Web application and API protection
in production
SolidWall WAF protects critical web resources from external attacks and controls application use across different scenarios.
Core protection capabilities
SolidWall WAF protects against major attack types covered by the OWASP Top 10 and application logic attacks, and counters brute-force attacks and bots. Protection accounts for business processes and user behavior.
Business logic protection
Countering application logic attacks and the exploitation of business logic flaws based on how the service is intended to operate.
Full-featured API protection
API Gateway functionality supports manual or automatic model creation, import and adjustment, including data formats and interaction methods beyond the OpenAPI standard.
Brute-force and bot protection
Combining a positive security model, rate limiting and user behavior analysis to counter attacks.
Targeted Layer 7 DoS mitigation
Protection against targeted application-layer attacks designed to exhaust resources, often called smart DoS. Mitigation accounts for service-specific business logic.
Authentication and session protection
Protection against attacks on authentication and session control mechanisms, taking legitimate application interaction patterns into account.
User activity monitoring
Analysis and storage of legitimate transactions, monitoring of business process execution and user behavior analytics (UBA) help detect violations of application logic.
How SolidWall WAF works
The WAF combines models of legitimate interaction, machine learning, user behavior analysis and manual configuration to account for application specifics and maintain control over protection.
A model of legitimate interaction
SolidWall WAF builds a model of interaction between the protected application and its legitimate users.
Machine learning
Machine learning algorithms reduce the resources needed to configure the WAF and improve the likelihood of detecting attacks.
Positive security model
The model describes permitted application interactions and helps identify deviations from legitimate usage scenarios.
False positive suppression
False positive suppression helps analysts focus on significant events.
Fine-grained manual configuration
The graphical interface accounts for customer-specific business requirements, simplifies positive model configuration and gives operators control over machine learning.
Integrations and incident handling
SolidWall WAF integrates with existing information security processes and retains the data needed for investigations and reporting.
Security system integrations
Integration with SIEM, analytics and antivirus systems, as well as external systems through Syslog, SNMP, SQL, REST API and ICAP.
Investigation data
Retaining suspicious HTTP transactions and their processing results supports high-quality incident investigations and simplifies reporting.
Traffic decryption within your perimeter
When SolidWall WAF is deployed on premises, traffic is decrypted and analyzed within the organization’s perimeter.
Integration with SolidPoint DAST
SolidPoint DAST integrates with SolidWall WAF to import application endpoints from traffic. This helps discover endpoints for subsequent security assessment.
Additional services
AntiDDoS and AntiFraud services can be added to the SolidWall WAF implementation. These are optional services whose scope is discussed separately.
AntiDDoS
Add a DDoS protection service to application and API protection.
AntiFraud
Add a fraud prevention service tailored to customer needs.
Questions and answers
How does the WAF account for application business logic?
SolidWall WAF models legitimate user interactions with the application and analyzes business process execution. Manual configuration accounts for service-specific requirements and gives operators control over machine learning.
Can we protect APIs beyond the OpenAPI standard?
Yes. SolidWall WAF supports models covering data formats and interaction methods beyond the OpenAPI standard. Models can be created and adjusted manually or automatically.
Where is traffic decrypted and analyzed?
When SolidWall WAF is deployed within the organization’s perimeter, traffic is decrypted and analyzed there. This enables request inspection within the customer’s infrastructure.
Are AntiDDoS and AntiFraud included in the base implementation?
AntiDDoS and AntiFraud services are added separately; their scope and necessity are discussed with the customer. Targeted application-layer (L7) DoS mitigation is a capability of SolidWall WAF itself.
Let’s discuss protecting your applications and APIs
Tell us about your applications, APIs and security requirements. We will discuss SolidWall WAF implementation, required integrations and optional services.
Contact us