Effectively secure critical web resources against external attacks and gain complete control over application usage in the allowed scenarios with the cloud Qrator Web Application Firewall.
Qrator Web Application Firewall
Qrator.WAF is an advanced next-generation tool that helps to prevent a wide range of threats to web applications during their operation.
A high level of protection against both simple and complex targeted attacks is achieved by using the most detailed models of the protected application along with signature-based and behavioral anomaly detection methods.
The distributed infrastructure of WAF filtering nodes within the perimeter of the Qrator Labs network allows you to protect even the most heavily loaded applications with minimal delay and guaranteed service availability.
Why web applications have to be protected
For many organizations, web applications are an important part of their business processes and they provide key competitive advantages.
They are a weak link in the perimeter of the organisation and the main target of attackers.
Web applications are subject to various threats, such as theft of confidential data, fraud, attacks on the web users.
Advantages of Qrator.WAF
Provided as a distributed cloud solution.
Fast connection.
Charging only for the actually used bandwidth to ensure the optimal cost of ownership.
A greater set of usage scenarios compared to similar solutions.
Flexible configuration taking into account features of protected applications.
Operation in the lock mode with minimal false positives.
A wide range of professional services from the solution developer.
Unique functional features
1. High level of protection
A high level of protection against both simple and complex targeted attacks is achieved by using the most detailed models of the protected application along with signature-based and semantic anomaly detection methods.
2. Effective prevention of false positives
A mechanism of early suppression of false positives minimizes their influence on decision-making. It makes it possible for a WAF operator to focus on significant events.
3. Unique functions of business logic analysis
Defining users, their actions in the application, action parameters, and data, as well as sequences (chains) of logical actions. This information can be used to suppress false positives and create a positive application model, or it can be exported to other systems for further analysis.
4. Specific machine learning algorithms
They optimize WAF performance, detect false positives, automatically build application models, and effectively use the solution in the active development cycle (SDLC).
Main use cases
Protection against major classes of web threats, including OWASP Top 10.
Protection against brute force attacks.
Protection against attacks on identification and authorization mechanisms.
API security.
Corporate service security.
Security mechanisms
Basic security mechanisms
HTTP protocol validation (request types, headers, and their parameters, etc.).
Automatic filtering of static resources: a separate mode for processing static resources (provides ease of data analysis in the control and monitoring subsystem).
Analysis of requests and responses using signature analysis (including those that detect OWASP Top 10 attacks).
The mechanism of «black» and «white» lists for basic types of sources (IP address, URLs).
Blocking sources when multiple anomalies are detected in the requests.
Enhanced security capabilities
Limiting the rate of requests from one source (Rate Limiting) for the application as a whole.
Automatic detection of the performed logical actions and checking its parameters for compliance with the predetermined patterns.
Controlling sequences of logical actions.
Success measurement of the performed actions based on the analysis of responses, including nested data.
Defining sources that are arbitrary parameters of logical actions that characterize the request source (IP address, session ID, user name, certain cookie, etc.).
Controlling users and sessions, which define the key session parameters and the logical actions that are used as a framework to set, monitor, and disable these parameters.
Controlling user authorization at the level of sessions and performed logical actions.
Controlling the rate of requests to individual logical actions depending on the parameters of the request source and other parameters (Rate Limiting).
Customers are not required to have special expertise to make changes to the architecture of the protected application and configure cloud WAF rules.
We provide access to a ready-made solution based on the customer's wishes and provide round-the-clock monitoring of incidents in your personal account.
There is a separate WAF section in the customer account, where the following features are available:
EVENTS is a flexible tool for analyzing detected security events, grouped by type and threat level, with an option to view all the details of each individual transaction. It is also possible to manually suppress a false positive when a false positive lock is detected in the transactions.
TRANSACTIONS is a section where all transactions of the protected application are stored, offering the possibility to flexibly search for requests using various parameters.Monitoring interface: TRANSACTIONS
OVERVIEW is a dashboard with different metrics of the traffic of the protected web applications (response code, locks, delay, sessions, hostility).Monitoring interface: OVERVIEW
Qrator Labs uses cookies to improve your experience, deliver personalized content and analyze
our traffic. By clicking
“Accept All” you agree to the storing of cookies on your device to
enhance website navigation and analyze usage, assisting in our marketing efforts and improving
user experience. You may modify your cookies settings at any time, as explained in our
Cookie notice.
Cookies Preference Center
Strictly Necessary Cookies
Always Active
These cookies are necessary for the website to function and cannot be switched
off in our systems. They are usually only set in response to actions made by
you which amount to a request for services, such as setting your privacy
preferences, logging in or filling in forms. You can set your browser to block
or alert you about these cookies, but some parts of the site will not then
work. These cookies do not store any personally identifiable information.
Detailed information about this category of cookies can be found in the Cookie
Policy.
Performance/Analytics Cookies
These cookies allow us to count visits and traffic sources so we can measure
and improve the performance of our site. They help us to know which pages are
the most and least popular and see how visitors move around the site. All
information these cookies collect is aggregated and therefore anonymous. If you
do not allow these cookies we will not know when you have visited our site and
will not be able to monitor its performance. Detailed information about this
category of cookies can be found in the Cookie Policy.
Targeting/Marketing Cookies
These cookies may be set through our site by our advertising partners. They
may be used by those companies to build a profile of your interests and show
you relevant adverts on other sites. They do not store directly personal
information but are based on uniquely identifying your browser and internet
device. If you do not allow these cookies, you will experience less targeted
advertising. You may opt out of Targeting/Marketing cookies through the "Cookie
settings" button. Detailed information about this category of cookies can be
found in the Cookie Policy.
Functionality Cookies
These cookies enable the Website to provide enhanced functionality and
personalization. Company sets some functionality cookies, while third
party providers whose services Qrator Labs added to the website set the rest
of these cookies. If you do not allow functionality cookies, then services
relying on functionality cookies may not function properly.