SlideShare a Scribd company logo
1 of 20
© Copyright Fortinet Inc. All rights reserved.
FortiWeb
Web Application Firewalls
Lan & Wan Solutions – Soluzioni Informatiche per Reti Locali & Geografiche
2
Scope/Definition of WAFs
 Protects web-based applications
from code-based attacks
» SQL Injection or other injection types
» Cross Site Scripting and Request Forgery
» Layer 7 DoS/DDoS attacks
» Cookie/schema poisoning
 Protects against application
vulnerabilities in custom code
and commercial platforms
 Understands/learns “normal”
behaviors and stops anomalies
» URL parameters, HTTP methods,
session IDs, cookies, schema, etc.
 Dynamic and adaptive to adjust
to new threats
Can’t a Firewall or IPS do this?
 Firewalls look for network-based attacks
 IPS Signatures detect only known
problems
» High rate of false positives
» No protection of SSL traffic
» No application or user awareness
FortiWeb WAF
Web Application
Servers
SQL Injection, XSS…
INTERNET
Web Application Firewalls
3
WAF Drivers/Challenges
 Protect current and existing
applications from code-based
vulnerabilities
 Meet PCI Compliance (5.5 and
6.6) for credit card and
healthcare data
 Address OWASP Top 10
Application Vulnerabilities
 Identify and address web
application vulnerabilities
 Website publishing for Microsoft
and other applications
 Protect against website
defacement
Who Needs it?
 Any organization that processes
credit cards and/or has PCI
requirements
 Large internal or external
applications
 Sensitive/proprietary information
 Mission-critical business
applications
Who Needs it Most?
 MSPs/Hosting Companies
 E-commerce/online services
 Retail, Food Service, Hospitality
 Financial services
 Healthcare
Web Application Firewalls
4
Emerging Requirements/Trends
 WAFs are converging other technologies
» High-end products adding web application firewall (WAF) and
traditional firewall technologies
» Low end is quickly adding high end features (WAF, scripting,
etc.)
 Business adoption increasing
» Awareness of threats and benefit of WAF increasingly
understood
» 96% of applications have been attacked in 2013
» Gartner expects over 80% of organizations will have a WAF by
2018 (60% today)
 WAF market continues to grow
» IDC 2014 market size: $1.0 billion
» 6.9% CAGR through 2017
Web Application Firewalls
5
FortiWeb – Web Application Firewalls
 6 models from 25 Mbps to 4 Gbps HTTP throughput
 Up to 6x GE and models with 2x 10GE SFP+ ports
 Included vulnerability scanning and antivirus
 Hardware and VM options
(VMware, Hyper-V and AWS)
 AWS On-demand Pricing
 Automatic behavior-based
scanning
 Auto setup/learning mode
 Layer 7 DDoS protection
 FortiGuard antivirus/IP reputation
 Transparent, reverse and non-
inline deployment options
 Central Management/ADOMs
 Advanced real-time reporting
 SSL offloading/compression
 SSO/Authentication
 Layer 7 load balancing
 NSS recommended
Complete WAF Solution for
PCI DSS Compliance
Web Application Firewalls
6
FortiWeb Benefits
 Protect custom and commercial applications with automatic usage
profiling and anomaly scanning
 Meet PCI Compliance (5.5 and 6.6) with behavior-based attack
detection and mitigation
 Protection against OWASP Top 10 Application Vulnerabilities
 Identify web application security weaknesses with vulnerability
scanning
 Website publishing with Single Sign On/Authentication
 Restore website pages from attacks with Anti-Defacement Protection
 Block botnets and attacks from known rogue and malicious sources
with FortiGuard IP Reputation
Web Application Firewalls
7
Performance&Scalability
WAF < 1 Gbps 1 – 2 Gbps 3+ Gbps
SSL Software ASIC ASIC
Ports GE GE/10GE GE/10GE
FortiWeb Product Lineup
FWB-400C
FWB-100D
FWB-3000DFsx
FWB-3000D
FWB-4000D
Web Application Firewalls
FWB-1000D
8
FortiWeb Product Matrix
100D 400C 1000D 3000D 3000DFsx 4000D
WAF Throughput 25 Mbps 100 Mbps 750 Mbps 1.5 Gbps 1.5 Gbps 4.0 Gbps
Latency Sub-ms Sub-ms Sub-ms Sub-ms Sub-ms Sub-ms
SSL Software Software ASIC ASIC ASIC ASIC
L7 Load Balancing P P P P P P
L7 DoS Protection P P P P P P
Site Publishing/SSO P P P P P P
Vulnerability
Scanner
P P P P P P
Antivirus/antimalwa
re
P P P P P P
Form Factor Desktop 1U 2U 2U 2U 2U
GE Port 4 4 6 6 6 8
GE Bypass 0 0 4 2 0 2
GE-SX Bypass 0 0 0 0 0 2
GE SFP 0 0 2 0 0 0
10GE SFP+ Bypass 0 0 0 0 2 2
ADOMs N/a 32 64 64 64 64
Web Application Firewalls
9
FortiWeb Virtual Appliances
Enterprise grade virtual WAF
 Deploy WAFs without extra hardware
 Dynamic expansion in VM environments
 Resource efficiency with uncompromised WAF functionality
 VMware ESX / ESXi / 4.0 / 4.1 / 5.0 / 5.1 / 5.5, Microsoft Hyper-V,
Citrix XenServer 6.2, Open Source Xen 4.2, AWS (BYOL/On-Demand)
Technical
Specifications FortiWeb VM01 FortiWeb VM02 FortiWeb VM04 FortiWeb VM08
vCPU Support (Max) 1 2 4 8
Memory Support (Max) Unlimited Unlimited Unlimited Unlimited
Network Interface Support (Max) 4 4 4 4
Storage Support (Min / Max) 40 GB / 1TB 40 GB / 1TB 40 GB / 1TB 40 GB / 1TB
Web Application Firewalls
10
FortiWeb Protection at all Layers
ATTACKS/THREATS
APPLICATION
IP REPUTATION
DDOS PROTECTION
PROTOCOL VALIDATION
ATTACK SIGNATURES
ANTIVIRUS/DLP
BEHAVIORAL VALIDATION
CORRELATION
BOTNETS, MALICIOUS HOSTS,
ANONYMOUS PROXIES, DDOS SOURCES
APPLICATION LEVEL
DDOS ATTACKS
IMPROPER
HTTP RFC
KNOWN APPLICATION
ATTACK TYPES
VIRUSES, MALWARE,
LOSS OF DATA
UNKNOWN APPLICATION
ATTACKS
11
Auto Setup and Protection
 Key Features
» Auto learn
» Completely transparent
» Traffic pattern monitoring
