VMware

  Community Feedback

2 votes

Log in to rate item

Profense Professional 2.2

Web application firewall and HTTP(S) load balancer with acceleration and automated adaptive learning

Description

Profense™ Web Application Firewall improves performance, reduces traffic cost and proactively protects web applications and servers against attacks from malicious hackers and worms.

Profense™ Web Application Firewall is implemented in the network as a filtering gateway which validates all requests to the web systems. Main features of Profense™ are:

WEB APPLICATION FIREWALL

Adaptive learning with instant protection
Profense™ Professional offers Auto mode using a combination of positive and negative policy rules with adaptive learning of changes in the web applications. The Auto mode provides instant protection which improves as Profense learns the web applications and consequently can create positive policy rules for critical application components.

Automated application profiling
Profense™ Professional includes the automated application profiling, or learning, engine which allows for completely automated policy building.

Positive security model
Profense™ is based on the positive security model. It determines allowable requests, and inputs and disallows everything else. This approach provides protection against unknown threats, simply because they are not in the white-list and thus are disallowed.

The working basis of the positive security model is that everything is forbidden unless explicitly allowed. In the context of Profense™ this implies that only allowed requests are forwarded to the web system - that is: requests for web pages, applications, parameters etc. which you allow. This positive security approach is proactive because you base your protection on known information, the business content you want your web system to make available, not attack signatures and other potentially unknown information.

Negative security model
In Profense™ Professional the negative security model - signatures matching known attacks - can be used in combination with positive policy rules. For example it is possible to specify (or learn) strict positive input validation rules for certain critical application components, like login.php or payment.jsp, and use more general negative signatures for the remaining part of the web site.

Proactive protection
Because of Profense™'s positive security model it stops exploits of vulnerabilities and weaknesses without dependence on signatures. By building an access control list based on a finite amount of information, the business content of the web system, Profense™ effectively blocks attacks from hackers and worms.

In other words: Profense™ does not identify attacks, it determines if a request is allowed based on a white-list. If a request is not in the list it is treated as if it was an attack. This means that Profense™ also protects from attacks targeting unpublished vulnerabilities.

Application layer firewall or web application firewall?
The Payment Card Industry Data Security Standard ver. 1.1 requires that all web facing applications are protected against known attacks either by installing an application layer firewall or by having all custom application code reviewed by application security specialists.

If your company is affected, or inspired, by the PCI DSS requirements and you choose to go for the application layer firewall solution you will need an application layer firewall which is capable of protecting web applications. A web application firewall will do the job as it is a specialization of an application layer firewall.

LOAD BALANCING

The Profense™ Load Balancer module enables scalability and acceleration of even complex SSL-enabled web applications.

Session persistence
Session persistence is achieved through insertion of a cookie tracking the session.

When the Profense™ Load Balancer is configured in an active/active cluster (is load balanced itself) the session persistence is independent of the cluster node handling the request.

Guaranteed secure persistence
Profense™ Load Balancer offers guaranteed SSL session persistence by decrypting the SSL content.

In this way the client is guaranteed a secure persistent browsing experience without loss of state information.

HTTP and HTTPS request switching
As SSL-connections are terminated by Profense™ it works equally well with HTTP and HTTPS.

Optionally requests from clients can be re-encrypted before being forwarding to back-end servers.

WEB ACCELERATION

Caching
Caching of static documents improves performance by 300 - 500%.

Documents that can be cached, are locally stored by Profense™. Any further requests for documents found in the cache, are automatically delivered to clients directly from Profense™. Therefore, the back-end web servers can focus on delivering dynamic content with improved response times to clients, without the overhead of delivering static content like images, PDF documents, static HTML documents, style-sheets and others.

HTTP compression
Dynamic compression of transmission data reduces bandwidth usage by 30 - 60% and increases transfer rate by 50 - 100%.

HTTP compression reduces the transfer volume of static and dynamically generated web pages to approximately 1/3 of their original size proportionally speeds up the load time performance. This results in reduced traffic costs and in a better experience for the web site visitors.

SSL acceleration
Profense™ has the ability to terminate HTTPS (SSL) based connections and requests from clients before forwarding them as HTTP non-SSL) to back-end servers.

This off-loads the back-end web servers from expensive SSL calculations thus allowing them to focus on faster content delivery to clients.

TCP connection off-loading
When forwarding legitimate requests from clients to back-end web servers, Profense™ will reuse socket connections already established with the back-end web server.

This gives a performance increase since back-end servers don't waste resources on establishing new and tearing down old socket connections.

Last updated: 05/14/2008

Operating system: OpenBSD 4.1

Applications installed:
Profense web application firewall

VMware Tools installed: No

Size: 111 MB
Torrent available: No
(What is BitTorrent?)

Primary account
Username: admin
Password: admin123

Memory allocated: 256 MB

License: Commercial

Submitted by: jgercke


Download link provided by the submitter, not VMware. Report broken downloads here.


« BACK...