for Web Assets and APIs
Hillstone W-Series Web Application Firewall
Hillstone WAF Value Proposition
Comprehensive Web Application SecurityHillstone Web Application Firewall (WAF) provides complete security of web-based applications and APIs for enterprises and other organizations. It detects and defends against attacks at both the network layer (such as DDoS attacks, flood attacks, scan and spoof, etc.), and at the application layer (such as the OWASP Top 10 risks including injection attacks, cross site scripting (XSS) attacks, injection, etc). Hillstone WAF automatically discovers web servers and related assets and puts them under protection. With this capability, Hillstone WAF covers the entire web estate even when it scales, which helps improve operational efficiencies and deliver faster time-to-value.
Advanced API ProtectionAs the digital transformation continues to evolve, APIs play a more and more important role in application development and integration. The popularity of APIs potentially exposes additional attack surfaces, such as excessive data exposure, lack of resources and rate limiting, injection and XSS attacks among API calls, etc. Based on the schema defined in the OpenAPI files, Hillstone WAF helps validate and generate positive security model policies to detect those threats in APIs.
Improved Detection Accuracy and Efficiency with Dual EnginesHillstone WAF integrates the industry’s most innovative semantics analysis with traditional WAF detection engines. Combined with traditional rules-based detection, the semantics analysis engine helps further detect threats like SQL injection and cross site scripting, and minimizes false positives. Hillstone WAF’s recursive decoding capability also detects attacks that are obscured by multiple encoding. This dual-engine approach significantly improves the accuracy of detection and efficiency in operation.
Rich Logs for Intelligent Analysis and ReportingHillstone WAF provides administrators and operators high visibility and comprehensive report with threat analysis, traffic analysis, attack breakdown and threat control. Its log aggregation capability allows logs to be aggregated from multiple dimensions, which helps operators easily identify suspicious anomalies or find false positives from logs, and then tune the policies accordingly.
Machine-Learning-Driven Security Rule Optimization and Unknown Attack DefenseIn addition to general protection based on rules and scripts for known attacks, Hillstone WAF’s auto-learning capability helps mitigate never-before-seen exploits to protect specific applications from zero-day attacks. Its ML-based model learns from the data of normal traffic such as parameter length, cookie, HTTP methods, etc., tunes itself based on the test results as well as input from administrators, and continues updating the learning models and optimizing WAF rules as applications evolve. It significantly reduces operational overhead by eliminating the troubleshooting of false positives and manual policy tuning.
Featured Hillstone WAF Resources
Recent Blog Articles
Cybersecurity Red Teams, Blue Teams: Rivals or Allies?
September 21, 2021 | HaiDong Deng
Learn more about Hillstone Security Audit
Engage with us to learn more or see a demonstration by contacting your local authorized Hillstone Networks reseller.