» Models application
based
on usage patterns
» Understands real
behavior
 Benefits
» No application changes
» Traffic anomalies
trigger actions
» Protects against
unknown vulnerabilities
and
zero-day attacks
Web Application Firewalls
12
 Key Features
» Scans all application
elements
» Granular crawling
capabilities
» Scheduled or on demand
» Recommendation reporting
» FortiGuard updates
 Benefits
» Automated vulnerability
reporting
» Complements WAF for PCI
DSS compliance
Vulnerability Scanning
Web Application Firewalls
13
 FortiGuard Labs
» Award-winning threat
research services
» Dynamic/automated
updates for FortiWeb
» Automatic downloads
» Always up-to-date
 Subscription Based
» Available per device
» Select services that are
needed
» Annual renewals
FortiGuard Services
Security Service
• Application layer
signatures
• Malicious bots
• Suspicious URL
pattern
• Web vulnerability
scanner updates
IP Reputation
• Protection for
automated
attacks and
malicious sources
• DDoS, Phishing,
Botnet, Spam,
Anonymous
proxies and
infected sources
Antivirus
• Scan file uploads
• Regular and
extended AV
databases
Web Application Firewalls
14
FortiWeb Recommended by NSS Labs
 SVM Published on September 30,
2014
 Test Categories
» Security: URL Parameter manipulation,
form/hidden field manipulation,
cookie/session poisoning, cross-site scripting,
directory traversal, SQL injection and padding
Oracle attacks
» Evasions: packet fragmentation reassembly,
stream segmentation, URL obfuscation
» Performance: stability, reliability and
connections per second
 Fortinet FortiWeb-1000D earned a
Recommended rating
 Strong performance with 99.85%
block rate and 15,865
connections/second
 Passed all tests for evasion
techniques and for stability and
reliability
 0.366% false positive detection rate
Web Application Firewalls
15
 Purchase price includes:
» Hardware: appliance,
mounting hardware, etc.
» VM: Downloadable software
and license
» 90 days of FortiCare 8x5 support
 FortiCare
(1, 2 and 3 year increments):
» 8x5 Enhanced
» 24x7 Comprehensive
 FortiGuard (1 year only)
» IP reputation
» FortiWeb Security Service
(signatures)
» Antivirus
 Central Management
(separate)
» Up to 10 FortiWeb appliances
» Unlimited option
 AWS
» Bring Your Own License (BYOL)
» On-demand licensing through
AWS marketplace
Pricing/Licensing
Web Application Firewalls
16
Complementary/Related Products
 FortiADC Application Delivery Controllers
» Server load balancing
» Layer 7 content-based routing and SSL offloading
 FortiDDoS DDoS Attack Mitigation Appliances
» Full layer 3, 4 and advance layer 7 DDoS attack mitigation
» 100% hardware and behavior-based detection and mitigation
 AscenLink/FortiWAN Link Load Balancers
» Advanced link load balancing up to 50 links
» Patented tunnel routing
Web Application Firewalls
17
Objection Handling
 We regularly review our applications for security flaws, we don’t need
a WAF
» A WAF can automatically protect applications without the need to constantly
manage existing older applications; frees up resources
 Only our developers know the code well enough to address security
issues
» Even the best of programmers can’t account for every possible vulnerability, and they
can’t predict unknown problems in advance
 We’ve never had a data breach and our other security measures are
good enough
» Over 96% of all web-based applications have been attacked in 2013. Chances are
you have been attacked and may not have known about it.
 I’ve never heard of FortiWeb (Fortinet) for WAF? Why should I look at a
FortiWeb WAF?
» FortiWeb has been in the WAF market for over 5 years. We’re a leader according to
NSS labs with over 99.85% security effectiveness against today’s latest web application
threats.
Web Application Firewalls
18
Qualifying Questions
 How do you protect your mission critical web-based applications from
attacks today?
» Look for opportunities to have a WAF automate manual processes like application
security patches and code changes on older applications.
 Do you regularly conduct code security reviews and if so, how often?
» If they’re not doing it, they’re most likely at risk. If they are, they are most likely spending
a lot of effort to conduct these reviews. A WAF can automate and protect better.
 Do you need to meet PCI DSS compliance standards? What were the
results of your last PCI DSS audit?
» If yes, they most likely need a WAF for PCI DSS 6.6. If not, then it’s a harder sell to
protect applications, however focus on mission critical systems, sensitive user and
proprietary data protection.
 Are you concerned about data breaches of sensitive customer or
proprietary information through your web-based applications?
» The answer should be “yes”. If so, only a WAF can protect against application specific
attacks.
Web Application Firewalls
19
Additional Resources
 White Papers
» Beyond the Firewall
» WAF or NFGW with IPS to Protect Applications
 Solution Guides/Briefs
» Fortinet Virtual Appliance Solutions (AWS)
» Protecting Against Layer 7 DoS Attacks with FortiWeb
» OWASP 2013 and FortiWeb
 Deployment Guides:
» Replacing Microsoft TMG with FortiWeb for Publishing
applications
 Positioning Guides/Responses:
» NSS Labs WAF SVM Talking Points
» NSS WAF SVM and Product Analysis Report
Web Application Firewalls
Lan & Wan Solutions
Innovare la tua Azienda. La nostra sfida
Via dell’Artigianato, 62 - 35010 Saletto di Vigodarzere (PD)
Tel. +39 049 8843198 digit 5
E-mail contacts@lanewan.it

