Our Hotline: + 852 352 60626
  English | 简体中文

Home Why Nexusguard Resources Contact Us
Loading
SOLUTIONS
Introduction
ClearTraffic >
ClearDDoS
ClearWeb
ClearWatch
Professional
Services
Home / Solutions / ClearTraffic / ClearWeb
ClearWeb

Nexusguard ClearWeb is a cloud-based Web Application Firewall (WAF) solution which offers different-size online content providers leading web defense technology, performance and simplicity by routing client traffic through data centers on multiple continents. Our resilient BGP core networks will ensure that clients get the best routes with low response latency based on the nearest reach to which clients are geo-located. Arranging hosting with our managed hosting partners will also derive additional performance.

ClearWeb is backed by a team of multi-domain certified professionals who manages a 365x7x24 security operations center (SOC) to monitor our clients’ online content. The SOC is trained to react and response to threats that are alerted by the web application firewall.

Industry-Leading Web Application Firewall (WAF)

ClearWeb protects multiple online content providers from current and future security threats by partnering with leading hardware web application firewall provider; Imperva. Powered by Imperva's SecureSphere which is certified by ICSA Labs, ClearWeb provides ironclad protection against the OWASP Top Ten, including SQL injection, XSS and CSRF, and also addresses PCI 6.6.

Automated Learning of Applications and User Behavior
Research-Driven Security Policies
Virtual Patching through vulnerability scanner integration.
Network and Platform Attack Protection
Granular Correlation Policies reduce false positives.
Customisable reports for compliance and forensics.
Industry-leading best in class web security cloud.
Fully addresses PCI6.6.

Automated Learning of Applications and User Behavior
A WAF must understand application structure, elements and expected user behaviors in order to accurately detect attacks. Imperva's patented Dynamic Profiling technology automates this process by profiling all application elements and building a baseline or “white list” of acceptable user behavior. It also automatically incorporates valid application changes into the application profile over time.

Research-Driven Security Policies
Developed by Nexusguard’s network security research professionals and Imperva Application Defense Center (ADC), ClearWeb offers the most complete set of application signatures and policies available, as well as DDoS attacks’ information data. The Nexusguard security operations centers have the most up-to-date attacking IP addresses from botnets all over the world and can be used to correlate with data from Imperva’s WAF to provide a total solution for end-to-end web security. The Imperva ADC investigates vulnerabilities reported by Bugtraq, CVE®, Snort®, and other underground forums and performs primary research to deliver the most up-to-date and comprehensive Web attack protection available.

Virtual Patching Through Vulnerability Scanner Integration
For immediate patching of application vulnerabilities, SecureSphere can import assessment results from WhiteHat, IBM, Cenzic, NT OBJECTives, Qualys, and others, before creating custom policies to block known vulnerabilities. Virtual patching reduces the window of exposure and the cost of emergency fixes and test cycles.

Network and Platform Attack Protection
ClearWeb protects web applications and underlying infrastructure by detecting application, web services, server, and network attacks. With over 6,500 signatures that are continuously updated by the Imperva ADC, ClearWeb fortifies all application layers against online threats. HTTP protocol validation prevents protocol exploits and evasion techniques. Flexible, rapidly-updated defenses allows ClearWeb to protect Web 2.0 applications and XML without requiring any application changes.

Granular Correlation Policies Reduce False Positives
ClearWeb distinguishes attacks from unusual, but legitimate, behavior by correlating web requests across security layers and over time. This Correlated Attack Validation examines multiple attributes such as HTTP protocol conformance, profile violations, signatures, special characters, and user reputation, to accurately alert on or block attacks with the lowest rate of false positives in the industry.

Customizable Reports for Compliance and Forensics
ClearWeb will be able to provide a rich statistics report for customers to analyze and understand the daily threats surrounding their online presence. A read-only dashboard login will be provided to all customers to view real-time threats mitigated by ClearWeb. ClearWeb’s monitoring and reporting framework provides instant visibility into security, compliance, and content delivery concerns.

Nexusguard ClearWeb delivers leading web defense technology to enterprises of all sizes and needs in a seemingly simple and yet effective way. Our resilient, low latency core BGP networks route client traffic through globally distributed Nexusguard Centers where our round-the-clock 24/7 Security Operations Centers (SOC) and teams of SecureSphere certified professionals are ever alert and responsive to handle any threats that arise.



Capitalizing on Nexusguard’s core BGP networks, clients can choose from 3 flexible deployment methods best suited to their infrastructure.

GRE Tunnel
Nexusguard Tunnel solution uses GRE to create a tunnel or virtual transport to connect Nexusguard with client infrastructure. BGP is then used inside the tunnel to exchange routing information. Tunnel solution is flexible and transparent, without any modification of client data using Network Address Translation or other methods. Nexusguard Tunnel solution is stable and reduces the risk of client’s real IP being attacked.

Direct Circuits
Dedicated Circuit creates a direct physical connection between Nexusguard and the client for discerning customers who demand the highest level of protection. Although costlier than the other two options, the client enjoys dedicated true out-of-band connection for optimal security and reliability.

Proxy Network
Proxy Solution clients will redirect their traffic to Nexusguard scrubbing centers by changing the DNS on their domain record to the Virtual IPs provided. Nexusguard will work with customers to create and secure a backend channel to prevent further direct attacks.






Copyright © 2011 Nexusguard Limited. All rights reserved.
Best viewed with Internet Explorer 8+ or Mozilla Firefox 3+ or Google Chrome 12+

HOME
Corporate News
Customer Testimonials

ABOUT US
Introduction
Career
Our Clients
Partners
INTERNET
THREATS

DDoS
Web Attacks
Trends

SOLUTIONS
ClearTraffic
ClearWatch
Professional
Services

WHY
NEXUSGUARD


RESOURCES
Brochures
Videos

LOG-IN
Partners
Customers
CONTACT US


ISO 27001 Accredited Company
More >
Distinguished Recipient of Hong Kong’s Most Valuable Companies Award 2010
More >