|
Traditionally, security has been considered a network issue,
where system administrators lock down host computers through a
network firewall. While a typical network firewall can help
restrict traffic to HTTP and HTTPS, this traffic can contain
command exploits leveraging vulnerabilities in the Web
application itself that can result in data leakage, site
defacement and other attacks by hackers that compromise both the
privacy and integrity of vital data. Businesses of all sizes
that operate their own Web applications should ensure that their
Web sites are protected against application vulnerabilities.
The Barracuda Web Site Firewall provides complete protection of
Web applications and is designed to enforce policies for both
internal and external data security standards, such as Payment
Card Industry Data Security Standard (PCI DSS). At the same time
the Barracuda Web Site Firewall 460 and higher models feature a
comprehensive set of application delivery capabilities designed
to improve the performance, scalability and manageability of
today’s most demanding data center infrastructures.
Comprehensive Web Site Protection:
The Barracuda Web Site Firewall proxies all of your Web site
traffic, providing complete protection in front of your Web
sites. Capabilities include:
- HTTP protocol compliance. At a basic level, the
Barracuda Web Site Firewall verifies that all inbound
requests comply with the HTTP specification. For example,
inbound requests with more than one Content-Length header
are typically the basis of HTTP request smuggling attacks;
therefore they are illegal according to the HTTP
specification and are blocked automatically.
- Protection against common, high-visibility attacks.
Hackers can take advantage of vulnerabilities in your online
Web forms to attack your applications. The Barracuda Web
Site Firewall protects your Web applications against SQL
injections, OS command injections and cross-site scripting
attacks.
- Protection against attacks based on session state.
The Barracuda Web Site Firewall protects your Web
applications against any attacks based on session state,
such as forms tampering or cookie tampering.
- Outbound data theft protection. In addition to
inspecting the request traffic, the Barracuda Web Site
Firewall also inspects all outbound packets for any data
pattern expressible as a UNIX-style regular expression.
Built-in policies protect all major credit cards and U.S.
Social Security number patterns and new data patterns can be
added at any time. Inspection for outbound leakage of these
patterns can be applied to security policy on-the-fly.
- Web site cloaking. To prevent hackers from doing
reconnaissance on your Web infrastructure, the Barracuda Web
Site Firewall automatically strips identifying banners of
Web server software and version numbers out of all
transactions.
- Anti-crawling. While some Web crawlers, such as
search engines are often desirable, you may wish to prevent
all other users from downloading your entire site. The
Barracuda Web Site Firewall can easily identify and allow
legitimate crawlers while blocking more malicious ones.
- Fine-grained control. The Barracuda Web Site
Firewall features automatic fine-grain rules creation based
on both HTTP requests and responses down to the level of
individual HTML elements.
- Application denial of service (DoS) protection.
By validating input limits for online form fields, Web
applications and sites are protected against the SQL
injections, OS command injections or form field-based
attacks. Fine-grain control on all points prevents hackers
from instigating these common attacks.
Application Access Control:
The Barracuda Web Site Firewall implements a single point for
policy enforcement and control, which includes authentication to
ensure that users are known, access control policy for resources
and protection against data leakage. Capabilities include:
- PKI support. By providing a full PKI
infrastructure, the Barracuda Web Site Firewall can act as a
Certificate Authority, including participating in a
certificate trust chain.
- Cookie tampering. The Barracuda Web Site Firewall
fully terminates and proxies every connection to insulate
each unique user session from exposure and can stamp or
encrypt the session cookies. Also included to prevent cookie
tampering is the ability to ensure that all hidden or
read-only form fields are not changed by the user.
Application Delivery and Acceleration:
In addition to the comprehensive security benefits of the
Barracuda Web Site Firewall, there are also additional
operational capabilities available in the Barracuda Web Site
Firewall. Capabilities include:
- SSL offloading. The Barracuda Web Site Firewall
includes SSL offloading, streamlining the encryption and
decryption of SSL traffic to quickly process secure online
transactions without additional burden on any servers.
- SSL acceleration. The Barracuda Web Site Firewall
includes hardware-based SSL acceleration, offloading
back-end servers from the computational burdens of
encrypting and decrypting secure Web traffic.
- Load balancing. The Barracuda Web Site Firewall
includes integrated load balancing capabilities to
distribute traffic among multiple back-end servers. It
supports both Layer 4 and Layer 7 cookie persistence and
includes support for Layer 7 content switching based on URL
pattern, parameter or HTTP header fields.
- High Availability. When inline in Bridge-path,
the Ethernet Hard Bypass ensures reliable application
delivery even with a single Barracuda Web Site Firewall. For
Web applications with stringent security requirements, the
Barracuda Web Site Firewall may be installed in a redundant
pair configuration, providing real-time application state
replication so that security and user sessions will not be
compromised during a failover event.
Logging, Monitoring and Reporting:
The Barracuda Web Site Firewall features advanced
capabilities to provide immediate feedback to the operations
team that deploy, manage and secure mission critical
applications. Capabilities include:
- Comprehensive logging. The Barracuda Web Site
Firewall maintains a rich set of logs on the appliance,
including system activity, Web Firewall activity, Web
services activity, network firewall activity and traditional
Web logs.
- PCI reports. The Barracuda Web Site Firewall
provides an easy-to-read snapshot of common application
attacks, critical for securing credit card important and
providing compliance to PCI DSS requirements.
- Syslog support. The Barracuda Web Site Firewall
forwards logs to a syslog server for centralized and
persistent storage or analysis by a third party tool.
|