Teros Unveils Secure Application Gateway

Enterprise Networks & Servers, May 2004

Teros is shipping the first application security appliance that provides unified protection for traditional Web applications and Web services. This new version of the Teros Secure Application Gateway allows organizations to safely use Web services without deploying and managing a separate security infrastructure. The new XML security capabilities are available at no additional cost on all Teros Gateways.

"Traditional security infrastructures were not designed, and as such are unable, to adequately protect Web services from attack," said Ray Wagner, research director, information security strategies at research firm Gartner. "Many enterprises are deploying Web services alongside traditional Web applications. Integrated products that enforce security policies across both types of applications hold the potential to reduce capital expenditures and deliver more consistent security."

Web services are vulnerable to many of the same threats as HTML applications, including buffer overflows, SQL injection, and denial of service attacks, and are even more attractive targets for hackers since they often connect directly to mission-critical databases and back office applications. To secure Web services, the Teros Gateway combines advanced application learning, identity theft protection and application-layer attack defenses.

Teros' adaptive learning engine learns the XML messages and data types received by applications with WSDL (Web Services Description Language) interfaces Once correct behavior is learned, the Teros Gateway recommends constraints on application inputs to prevent attackers from inserting unexpected or malicious data that could compromise the Web service.

For example, the Teros Gateway will block the submission of a script to a Web services port if that interface port is only expecting accounts numbers. By learning correct application behavior and controlling application inputs, the Teros Gateway protects against both known and unknown attacks.

The Teros Gateway delivers Deep Stream Inspection of XML traffic and provides confidentiality for Web services data using ASIC-based SSL acceleration It enables security managers to block access to any Web services operation, as well as stop malicious XML inputs to an application's WSDL interface.

www.teros.com

Copyright Publications & Communications, Inc. May 2004
Provided by ProQuest Information and Learning Company. All rights Reserved
 

BNET TalkbackShare your ideas and expertise on this topic

Please add your comment:

  1. You are currently: a Guest |
  2.  

Basic HTML tags that work in comments are: bold (<b></b>), italic (<i></i>), underline (<u></u>), and hyperlink (<a href></a)

advertisement
CXO UnpluggedSmart Business interviews on BNET

See and hear how senior level executives across the Asia Pacific are developing smart business ideas across a variety of sectors. The focus is on the future, and on how businesses need to evolve.

advertisement
  • Click Here
  • Click Here
  • Click Here
advertisement

Content provided in partnership with ProQuest