More Related Content

What's hot

10 palo alto nat policy concepts
10 palo alto nat policy concepts10 palo alto nat policy concepts
10 palo alto nat policy conceptsMostafa El Lathy
 
13 palo alto url web filtering concept
13 palo alto url web filtering concept13 palo alto url web filtering concept
13 palo alto url web filtering conceptMostafa El Lathy
 
01- intro to firewall concepts
01- intro to firewall concepts01- intro to firewall concepts
01- intro to firewall conceptsMostafa El Lathy
 
Palo alto networks next generation firewalls
Palo alto networks next generation firewallsPalo alto networks next generation firewalls
Palo alto networks next generation firewallsCastleforce
 
3 palo alto ngfw architecture overview
3 palo alto ngfw architecture overview3 palo alto ngfw architecture overview
3 palo alto ngfw architecture overviewMostafa El Lathy
 
12 palo alto app-id concept
12 palo alto app-id concept12 palo alto app-id concept
12 palo alto app-id conceptMostafa El Lathy
 
Transform your enterprise branch with secure sd-wan
Transform your enterprise branch with secure sd-wanTransform your enterprise branch with secure sd-wan
Transform your enterprise branch with secure sd-wanDATA SECURITY SOLUTIONS
 
From Cisco ACS to ISE
From Cisco ACS to ISE From Cisco ACS to ISE
From Cisco ACS to ISE Mahzad Zahedi
 
What is SASE and How Can Partners Talk About it?
What is SASE and How Can Partners Talk About it?What is SASE and How Can Partners Talk About it?
What is SASE and How Can Partners Talk About it?QOS Networks
 
Radius Protocol
Radius ProtocolRadius Protocol
Radius ProtocolNetwax Lab
 
FortiGate_Sec_02_Security Fabric (1).pptx
FortiGate_Sec_02_Security Fabric (1).pptxFortiGate_Sec_02_Security Fabric (1).pptx
FortiGate_Sec_02_Security Fabric (1).pptxNajahIdrissiMoulayRa
 
Radware - WAF (Web Application Firewall)
Radware - WAF (Web Application Firewall)Radware - WAF (Web Application Firewall)
Radware - WAF (Web Application Firewall)Deivid Toledo
 

What's hot (20)

10 palo alto nat policy concepts
10 palo alto nat policy concepts10 palo alto nat policy concepts
10 palo alto nat policy concepts
 
13 palo alto url web filtering concept
13 palo alto url web filtering concept13 palo alto url web filtering concept
13 palo alto url web filtering concept
 
01- intro to firewall concepts
01- intro to firewall concepts01- intro to firewall concepts
01- intro to firewall concepts
 
Secure sd wan
Secure sd wanSecure sd wan
Secure sd wan
 
Palo alto networks next generation firewalls
Palo alto networks next generation firewallsPalo alto networks next generation firewalls
Palo alto networks next generation firewalls
 
SD WAN
SD WANSD WAN
SD WAN
 
3 palo alto ngfw architecture overview
3 palo alto ngfw architecture overview3 palo alto ngfw architecture overview
3 palo alto ngfw architecture overview
 
12 palo alto app-id concept
12 palo alto app-id concept12 palo alto app-id concept
12 palo alto app-id concept
 
Transform your enterprise branch with secure sd-wan
Transform your enterprise branch with secure sd-wanTransform your enterprise branch with secure sd-wan
Transform your enterprise branch with secure sd-wan
 
20 palo alto site to site
20 palo alto site to site20 palo alto site to site
20 palo alto site to site
 
From Cisco ACS to ISE
From Cisco ACS to ISE From Cisco ACS to ISE
From Cisco ACS to ISE
 
What is SASE and How Can Partners Talk About it?
What is SASE and How Can Partners Talk About it?What is SASE and How Can Partners Talk About it?
What is SASE and How Can Partners Talk About it?
 
SD-WAN Economics 101 - VeloCloud
SD-WAN Economics 101 - VeloCloudSD-WAN Economics 101 - VeloCloud
SD-WAN Economics 101 - VeloCloud
 
Understanding SASE
Understanding SASE Understanding SASE
Understanding SASE
 
Radius Protocol
Radius ProtocolRadius Protocol
Radius Protocol
 
Fortigate Training
Fortigate TrainingFortigate Training
Fortigate Training
 
FortiGate_Sec_02_Security Fabric (1).pptx
FortiGate_Sec_02_Security Fabric (1).pptxFortiGate_Sec_02_Security Fabric (1).pptx
FortiGate_Sec_02_Security Fabric (1).pptx
 
F5 DDoS Protection
F5 DDoS ProtectionF5 DDoS Protection
F5 DDoS Protection
 
Adapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear passAdapting to evolving user, security, and business needs with aruba clear pass
Adapting to evolving user, security, and business needs with aruba clear pass
 
Radware - WAF (Web Application Firewall)
Radware - WAF (Web Application Firewall)Radware - WAF (Web Application Firewall)
Radware - WAF (Web Application Firewall)
 

Viewers also liked

UTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-X
UTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-XUTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-X
UTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-Xシスコシステムズ合同会社
 
Allot Cloud/Trends H2/2014 Slideshare
Allot Cloud/Trends H2/2014 Slideshare Allot Cloud/Trends H2/2014 Slideshare
Allot Cloud/Trends H2/2014 Slideshare Allot Communications
 
Allot Content Delivery Networks (CDN)
Allot Content Delivery Networks (CDN)Allot Content Delivery Networks (CDN)
Allot Content Delivery Networks (CDN)Allot Communications
 
Bluecoat Services
Bluecoat ServicesBluecoat Services
Bluecoat ServicesChessBall
 
Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法
Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法
Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法シスコシステムズ合同会社
 
[G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料]
[G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料][G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料]
[G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料]Trainocate Japan, Ltd.
 

