Imperva: Protecting the Data that Drives Business Login|Japanese
SecureSphere SE Web Application Firewall

A Proven, Trusted Web Application Firewall for Mid-Size Enterprises

The Imperva SecureSphere Standard Edition (SE) Web Application Firewall provides market-leading Web application security for medium size enterprises. It combines superior application security with proven performance, ease-of-use, and automatic security updates demanded by medium enterprises with limited IT resources. The Imperva SecureSphere SE Web Application Firewall delivers enterprise-class security at an affordable price.

More organizations rely on Imperva to monitor and protect their critical Web applications than any other vendor. The Imperva SecureSphere SE Web Application Firewall provides your business with a practical and highly secure solution to ensure that your Web applications and data are safe.

Benefits

  • Offers enterprise-class Web Application Firewall for medium enterprises
  • Meets critical PCI compliance mandates
  • Protects confidential data from breaches and data leaks
  • Provides easy deployment with minimal configuration
  • Delivers dynamic up-to-date security protection

SecureSphere SE Web Application Firewall Features

  • Automated Application Learning – Dynamic Profiling enables SecureSphere to automatically learn application structure and usage which augments security and streamlines configuration and management.
  • Flexible Deployment – Multiple configuration options, including layer 2 bridge, proxy and non-inline monitor, enable drop-in deployment with no changes to existing applications or network.
  • Reliable Data Leak Prevention – SecureSphere inspects outbound traffic to identify potential leakage of sensitive data such as cardholder data and social security numbers.
  • Accurate Application Protection – Imperva’s unique Correlated Attack Validation technology correlates violations across security layers and over time to accurately identify the most complex attacks.
  • Ease of Monitoring and Alerting – Real-time dashboard provides high level view of system status and security events. Alerts are easily searched, sorted, and directly linked to corresponding security rules.
  • Business Relevant Reporting – SecureSphere includes reporting for specific business applications and regulatory mandates, and provides an extensive list of pre-defined and customizable Web based reports.
  • Scalable Management – SecureSphere can be deployed as a standalone appliance and can also scale to protect a cluster of Web servers. The SecureSphere SE Management Server offers a centralized configuration, monitoring, and reporting infrastructure to manage multiple SecureSphere SE WAF appliances and applications from a single console.
  • Dynamic up-to-date Security protections – SecureSphere provides real-time security updates to protect against the latest threats based on feeds from the Imperva Application Defense Center (ADC), which analyzes exploit traffic from a diversity of real Web sites and conducts primary vulnerability research to identify the latest threats.
  • Upgradeable to Enterprise Edition – SecureSphere SE has everything you need to protect your online-applications, packaged in a solution for small IT staff. To provide maximum flexibility, the SecureSphere SE appliance may be upgraded to the Enterprise Edition as customers’ needs grow.

SecureSphere SE Web Application Firewall Specifications


Specification        Description
Web Security
  • Dynamic Profile (White List security)
  • Web server & application signatures
  • HTTP RFC compliance
  • Normalization of encoded data
        See list of attacks prevented
HTTPS/SSL Inspection
  • Passive decryption or termination
  • Optional HSM for SSL key storage
Web Services Security
  • XML/SOAP profile enforcement
  • Web services signatures
  • XML protocol conformance
Content Modification
  • URL rewriting (obfuscation)
  • Cookie signing
  • Cookie encryption
  • Custom error messages
  • Error code handling
Platform Security
  • Operating system intrusion signatures
  • Known and zero-day worm security
Network Security
  • Stateful firewall
  • DoS prevention
Advanced Protection
  • Correlation rules incorporate all security elements (white list, black list) to detect complex, multi-stage attacks
Data Leak Prevention
  • Credit card number
  • PII (personally identifiable information)
  • Pattern matching
Policy/Signature Updates
  • Security updates provided weekly or immediately for critical threats
User Awareness
  • Automated Tracking of Web Application Users
Deployment Modes
  • Transparent Bridge (Layer 2)
  • Reverse Proxy and Transparent Proxy (Layer 7)
  • Non-inline sniffer
Management
  • Web User Interface (HTTP/HTTPS)
  • Command Line Interface (SSH/Console)
Administration
  • SecureSphere SE Management Server for centralized management
  • Integrated management option
Logging/Monitoring
  • SNMP
  • Syslog
  • Email
  • Integrated graphical reporting
  • Real-time dashboard
High Availability
  • IMPVHA (Active/Active, Active/Passive)
  • Fail open interfaces (bridge mode only)
  • VRRP
  • STP and RSTP