|
|
 |
Application Security Manager (ASM) is a web application firewall that provides comprehensive, proactive, network and application-layer protection from generalised and targeted attacks by understanding the user interaction with the application firewall. ASM employs a positive security model ('deny all unless allowed') to permit only valid and authorised application transactions, while automatically protecting critical web applications from attacks such as Google hacking, cross-site scripting, and parameter tampering.
F5 Application Firewall Datasheet
|
Key Features
Comprehensive Web Application Security - Protects against entire classes of HTTP and HTTPS-based threats (both known and unknown) rather than guarding against a limited list of known attacks.
Hardened Appliance Protection - Protects servers from attacks and ensures that only valid responses get through.
Targeted Attack Protection - Protects scanners and other automated devices that can't defend themselves against targeted attacks because these attacks involve a malicious user seeking vulnerabilities unique to a particular session. TrafficShield detects and mitigates pattern-less exploits in real time, adding complementary protection to existing firewalls and Intrusion Detection Systems, which cannot efficiently address HTTP and HTTPS-borne threats.
Random Attack Protection - Application layer packet inspection and behavioural logic protect against counterfeit application activity, providing precise attack mitigation and granular blocking against script kiddies, known worms and vulnerabilities, requests for restricted object and file types, and other known exploits.
Security Policy Management - Automatically generates and enforces application security policies that are easy to manage, intuitive, and incredibly accurate.
Comprehensive Network Security Services - Provides a secure reverse proxy, including SSL acceleration, termination, and re-encryption to web servers, key management and failover handling, and basic network firewalling capabilities.
Web Server Protection - Hides your web infrastructure so that hackers can't tell what servers you're running. Strips out identifying operating system and web server information from message headers, conceals any HTTP error messages from users, and removes application error messages from pages sent to users while checking to make sure no server code leaks out onto web pages.
VLAN support - Delivers maximum flexibility for easier deployments.
|