Apr, 2009 : Privacyware Upgrades Web Application Firewall


📅 - IIS Web Application Firewall offers increased protection from SQL injection attacks cross-site scripting and other attack techniques.

Privacyware, a provider of web application firewall, intrusion prevention and security data analytics software, yesterday announced the release of a new version of its award-winning ThreatSentry IIS Web Application Firewall and Intrusion Prevention solution. The company claims that the updated release features an expanded knowledgebase of pre-configured filters designed to identify and block a broader range of web application threats including Cross Site Request Forgery (CSRF/XSRF), Structured Query Language (SQL) Injection, Cross-Site Scripting (XSS) and other attack techniques.

It adds that default configuration settings have also been modified to deliver improved out-of-box performance and administrative control and ensure greater overall value and ease of use. The company further states that ThreatSentry protects Microsoft IIS Web servers, Windows operating systems, and popular Web application platforms including ASP.NET, PHP, JavaScript and more from known and new threats and helps customers comply with section 6.6 of the Payment Card Industry Data Security Standard (PCI DSS).

It avers that Key ThreatSentry features include:
  • Web Application Firewall provides configurable and extensible rules-based control over HTTP/HTTPS request methods (OPTIONS, GET, POST, HEAD), URL Paths, URL Path Request Frequency, URL Query String length, and HTTP Request Headers
  • Fulfills the web application layer firewall (WAF) requirement in PCI DSS 6.6 and aids in the web application code review process by revealing vulnerabilities embedded within the software
  • Proprietary NDIS driver delivers flexible network IP blocking (featuring white list, black list and duration control) at TCP/IP and UDP layers for all ports
  • Artificial intelligence (AI)-based behavioral engine (with sensitivity control) analyzes Web traffic patterns to detect new threats and behavioral deviations
  • Compatible with IIS Lockdown, URLScan, and major third party server-side scripting platforms like ASP, ASP.NET, PHP, JSP, ColdFusion, and Perl
  • Email alert notification, compliance and security reporting, centralized management for multiple servers, Active and Passive security modes
''Our coordination with customers throughout the world continues to intensify as attacks on leading-edge as well as legacy web applications has become more frequent, severe and dynamic,'' said Privacyware Chief Executive Officer, Greg Salvato. ''The resulting enhancements within ThreatSentry include expanded and optimized coverage for system, extended and other stored procedures as well as potentially dangerous SQL functions. The default rules configuration and behavioral engine settings have also been re-calibrated to ensure more efficient and proactive out-of-box protection while limiting potential interference with the growing variety of increasingly complex web applications.''

"The IT and compliance personnel of small and mid-sized businesses must manage Web application and database threats and demonstrate compliance with the PCI Data Security Standard and other regulatory mandates just as effectively as any global enterprise, but typically with much smaller budgets," stated Salvato. "The ThreatSentry IIS Web Application Firewall not only delivers exceptional protection against an array of SQL and web application threats, but also fulfills the application layer firewall requirement specified in PCI DSS 6.6 at a very affordable price.''

Reads: 2845 | Category: General | Source: http://www.webhosting.info/news/1/privacyware-upgrades-web-application-firewall_0416092215.htm

Want to add a website news or press release ? Just do it, it's free! Use add web hosting news!