match Location where inspected Exceptions/Whitelist Create exceptions down to the signature User regex to cover more URLs ü Flexible and granular signature interface 23

FortiWeb Auto Learn Understand Application Structure Models elements from actual traffic Builds baseline based on URLs, parameters, HTTP methods Automatically Understands Real Behavior Can form fields/parameters be modified by users? What are the length and type of each form field? What characters are acceptable (min, max, average)? Is a form field required or optional? ý ý ý þ þ þ þ þ þ þ þ þ þ þ þ þ Provides Recommendations and Graphs 24

FortiWeb Auto Learn Learns the protected applications structure URLs Parameters Expected behavior Analyzes: Visits Attacks Provides automatic rules Exportable to PDF 25

FortiGuard Services FortiGuard Labs» Award-winning threat research services» Dynamic/automated updates for FortiWeb» Automatic downloads» Always up-to-date Subscription Based» Available per device» Select services that are needed» Annual renewals Security Service Application layer signatures Malicious bots Suspicious URL pattern Web vulnerability scanner updates IP Reputation Protection for automated attacks and malicious sources DDoS, Phishing, Botnet, Spam, Anonymous proxies and infected sources Antivirus Scan file uploads Regular and extended AV databases 26

Additional FortiWEB Services for the ISP

On Premise Web Application FortiWeb is configured in Reverse Proxy mode Cloud WAF! A cloud WAF solution allows customers to have an external device scan their traffic without the need to deploy any SW/HW in their environment End customer change their application s DNS entry to point to the cloud WAF which scans the traffic and forwards it to the application The solution provides each customer:» Application security» Performance acceleration (caching, compression, etc)» UI access dashboard Traffic graphs, alerts, minimal configuration Customer B! Customer A! 28

Hosted Web Application FortiWeb is configured in True Transparent Proxy mode This solution gives the ISP additional revenue by offering WAF services to its hosted applications All applications are hosted at the ISP infrastructure Managed by ISP, no UI access for end customers The solution provides each customer:» Application security» Performance acceleration (possibly)» Reports via email MSSP Site! Customer! Applications 1-N! 29

Multi-tenancy Administrative Domains Controls privileges and permissions across the organization True role based access control (RBAC) Global and per-adom settings Per ADOM logging and reporting MSSP Features Protect multiple customers with one FortiWeb appliance Allow customers to securely access their own logs and reports Per user read/write permissions ü Provides multiple logical entities in a single physical unit ü Out-of-the box Multi-tenant solution Customer 1,2,3,4..N 30

High Availability Active/Passive Failover Full configuration synchronization Seamless failover No downtime ü Use Active/Passive failover or simply sync policies across multiple data centres, regardless of location Configuration-Sync Sync FortiWeb devices across networks Allows managing policies across multiple devices from a central location Seamless integration into already existing HA/LB environments Support for DR environments FortiWeb! Disaster Recovery 31

FortiWeb for Virtual Datacenter Virtual WAF for VDC Deploy WAFs without extra hardware Dynamic expansion in VM environments Resource efficiency with uncompromised WAF functionality Virtualization Environment:» VMware ESX / ESXi / 4.0 / 4.1 / 5.0 / 5.1 / 5.5,» Microsoft Hyper-V,» Citrix XenServer 6.2» Open Source Xen 4.2 DMZ Servers / DMZ Public Zone FortiWeb Desktops / Virtual Private Appliance Virtualized Data Center 32

FortiWeb Family

FortiWeb Product Lineup Performance & Scalability FWB-1000D FWB-3000DFsx FWB-3000D FWB-4000D FWB-400C WAF < 1 Gbps 1 2 Gbps 3+ Gbps SSL Software ASIC ASIC Ports GE GE/10GE GE/10GE 34

FortiWeb Product Matrix 400C 1000D 3000D 3000DFsx 4000D WAF Throughput 100 Mbps 750 Mbps 1.5 Gbps 1.5 Gbps 4.0 Gbps Latency Sub-ms Sub-ms Sub-ms Sub-ms Sub-ms SSL Software ASIC ASIC ASIC ASIC L7 Load Balancing P P P P P L7 DoS Protection P P P P P Site Publishing/SSO P P P P P Vulnerability Scanner P P P P P Antivirus/antimalware P P P P P GE Port 4 6 6 6 8 GE Bypass 0 4 2 0 2 GE-SX Bypass 0 0 0 0 2 GE SFP 0 2 0 0 0 10GE SFP+ Bypass 0 0 0 2 2 35

FortiWeb Virtual Appliances Virtual WAF Deploy WAFs without extra hardware Dynamic expansion in VM environments Resource efficiency with uncompromised WAF functionality VMware ESX / ESXi / 4.0 / 4.1 / 5.0 / 5.1 / 5.5, Microsoft Hyper-V, Citrix XenServer 6.2, Open Source Xen 4.2 Technical Specifications FortiWeb VM01 FortiWeb VM02 FortiWeb VM04 FortiWeb VM08 vcpu Support (Max) 1 2 4 8 Memory Support (Max) Unlimited Unlimited Unlimited Unlimited Network Interface Support (Max) 4 4 4 4 Storage Support (Min / Max) 40 GB / 1TB 40 GB / 1TB 40 GB / 1TB 40 GB / 1TB 36