Viewers also liked (7)

ATP
ATPATP
ATP
 
UTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-X
UTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-XUTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-X
UTM を超えた統合セキュリティ アプライアンス Cisco ASA 5506-X/5508-X/5516-X
 
Allot Cloud/Trends H2/2014 Slideshare
Allot Cloud/Trends H2/2014 Slideshare Allot Cloud/Trends H2/2014 Slideshare
Allot Cloud/Trends H2/2014 Slideshare
 
Allot Content Delivery Networks (CDN)
Allot Content Delivery Networks (CDN)Allot Content Delivery Networks (CDN)
Allot Content Delivery Networks (CDN)
 
Bluecoat Services
Bluecoat ServicesBluecoat Services
Bluecoat Services
 
Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法
Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法
Cisco Connect Japan 2014:Cisco ASA 5500-X 次世代ファイアウォールの機能と、安定導入・運用方法
 
[G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料]
[G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料][G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料]
[G-Tech2015]次世代ファイアウォール -Cisco ASA with FirePOWER Services- によるセキュリティ対策[講演資料]
 

Similar to Forti web

Protecting web aplications with machine learning and security fabric
Protecting web aplications with machine learning and security fabricProtecting web aplications with machine learning and security fabric
Protecting web aplications with machine learning and security fabricDATA SECURITY SOLUTIONS
 
FortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptxFortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptxNuttapolMix
 
Sophos Day Belgium - What's cooking in Sophos' Network Security Group?
Sophos Day Belgium - What's cooking in Sophos' Network Security Group?Sophos Day Belgium - What's cooking in Sophos' Network Security Group?
Sophos Day Belgium - What's cooking in Sophos' Network Security Group?Sophos Benelux
 
Benefits of web application firewalls
Benefits of web application firewallsBenefits of web application firewalls
Benefits of web application firewallsEnclaveSecurity
 
Firewall seguro, proteção para aplicações
Firewall seguro, proteção para aplicaçõesFirewall seguro, proteção para aplicações
Firewall seguro, proteção para aplicaçõesCYLK IT Solutions
 
How PCI And PA DSS will change enterprise applications
How PCI And PA DSS will change enterprise applicationsHow PCI And PA DSS will change enterprise applications
How PCI And PA DSS will change enterprise applicationsBen Rothke
 
7 Ways to Stay 7 Years Ahead of the Threat
7 Ways to Stay 7 Years Ahead of the Threat7 Ways to Stay 7 Years Ahead of the Threat
7 Ways to Stay 7 Years Ahead of the ThreatIBM Security
 
Estratégia de segurança da Cisco (um diferencial para seus negócios)
Estratégia de segurança da Cisco (um diferencial para seus negócios)Estratégia de segurança da Cisco (um diferencial para seus negócios)
Estratégia de segurança da Cisco (um diferencial para seus negócios)Cisco do Brasil
 
Security Operations
Security OperationsSecurity Operations
Security Operationsankitmehta21
 
2009: Securing Applications With Web Application Firewalls and Vulnerability ...
2009: Securing Applications With Web Application Firewalls and Vulnerability ...2009: Securing Applications With Web Application Firewalls and Vulnerability ...
2009: Securing Applications With Web Application Firewalls and Vulnerability ...Neil Matatall
 
Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!Distil Networks
 
WAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rulesWAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rulesDimitris Gkizanis
 
Brocade vADC Portfolio Overview 2016
Brocade vADC Portfolio Overview 2016Brocade vADC Portfolio Overview 2016
Brocade vADC Portfolio Overview 2016Scott Sims
 
A Different Approach to Securing Your Cloud Journey
A Different Approach to Securing Your Cloud JourneyA Different Approach to Securing Your Cloud Journey
A Different Approach to Securing Your Cloud JourneyCloudflare
 
Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...
Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...
Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...Cristian Garcia G.
 
I Vi Z Profile
I Vi Z ProfileI Vi Z Profile
I Vi Z Profilekhushboo
 
Injecting Security into Web apps at Runtime Whitepaper
Injecting Security into Web apps at Runtime WhitepaperInjecting Security into Web apps at Runtime Whitepaper
Injecting Security into Web apps at Runtime WhitepaperAjin Abraham
 

Similar to Forti web (20)

Protecting web aplications with machine learning and security fabric
Protecting web aplications with machine learning and security fabricProtecting web aplications with machine learning and security fabric
Protecting web aplications with machine learning and security fabric
 
F5 Web Application Security
F5 Web Application SecurityF5 Web Application Security
F5 Web Application Security
 
Web Access Firewall
Web Access FirewallWeb Access Firewall
Web Access Firewall
 
FortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptxFortiProxy sales presentation-02022020_Vee.pptx
FortiProxy sales presentation-02022020_Vee.pptx
 
Sophos Day Belgium - What's cooking in Sophos' Network Security Group?
Sophos Day Belgium - What's cooking in Sophos' Network Security Group?Sophos Day Belgium - What's cooking in Sophos' Network Security Group?
Sophos Day Belgium - What's cooking in Sophos' Network Security Group?
 
