adc (glsb) for hybrid cloud - the ict solution provider service.pdfradware’s waf offerings...

38
Sam Lin Country Manager/Radware Taiwan Radware 雲端 based Security ADC (GLSB) for Hybrid Cloud

Upload: others

Post on 25-May-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Sam Lin

Country Manager/Radware Taiwan

Radware 雲端 based Security 及

ADC (GLSB) for Hybrid Cloud

Page 2: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Security issues inside the cloud

Page 3: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Security cloud for public & private cloud

Page 4: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

DDoS/SSL protection needed

Page 5: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 6: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 7: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 8: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 9: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 10: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 11: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 12: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 13: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Radware’s WAF Offerings

Best-of-breed WAF (Physical or Virtual Appliance)

Cloud WAF Service

13

No risk. No latency. Out-of-path deployment with line-speed mitigation at the perimeter

Integrated with ADC. Complete application delivery protection

Easy. Fully-managed on-premise WAF Fully Managed. Fully managed, cloud based protection

Unmatched protection. Full OWASP Top-10. Zero-day web-attack protection.

Continuously Adaptive. Auto policy generation. Advanced bot detection.

Page 14: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

User need only to change cname in DNS for cloud WAF service

Page 15: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 16: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 17: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 18: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 19: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 20: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

www.reservations.com

/register/

/info/

/reserve/

App Mapping

/admin/

/config/

/hotels/

20

Page 21: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

www.reservations.com

/register/

/info/

/reserve/

App Mapping

/admin/

/config/

/hotels/

Threat Analysis

SQL Injection

CCN breach

Directory Traversal

Buffer Overflow

Spoof identity, steal user

information, data tampering

Information leakage

Gain root access control

Unexpected application behavior, system crash, full system compromise

21

Page 22: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

www.reservations.com

/register/

/info/

/reserve/

App Mapping

/admin/

/config/

/hotels/

Threat Analysis

SQL Injection

CCN breach

Directory Traversal

Buffer Overflow

Policy Generation

Prevent access to sensitive app sections

Mask CCN, SSN, etc. in responses.

Parameters inspection a

Traffic normalization & HTTP RFC validation

22

Page 23: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

www.reservations.com

/register/

/info/

/reserve/

App Mapping

/admin/

/config/

/hotels/

Threat Analysis

SQL Injection

CCN breach

Directory Traversal

Buffer Overflow

Policy Generation Policy Activation

Time to protect

Add tailored application rules

Optimize rules for best accuracy

Best Security coverage

Virtually zero false positive

23

Page 24: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

IP-Agnostic Device Fingerprinting & Tracking

Operating System

Beyond source IP for identification & blocking

Detailed device fingerprint from over 2 dozen parameters

Precise activity tracking over time

Development of Device Reputation

Provides advanced protection from

- Website Scraping

- Brute Force Attacks

- HTTP Dynamic Floods

System Fonts

Browser Plug-ins

Screen Resolution

Local IPs

Improved Bot Detection and Blocking

24

Page 25: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Robust Global Cloud Security Network

Segregate clean and attack traffic with dedicated scrubbing centers

Over 2Tbps of global mitigation capacity

25

Radware Scrubbing Centers

Radware Security Cloud

Page 26: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 27: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Global Application Deployment

Slide 27

Private Data Center PUBLIC CLOUD

GSLB

50% 50% 100 Users The Rest All traffic Proximity based distribution

Controlled application availability and QoE 24/7!

Page 28: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

What is an ADC

• Server load balancing for:

– High availability

– Scalability

– Performance optimization

WAN Datacenter

Alteon

Page 29: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Virtual ADC (vADC)

While in standard ADC resources are shared between apps,

Radware’s ADC fully isolates application resources to guarantee service-level

Physical (Memory, CPU, Storage)

Network (Network Tables, ARP tables)

Fault

Management

Optimize Normal

Operation

Page 30: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

RTT-Based Optimal Link Selection

Optimal link selection based on full-path RTT measurement

Optimize Normal

Operation

Link A: 55ms

Link B: 94ms

Link A: 55ms

Page 31: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

FastView Web Accelerator Optimize

Normal Operation

Automatically generates optimized browser/device-specific website versions

Website FastView

Page 32: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Real User Monitoring

Minimize Degradation

End-to-end transaction monitoring, as experienced by the end user: Real user time = Data Center Time + Network Time + Rendering Time

Network Time

Rendering time

Data Center Time

Page 33: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Integrated Web-Application Firewall (WAF)

Prevent Outage

Integrated WAF for protection against OWASP top 10 supporting separate policies per app

Page 34: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency
Page 35: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Streamlined Orchestration Optimize

Normal Operation

Seamless integration with Cloud Orchestration systems Via vDirect

Data Center/Cloud Ecosystems

Radware ADC Fabric

Page 36: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Alteon NG Platform Line-Up

Alteon VA

Alteon NG 6420 Alteon NG 5208 Alteon NG 8420

Alteon NFV Alteon Cloud VA

For any Size Enterprise Data Centers

Virtual

Appliances

Throughput: from 1 Mbps to 200 Gbps

Throughput: from 1 Mbps to 160 Gbps, vADCs: from 1 to 100

Alteon NG 6024

Page 37: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Radware DDoS/IPS/SSL Inspection (獨家完整,台灣最大) Security Solution

Perimeter LAN

Security Appliances (i.e. DLP,APT)

Client facing SSL handshake (server emulation)

Server facing SSL handshake (client emulation)

Prevent SSL re-negotiation Attack Prevent IPS ,high/low speed DDoS

Attack

Prevent high volume DDoS/SSl Attack and WAF service

Prevent SSL Malware intrusion and server/Link load balancing/ URL filter/WAF

Radware cloud

ISP( IPS/DDoS/WAF) cloud

綠線上四部机可連合防禦功能,單獨運做

Page 38: ADC (GLSB) for Hybrid Cloud - The ICT Solution Provider Service.pdfRadware’s WAF Offerings Best-of-breed WAF (Physical or Virtual Appliance) Cloud WAF Service 13 No risk. No latency

Thank You