The Barracuda Web Application Firewall combines a reverse-proxy security architecture with application acceleration. SMEs and other enterprises looking for a good-enough WAF at a decent price point should consider this product, along with those seeking support for public cloud platforms.
The Barracuda Web Application Firewall can deal with complex
threats with inspection capabilities that don't affect throughput. It combines
a reverse-proxy security architecture with application acceleration. Features
include web application security, API security, mobile application security,
app backend security, application acceleration and delivery, and identity and
access control. The company offers a series of appliances for SMEs through
large enterprises. The vendor delivers its Web Application Firewall line in
physical or virtual appliances. It is also available on the Microsoft Azure,
AWS and VMware vCloud Air platforms.
Barracuda WAF Features Rated
Security:
Barracuda WAF protects applications from the attacks that
are categorized by OWASP, as well as additional attacks such as DDoS, Slow
Client, session hijacking, and XML/SOAP-based attacks. This is applicable to
both HTTP and HTTPS application traffic. Security Policies define matching
criteria for requests and specify what actions to take when a request match.
The company reports
190,000 transactions and 70,000 connections per second, as well as 2.8 million
concurrent connections and throughput of 10 Gbps for the highest end model.
Testing by Miercom, a third party testing organization, achieved the numbers
claimed in the hardware datasheet. Miercom also said the WAF detected 100% of
cross-site scripting, SQL injection, system command injection and file
inclusion vulnerabilities; and achieved HTTP performance of 7.6 Gbps throughput
(this was not for its highest end model).
Implementation
The average time to
onboard an application in passive security enforcement is two minutes. The time
taken to fine-tune the security policy depends on the complexity of the
application but on average is less than one hour. Miercom tests noted the WAF
can be deployed in one hour from unboxing to full operation.
No comments:
Post a Comment