Protecting HTTP
HTTP Deep Packet Inspection
– Firewall That Can Clean Your Web Traffic
Often companies have to keep their Web traffic fairly open for business to run smoothly.
However, this creates the risk that intruders find their way to the internal networks through the
holes opened up for Web traffic.
StoneGate Firewall has always been capable of basic protocol validation to prevent this route
from being abused. However, until now only a full-blown Intrusion Detection/Prevention System has
been able to do more detailed inspection of connections to ensure that Web traffic truly is Web
traffic and to detect any misuse.
StoneGate Firewall 3.0 offers now the same capabilities that have so far been provided by the
IPS.
StoneGate Firewall uses fingerprinting for misuse detection. What makes it so powerful in
HTTP deep packet inspection is that not only does it have a part of the IPS functionality, but the
full system fingerprint library in its use, and the same analysis and inspection capability that
IPS has.
Benefits
- Remote offices may no longer need a separate IPS to protect the Web traffic – all they need is
the StoneGate Firewall
- Malicious activity can be cleaned up already at the firewall level - before it has time to
enter the internal networks and cause damage
- Malicious traffic is prevented from spreading from internal to external networks (partner,
extranet, Internet) and causing damage you might otherwise be liable for.