posted on Friday, November 20, 2009 7:48 AM
With the BIG-IP v10.1 announcement, F5 continues to address existing and emerging web security threats, such as PCI Compliance and Web Scraping along with helping IT administrators understand Web Security threats.
SANS reports that 80% of vulnerabilities are in web apps and 60% of the attack vectors are web based. PCI compliance is the main driver for customers to deploy a Web Application Firewall yet compliance can still be difficult for some to achieve. PCI will be making some regulatory changes to update PCI standards come summer 2010 so it will continue to be one of the top IT challenges. Web Scraping, which has gotten a lot of press lately, can involve automated bots that scan your site to steal proprietary data or intellectual property. The terms of use of many web properties prohibit Web Scraping but enforceability is difficult. Finally, with all the various attacks emerging, IT needs a way to understand the threats to be able to properly address them.
The enhancements in BIG-IP ASM (Application Security Manager) v10.1 to help you with today’s Web Security issues.
PCI Compliance: BIG-IP ASM now includes a nifty PCI Compliance Report. The PCI Compliance Report lists each security measure required to comply with PCI-DSS 1.2, and shows, at a glance, how each item that is listed in the report compares to the PCI security criteria.
Web Scraping: Out of the box, BIG-IP ASM offers better protection against automated scanners and bots that are out to steal your intellectual property. In order to mitigate web scraping (web data extraction) on the web sites it defends, BIG-IP ASM attempts to determine whether a web client source is human, if the web site is being scraped and can block those requests. This can quickly eliminate any automated programs designed to ‘lift’ your content while legitimate users see data. Scrapers are remediated along with comprehensive reporting on scraping attacks.
Attack Expert System: Is an Online dictionary for help. Since application security can be challenging and IT needs to understand the both the violations and attack types, the Attack Expert System provides knowledge, testing and reporting of attacks and policies. Every attack is explained and every violation includes detailed description of the exact check that ASM performs allowing for fast mitigation and easy management.
L7 attacks are hackers favorites and protecting web applications is a challenge within many organizations. BIG-IP ASM protects Web applications and provides easy configuration options providing deep application visibility & reporting and with 10.1, compliance and protection from Web Security issues just got easier.
Related Resources