Protecting Web services
Web service is the part of a company that is often most visible to customers.
Consequently, it has a impact on the customer's opinion about the company. If even a small part of
the company's business is conducted via the Web, it becomes critical for the business.
Unfortunately, the Web is also very visible to any attackers. So, it has to be protected.
StoneGate products provide several layers of protection for Web services. The protection
starts with a firewall and segmentation and continues with deep protocol analysis.
Read more about protecting your Web services and
HTTP
deep packet inspection here.
As more and more services move to the Internet, more and more complex attacks are developed
to harm them. Denial-of-Service (DoS) attacks have become frequent annoyances for Web
administrators. With denial-of-service attacks, attackers strain an organization's network
connections and/or services either with a huge amount of useless traffic or with tailored malformed
traffic that makes resources became unavailable to legitimate users.
DoS attacks range from single packet attacks that crash servers to coordinated packet floods
from multiple hosts (DDoS). With these attacks, an attacker is able to prevent employees,
customers, partners and other interested parties from accessing essential network services.
With StoneGate Secure Connectivity Solution you are able to protect your self against these
attacks. The multi-layered protection provided by StoneGate Firewall and IPS gives comprehensive
protection against both server and connection overload.
Protecting against server overload
Traffic flood protection with StoneGate
IPS. In a network that is protected by StoneGate Secure Connectivity Solution there is an
IPS appliance inspecting the network traffic. When an attacker makes a DoS attack against the
network, StoneGate IPS detects that the network is overloaded by traffic generated by non-existent
users. IPS steps between and filters out this traffic so that business servers can stay up and
running, serving the real customers.
Balancing the load on critical servers evenly
with StoneGate Firewall. In StoneGate Secure Connectivity networks, business servers can be
clustered with a firewall load-balancing feature so that in case of a heavy network load, the load
is spread evenly to each server, holding the services up and running.
Denying access from hostile IP addresses with
StoneGate Firewall. In StoneGate Secure Connectivity networks, the administrator can deny
access from any hostile environment. When IPS alerts the firewall that there is hostile traffic on
a certain network segment, the firewall can blacklist it and thus prevent any further attacks from
this environment.
Protecting against connection overload
Separating business critical traffic with
StoneGate Firewall. In StoneGate Secure Connectivity networks, the StoneGate Multi-Link
functionality allows network administrators to dedicate separate ISP connections for
business-critical traffic. Dedicated VPN connections connect offices securely and ensure secure
information flow unaffected by any DOS attacks.
Channelling the network traffic via multiple
Internet connections with StoneGate Firewall. In order to prevent an attacker from attacking
against networks connecting Web services, StoneGate secure connectivity solution features multilink
functionality in firewall appliance. With StoneGate Multi-Link, you can use several separate IPS
connections at the same time, providing additional throughput capacity when most needed.
Guaranteed Quality of Service with StoneGate
Firewall. In case of a DOS attack, business-critical network connections can be blocked. But
with StoneGate quality of service, you can limit the bandwidth available for HTTP traffic. This way
you can guarantee that your business-critical traffic flows all the time.
"A business can come to us when it requires e-commerce and Internet trading capabilities, and
we can provide all the services they need, from consultancy to design and hosting, to get them
up-and-running on the Internet."
"This is why we required an ’always-on’ security solution. As a host we absolutely cannot let
our systems fail, because unnecessary downtime would have repercussions for all the customers that
trust us with their business."
Michael Robertson, Director, Commerce Media
This solution is built on StoneGate technology. Read more on
Firewall/VPN,
IPS and
SMC.