Benefits of web application firewalls
Benefits of web application firewallsBenefits of web application firewalls
Benefits of web application firewalls
 
Firewall seguro, proteção para aplicações
Firewall seguro, proteção para aplicaçõesFirewall seguro, proteção para aplicações
Firewall seguro, proteção para aplicações
 
How PCI And PA DSS will change enterprise applications
How PCI And PA DSS will change enterprise applicationsHow PCI And PA DSS will change enterprise applications
How PCI And PA DSS will change enterprise applications
 
7 Ways to Stay 7 Years Ahead of the Threat
7 Ways to Stay 7 Years Ahead of the Threat7 Ways to Stay 7 Years Ahead of the Threat
7 Ways to Stay 7 Years Ahead of the Threat
 
Estratégia de segurança da Cisco (um diferencial para seus negócios)
Estratégia de segurança da Cisco (um diferencial para seus negócios)Estratégia de segurança da Cisco (um diferencial para seus negócios)
Estratégia de segurança da Cisco (um diferencial para seus negócios)
 
Novinky F5
Novinky F5Novinky F5
Novinky F5
 
Security Operations
Security OperationsSecurity Operations
Security Operations
 
2009: Securing Applications With Web Application Firewalls and Vulnerability ...
2009: Securing Applications With Web Application Firewalls and Vulnerability ...2009: Securing Applications With Web Application Firewalls and Vulnerability ...
2009: Securing Applications With Web Application Firewalls and Vulnerability ...
 
Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!Tune in for the Ultimate WAF Torture Test: Bots Attack!
Tune in for the Ultimate WAF Torture Test: Bots Attack!
 
WAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rulesWAFFLE - A Web Application Firewall that defies rules
WAFFLE - A Web Application Firewall that defies rules
 
Brocade vADC Portfolio Overview 2016
Brocade vADC Portfolio Overview 2016Brocade vADC Portfolio Overview 2016
Brocade vADC Portfolio Overview 2016
 
A Different Approach to Securing Your Cloud Journey
A Different Approach to Securing Your Cloud JourneyA Different Approach to Securing Your Cloud Journey
A Different Approach to Securing Your Cloud Journey
 
Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...
Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...
Porque las Amenazas avanzadas requieren de una Seguridad para Aplicaciones av...
 
I Vi Z Profile
I Vi Z ProfileI Vi Z Profile
I Vi Z Profile
 
Injecting Security into Web apps at Runtime Whitepaper
Injecting Security into Web apps at Runtime WhitepaperInjecting Security into Web apps at Runtime Whitepaper
Injecting Security into Web apps at Runtime Whitepaper
 

More from Lan & Wan Solutions (20)

CYBER THREAT ASSESSMENT
CYBER THREAT ASSESSMENTCYBER THREAT ASSESSMENT
CYBER THREAT ASSESSMENT
 
Nuova presentazione Lan & Wan Solutions Fortinet Partner
Nuova presentazione Lan & Wan Solutions Fortinet PartnerNuova presentazione Lan & Wan Solutions Fortinet Partner
Nuova presentazione Lan & Wan Solutions Fortinet Partner
 
Nuova presentazione Lan & Wan Solutions
Nuova presentazione Lan & Wan SolutionsNuova presentazione Lan & Wan Solutions
Nuova presentazione Lan & Wan Solutions
 
CTAP
CTAPCTAP
CTAP
 
Mc business solutions set
Mc business solutions setMc business solutions set
Mc business solutions set
 
Mc partner playbook
Mc partner playbookMc partner playbook
Mc partner playbook
 
160415 lan and-wan-secure-access-architecture
160415 lan and-wan-secure-access-architecture160415 lan and-wan-secure-access-architecture
160415 lan and-wan-secure-access-architecture
 
160415 lan and-wan-ctap
160415 lan and-wan-ctap160415 lan and-wan-ctap
160415 lan and-wan-ctap
 
Lan & Wan
Lan & WanLan & Wan
Lan & Wan
 
Lan & Wan
Lan & WanLan & Wan
Lan & Wan
 
Evento 15 aprile
Evento 15 aprileEvento 15 aprile
Evento 15 aprile
 
Secure Access Architecture
Secure Access ArchitectureSecure Access Architecture
Secure Access Architecture
 
CTAP
CTAPCTAP
CTAP
 
Advanced Threat Protection
Advanced Threat ProtectionAdvanced Threat Protection
Advanced Threat Protection
 
scheda tecnica smartphone zona 1.21 e zona 2.22
scheda tecnica smartphone zona 1.21 e zona 2.22scheda tecnica smartphone zona 1.21 e zona 2.22
scheda tecnica smartphone zona 1.21 e zona 2.22
 
scheda tecnica smartphone zona 1.21 e zona 2.22
scheda tecnica smartphone zona 1.21 e zona 2.22scheda tecnica smartphone zona 1.21 e zona 2.22
scheda tecnica smartphone zona 1.21 e zona 2.22
 
Scheda tecnica hspa 08
Scheda tecnica hspa 08Scheda tecnica hspa 08
Scheda tecnica hspa 08
 
Vmware
VmwareVmware
Vmware
 
Antenne filari
Antenne filariAntenne filari
Antenne filari
 
Antenne multifilari
Antenne multifilariAntenne multifilari
Antenne multifilari
 

Recently uploaded

NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...
NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...
NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...Amil baba
 
Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝
Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝
Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝soniya singh
 
如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一
如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一
如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一ga6c6bdl
 
定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一
定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一
定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一ss ss
 
Russian Call Girls Kolkata Chhaya 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls Kolkata Chhaya 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls Kolkata Chhaya 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls Kolkata Chhaya 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Call Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur EscortsCall Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur Escortsranjana rawat
 
Alambagh Call Girl 9548273370 , Call Girls Service Lucknow
Alambagh Call Girl 9548273370 , Call Girls Service LucknowAlambagh Call Girl 9548273370 , Call Girls Service Lucknow
Alambagh Call Girl 9548273370 , Call Girls Service Lucknowmakika9823
 
Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,
Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,
Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,Pooja Nehwal
 
Gaya Call Girls #9907093804 Contact Number Escorts Service Gaya
Gaya Call Girls #9907093804 Contact Number Escorts Service GayaGaya Call Girls #9907093804 Contact Number Escorts Service Gaya
Gaya Call Girls #9907093804 Contact Number Escorts Service Gayasrsj9000
 
定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一
定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一
定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一ga6c6bdl
 
Vip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Vip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best ServicesVip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Vip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best Servicesnajka9823
 
Beautiful Sapna Call Girls CP 9711199012 ☎ Call /Whatsapps
Beautiful Sapna Call Girls CP 9711199012 ☎ Call /WhatsappsBeautiful Sapna Call Girls CP 9711199012 ☎ Call /Whatsapps
Beautiful Sapna Call Girls CP 9711199012 ☎ Call /Whatsappssapnasaifi408
 
Call Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up Number
Call Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up NumberCall Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up Number
Call Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up NumberMs Riya
 
定制(USF学位证)旧金山大学毕业证成绩单原版一比一
定制(USF学位证)旧金山大学毕业证成绩单原版一比一定制(USF学位证)旧金山大学毕业证成绩单原版一比一
定制(USF学位证)旧金山大学毕业证成绩单原版一比一ss ss
 
(办理学位证)多伦多大学毕业证成绩单原版一比一
(办理学位证)多伦多大学毕业证成绩单原版一比一(办理学位证)多伦多大学毕业证成绩单原版一比一
(办理学位证)多伦多大学毕业证成绩单原版一比一C SSS
 
VIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service Saharanpur
VIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service SaharanpurVIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service Saharanpur
VIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service SaharanpurSuhani Kapoor
 
如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一
如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一
如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一ga6c6bdl
 
定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一
定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一
定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一zul5vf0pq
 
Call Girls Delhi {Rohini} 9711199012 high profile service
Call Girls Delhi {Rohini} 9711199012 high profile serviceCall Girls Delhi {Rohini} 9711199012 high profile service
Call Girls Delhi {Rohini} 9711199012 high profile servicerehmti665
 
如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一
如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一
如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一ga6c6bdl
 

Recently uploaded (20)

NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...
NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...
NO1 Qualified Best Black Magic Specialist Near Me Spiritual Healer Powerful L...
 
Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝
Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝
Call Girls in Dwarka Sub City 💯Call Us 🔝8264348440🔝
 
如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一
如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一
如何办理萨省大学毕业证(UofS毕业证)成绩单留信学历认证原版一比一
 
定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一
定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一
定制(Salford学位证)索尔福德大学毕业证成绩单原版一比一
 
Russian Call Girls Kolkata Chhaya 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls Kolkata Chhaya 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls Kolkata Chhaya 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls Kolkata Chhaya 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Call Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur EscortsCall Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur Escorts
Call Girls in Nagpur Bhavna Call 7001035870 Meet With Nagpur Escorts
 
Alambagh Call Girl 9548273370 , Call Girls Service Lucknow
Alambagh Call Girl 9548273370 , Call Girls Service LucknowAlambagh Call Girl 9548273370 , Call Girls Service Lucknow
Alambagh Call Girl 9548273370 , Call Girls Service Lucknow
 
Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,
Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,
Call Girls In Andheri East Call 9892124323 Book Hot And Sexy Girls,
 
Gaya Call Girls #9907093804 Contact Number Escorts Service Gaya
Gaya Call Girls #9907093804 Contact Number Escorts Service GayaGaya Call Girls #9907093804 Contact Number Escorts Service Gaya
Gaya Call Girls #9907093804 Contact Number Escorts Service Gaya
 
定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一
定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一
定制宾州州立大学毕业证(PSU毕业证) 成绩单留信学历认证原版一比一
 
Vip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Vip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best ServicesVip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Vip Udupi Call Girls 7001305949 WhatsApp Number 24x7 Best Services
 
Beautiful Sapna Call Girls CP 9711199012 ☎ Call /Whatsapps
Beautiful Sapna Call Girls CP 9711199012 ☎ Call /WhatsappsBeautiful Sapna Call Girls CP 9711199012 ☎ Call /Whatsapps
Beautiful Sapna Call Girls CP 9711199012 ☎ Call /Whatsapps
 
Call Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up Number
Call Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up NumberCall Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up Number
Call Girls Delhi {Rs-10000 Laxmi Nagar] 9711199012 Whats Up Number
 
定制(USF学位证)旧金山大学毕业证成绩单原版一比一
定制(USF学位证)旧金山大学毕业证成绩单原版一比一定制(USF学位证)旧金山大学毕业证成绩单原版一比一
定制(USF学位证)旧金山大学毕业证成绩单原版一比一
 
(办理学位证)多伦多大学毕业证成绩单原版一比一
(办理学位证)多伦多大学毕业证成绩单原版一比一(办理学位证)多伦多大学毕业证成绩单原版一比一
(办理学位证)多伦多大学毕业证成绩单原版一比一
 
VIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service Saharanpur
VIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service SaharanpurVIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service Saharanpur
VIP Call Girl Saharanpur Aashi 8250192130 Independent Escort Service Saharanpur
 
如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一
如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一
如何办理(UCLA毕业证书)加州大学洛杉矶分校毕业证成绩单留信学历认证原版一比一
 
定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一
定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一
定制加拿大滑铁卢大学毕业证(Waterloo毕业证书)成绩单(文凭)原版一比一
 
Call Girls Delhi {Rohini} 9711199012 high profile service
Call Girls Delhi {Rohini} 9711199012 high profile serviceCall Girls Delhi {Rohini} 9711199012 high profile service
Call Girls Delhi {Rohini} 9711199012 high profile service
 
如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一
如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一
如何办理(NUS毕业证书)新加坡国立大学毕业证成绩单留信学历认证原版一比一
 

