SolidLab
SolidWall WAF

SolidWall WAF

SolidWall WAF is an intelligent application-layer firewall for protecting web applications and APIs from internet threats. The solution analyzes traffic, detects and blocks attacks, controls application usage scenarios, and helps minimize the exploitation of business logic flaws.

Use cases

  • Protection against OWASP Top 10 attacks;
  • Protection of APIs and mobile applications;
  • Blocking DoS and DDoS attacks at the application level;
  • Prevention of fraud, logical attacks, bots, and brute-force attacks;
  • Protection of internal resources and user behavior analytics (UBA);
  • Blocking attacks on 0-day and 1-day vulnerabilities.

SolidWall WAF benefits

  • Fast onboarding and minimal support effort.
  • Different deployment options and pricing plans for optimal total cost of ownership.
  • Flexible tuning that takes into account the specifics of protected applications.
  • The widest possible range of usage scenarios.
  • Blocking mode with a minimal level of false positives.
  • Available as a cloud solution or deployed on the customer site.
  • Enterprise-grade scalability and fault tolerance.

Key functional features

⇄

Effective business logic analysis

SolidWall WAF is the only solution that fully reconstructs application business logic. Information about user actions and their parameters is used for fine-grained protection tuning and can be exported to other systems.

◉

Ready-made models for all aspects of application behavior

Universal application behavior models are built from the application architecture rather than specific attack types, which makes it possible to use the WAF in many scenarios and adapt it quickly to new tasks.

⋮

Effective false-positive suppression

Early suppression tools based on signature analysis and normal application behavior models make it possible to put the WAF into production quickly and reduce the probability of false positives.

🛡

Comprehensive brute-force and bot protection algorithms

Multi-layer protection against brute-force and automated attacks includes a positive security model, rate limiting, user behavior analysis, and other mechanisms that operate at different levels, including the business-logic level. Full-featured analysis of the client environment is supported.

{ }

Full-featured API protection

API Gateway functionality. Models can be created and adjusted manually or automatically, including support for data formats and interaction methods not covered by the OpenAPI standard.

▣

Interpretable machine learning

Intelligent machine-learning algorithms help minimize the resources required to tune the WAF. Training results can be reviewed and corrected by the operator.

Professional services and support

  • Design, deployment, and initial WAF configuration;
  • Fine-tuning for customer application changes and false-positive elimination;
  • Installation health monitoring, updates, and troubleshooting;
  • Retrospective event analysis, incident response, and attack investigation;
  • Brute-force and bot protection tuning, analytics reporting, and expert consulting.