Imperva: Protecting the Data that Drives Business Blog|Login|中文Deutsche日本語
Web Application Security

Monitor and Protect Critical Web Applications

SecureSphere Web Security Imperva Web Application Security solutions protect Web applications from online attacks. Imperva solutions continuously adapt to evolving threats and enable security professionals, network managers, and application developers to mitigate the risk of a data breach and address compliance requirements such as PCI 6.6.

Key Capabilities


  • Dynamically learns legitimate Web application usage
  • Fortifies Web defenses with research-driven intelligence on current threats
  • Alerts or blocks requests that:
    • Deviate from normal application and data usage
    • Attempt to exploit known and unknown vulnerabilities
    • Originate from malicious or fraudulent sources
    • Indicate a sophisticated, multi-stage attack
  • Virtually patches application vulnerabilities through integration with Web application vulnerability scanners, reducing the window of exposure and impact of ad-hoc application fixes
  • Supports transparent, drop-in deployment
  • Cloud-based services simplify Web application security and prevent DDoS attacks

Web Application Security Products


SecureSphere Web Application Firewall

The market-leading SecureSphere Web Application Firewall delivers automated protection against current application attacks, including SQL injection, XSS, and CSRF. SecureSphere combines automated application learning with up-to-date protection polices and signatures from the Imperva Application Defense Center to accurately identify and stop attacks. Granular correlation rules, reputation-based security, and a powerful reporting framework complete SecureSphere's superior multi-layer protection. With multi-gigabit inline and non-inline configuration options, SecureSphere offers drop-in deployment and ultra high performance, meeting the most demanding data center requirements.

ThreatRadar Reputation Services

As an optional subscription for the SecureSphere Web Application Firewall, ThreatRadar Reputation Services protect applications against large-scale automated attacks. Reputation Services enable timely, real-world protection from known attack sources, such as malicious IP addresses and phishing URLs, and identifies source reputation and geographic location for forensics. By transmitting attack source feeds in near real time to SecureSphere WAFs, Reputation Services can quickly and accurately stop malicious users before an attack can be launched.

ThreatRadar Fraud Prevention

ThreatRadar Fraud Prevention empowers organizations to rapidly provision and manage fraud detection and centrally enforce fraud security policies. As an add-on service for the SecureSphere Web Application Firewall, ThreatRadar Fraud Prevention can integrate with leading Web fraud solutions to transparently identify and stop fraudulent transactions. Fraud Prevention also offers advanced monitoring and reporting capabilities and granular policy control, with the ability to alert of block high risk transactions, redirect users, or integrate with a SIEM, fraud management, or ticketing system.

SecureSphere Web Application Firewall and ThreatRadar are part of the SecureSphere solution which extends end-to-end protection to web applications, databases, and files.

Imperva Incapsula

Imperva Incapsula is an easy and affordable service that integrates three effective web solutions –a Web Application Firewall (WAF), a DDoS mitigation service, and a content delivery network (CDN) — into a single cloud-based service. Imperva Incapsula ensures that malicious traffic such as DDoS attacks, Web application attacks and bad bots are removed before reaching protected Websites, and legitimate traffic is accelerated – creating a more secure, more enjoyable experience for Website visitors. Provisioned via a simple DNS change, Imperva Incapsula requires no hardware or software installation and no code changes, allowing companies without dedicated security or IT staff to benefit from an enterprise grade web security solution.