Forti web

  • 1. © Copyright Fortinet Inc. All rights reserved. FortiWeb Web Application Firewalls Lan & Wan Solutions – Soluzioni Informatiche per Reti Locali & Geografiche
  • 2. 2 Scope/Definition of WAFs  Protects web-based applications from code-based attacks » SQL Injection or other injection types » Cross Site Scripting and Request Forgery » Layer 7 DoS/DDoS attacks » Cookie/schema poisoning  Protects against application vulnerabilities in custom code and commercial platforms  Understands/learns “normal” behaviors and stops anomalies » URL parameters, HTTP methods, session IDs, cookies, schema, etc.  Dynamic and adaptive to adjust to new threats Can’t a Firewall or IPS do this?  Firewalls look for network-based attacks  IPS Signatures detect only known problems » High rate of false positives » No protection of SSL traffic » No application or user awareness FortiWeb WAF Web Application Servers SQL Injection, XSS… INTERNET Web Application Firewalls
  • 3. 3 WAF Drivers/Challenges  Protect current and existing applications from code-based vulnerabilities  Meet PCI Compliance (5.5 and 6.6) for credit card and healthcare data  Address OWASP Top 10 Application Vulnerabilities  Identify and address web application vulnerabilities  Website publishing for Microsoft and other applications  Protect against website defacement Who Needs it?  Any organization that processes credit cards and/or has PCI requirements  Large internal or external applications  Sensitive/proprietary information  Mission-critical business applications Who Needs it Most?  MSPs/Hosting Companies  E-commerce/online services  Retail, Food Service, Hospitality  Financial services  Healthcare Web Application Firewalls
  • 4. 4 Emerging Requirements/Trends  WAFs are converging other technologies » High-end products adding web application firewall (WAF) and traditional firewall technologies » Low end is quickly adding high end features (WAF, scripting, etc.)  Business adoption increasing » Awareness of threats and benefit of WAF increasingly understood » 96% of applications have been attacked in 2013 » Gartner expects over 80% of organizations will have a WAF by 2018 (60% today)  WAF market continues to grow » IDC 2014 market size: $1.0 billion » 6.9% CAGR through 2017 Web Application Firewalls
  • 5. 5 FortiWeb – Web Application Firewalls  6 models from 25 Mbps to 4 Gbps HTTP throughput  Up to 6x GE and models with 2x 10GE SFP+ ports  Included vulnerability scanning and antivirus  Hardware and VM options (VMware, Hyper-V and AWS)  AWS On-demand Pricing  Automatic behavior-based scanning  Auto setup/learning mode  Layer 7 DDoS protection  FortiGuard antivirus/IP reputation  Transparent, reverse and non- inline deployment options  Central Management/ADOMs  Advanced real-time reporting  SSL offloading/compression  SSO/Authentication  Layer 7 load balancing  NSS recommended Complete WAF Solution for PCI DSS Compliance Web Application Firewalls
  • 6. 6 FortiWeb Benefits  Protect custom and commercial applications with automatic usage profiling and anomaly scanning  Meet PCI Compliance (5.5 and 6.6) with behavior-based attack detection and mitigation  Protection against OWASP Top 10 Application Vulnerabilities  Identify web application security weaknesses with vulnerability scanning  Website publishing with Single Sign On/Authentication  Restore website pages from attacks with Anti-Defacement Protection  Block botnets and attacks from known rogue and malicious sources with FortiGuard IP Reputation Web Application Firewalls
  • 7. 7 Performance&Scalability WAF < 1 Gbps 1 – 2 Gbps 3+ Gbps SSL Software ASIC ASIC Ports GE GE/10GE GE/10GE FortiWeb Product Lineup FWB-400C FWB-100D FWB-3000DFsx FWB-3000D FWB-4000D Web Application Firewalls FWB-1000D
  • 8. 8 FortiWeb Product Matrix 100D 400C 1000D 3000D 3000DFsx 4000D WAF Throughput 25 Mbps 100 Mbps 750 Mbps 1.5 Gbps 1.5 Gbps 4.0 Gbps Latency Sub-ms Sub-ms Sub-ms Sub-ms Sub-ms Sub-ms SSL Software Software ASIC ASIC ASIC ASIC L7 Load Balancing P P P P P P L7 DoS Protection P P P P P P Site Publishing/SSO P P P P P P Vulnerability Scanner P P P P P P Antivirus/antimalwa re P P P P P P Form Factor Desktop 1U 2U 2U 2U 2U GE Port 4 4 6 6 6 8 GE Bypass 0 0 4 2 0 2 GE-SX Bypass 0 0 0 0 0 2 GE SFP 0 0 2 0 0 0 10GE SFP+ Bypass 0 0 0 0 2 2 ADOMs N/a 32 64 64 64 64 Web Application Firewalls
  • 9. 9 FortiWeb Virtual Appliances Enterprise grade virtual WAF  Deploy WAFs without extra hardware  Dynamic expansion in VM environments  Resource efficiency with uncompromised WAF functionality  VMware ESX / ESXi / 4.0 / 4.1 / 5.0 / 5.1 / 5.5, Microsoft Hyper-V, Citrix XenServer 6.2, Open Source Xen 4.2, AWS (BYOL/On-Demand) Technical Specifications FortiWeb VM01 FortiWeb VM02 FortiWeb VM04 FortiWeb VM08 vCPU Support (Max) 1 2 4 8 Memory Support (Max) Unlimited Unlimited Unlimited Unlimited Network Interface Support (Max) 4 4 4 4 Storage Support (Min / Max) 40 GB / 1TB 40 GB / 1TB 40 GB / 1TB 40 GB / 1TB Web Application Firewalls
  • 10. 10 FortiWeb Protection at all Layers ATTACKS/THREATS APPLICATION IP REPUTATION DDOS PROTECTION PROTOCOL VALIDATION ATTACK SIGNATURES ANTIVIRUS/DLP BEHAVIORAL VALIDATION CORRELATION BOTNETS, MALICIOUS HOSTS, ANONYMOUS PROXIES, DDOS SOURCES APPLICATION LEVEL DDOS ATTACKS IMPROPER HTTP RFC KNOWN APPLICATION ATTACK TYPES VIRUSES, MALWARE, LOSS OF DATA UNKNOWN APPLICATION ATTACKS
  • 11. 11 Auto Setup and Protection  Key Features » Auto learn » Completely transparent » Traffic pattern monitoring » Models application based on usage patterns » Understands real behavior  Benefits » No application changes » Traffic anomalies trigger actions » Protects against unknown vulnerabilities and zero-day attacks Web Application Firewalls
  • 12. 12  Key Features » Scans all application elements » Granular crawling capabilities » Scheduled or on demand » Recommendation reporting » FortiGuard updates  Benefits » Automated vulnerability reporting » Complements WAF for PCI DSS compliance Vulnerability Scanning Web Application Firewalls
  • 13. 13  FortiGuard Labs » Award-winning threat research services » Dynamic/automated updates for FortiWeb » Automatic downloads » Always up-to-date  Subscription Based » Available per device » Select services that are needed » Annual renewals FortiGuard Services Security Service • Application layer signatures • Malicious bots • Suspicious URL pattern • Web vulnerability scanner updates IP Reputation • Protection for automated attacks and malicious sources • DDoS, Phishing, Botnet, Spam, Anonymous proxies and infected sources Antivirus • Scan file uploads • Regular and extended AV databases Web Application Firewalls
  • 14. 14 FortiWeb Recommended by NSS Labs  SVM Published on September 30, 2014  Test Categories » Security: URL Parameter manipulation, form/hidden field manipulation, cookie/session poisoning, cross-site scripting, directory traversal, SQL injection and padding Oracle attacks » Evasions: packet fragmentation reassembly, stream segmentation, URL obfuscation » Performance: stability, reliability and connections per second  Fortinet FortiWeb-1000D earned a Recommended rating  Strong performance with 99.85% block rate and 15,865 connections/second  Passed all tests for evasion techniques and for stability and reliability  0.366% false positive detection rate Web Application Firewalls
  • 15. 15  Purchase price includes: » Hardware: appliance, mounting hardware, etc. » VM: Downloadable software and license » 90 days of FortiCare 8x5 support  FortiCare (1, 2 and 3 year increments): » 8x5 Enhanced » 24x7 Comprehensive  FortiGuard (1 year only) » IP reputation » FortiWeb Security Service (signatures) » Antivirus  Central Management (separate) » Up to 10 FortiWeb appliances » Unlimited option  AWS » Bring Your Own License (BYOL) » On-demand licensing through AWS marketplace Pricing/Licensing Web Application Firewalls
  • 16. 16 Complementary/Related Products  FortiADC Application Delivery Controllers » Server load balancing » Layer 7 content-based routing and SSL offloading  FortiDDoS DDoS Attack Mitigation Appliances » Full layer 3, 4 and advance layer 7 DDoS attack mitigation » 100% hardware and behavior-based detection and mitigation  AscenLink/FortiWAN Link Load Balancers » Advanced link load balancing up to 50 links » Patented tunnel routing Web Application Firewalls
  • 17. 17 Objection Handling  We regularly review our applications for security flaws, we don’t need a WAF » A WAF can automatically protect applications without the need to constantly manage existing older applications; frees up resources  Only our developers know the code well enough to address security issues » Even the best of programmers can’t account for every possible vulnerability, and they can’t predict unknown problems in advance  We’ve never had a data breach and our other security measures are good enough » Over 96% of all web-based applications have been attacked in 2013. Chances are you have been attacked and may not have known about it.  I’ve never heard of FortiWeb (Fortinet) for WAF? Why should I look at a FortiWeb WAF? » FortiWeb has been in the WAF market for over 5 years. We’re a leader according to NSS labs with over 99.85% security effectiveness against today’s latest web application threats. Web Application Firewalls
  • 18. 18 Qualifying Questions  How do you protect your mission critical web-based applications from attacks today? » Look for opportunities to have a WAF automate manual processes like application security patches and code changes on older applications.  Do you regularly conduct code security reviews and if so, how often? » If they’re not doing it, they’re most likely at risk. If they are, they are most likely spending a lot of effort to conduct these reviews. A WAF can automate and protect better.  Do you need to meet PCI DSS compliance standards? What were the results of your last PCI DSS audit? » If yes, they most likely need a WAF for PCI DSS 6.6. If not, then it’s a harder sell to protect applications, however focus on mission critical systems, sensitive user and proprietary data protection.  Are you concerned about data breaches of sensitive customer or proprietary information through your web-based applications? » The answer should be “yes”. If so, only a WAF can protect against application specific attacks. Web Application Firewalls
  • 19. 19 Additional Resources  White Papers » Beyond the Firewall » WAF or NFGW with IPS to Protect Applications  Solution Guides/Briefs » Fortinet Virtual Appliance Solutions (AWS) » Protecting Against Layer 7 DoS Attacks with FortiWeb » OWASP 2013 and FortiWeb  Deployment Guides: » Replacing Microsoft TMG with FortiWeb for Publishing applications  Positioning Guides/Responses: » NSS Labs WAF SVM Talking Points » NSS WAF SVM and Product Analysis Report Web Application Firewalls
  • 20. Lan & Wan Solutions Innovare la tua Azienda. La nostra sfida Via dell’Artigianato, 62 - 35010 Saletto di Vigodarzere (PD) Tel. +39 049 8843198 digit 5 E-mail contacts@lanewan.it