DefensePro User Guide
Glossary
Document ID: RDWR-DP-V0602_UG1201
337
IP interface
An IP interface in DefensePro is comprised of two components: an IP
address and an associated interface. The associated interface can be a
physical interface or a virtual interface (VLAN). IP routing is performed
between DefensePro IP interfaces, while bridging is performed within an
IP interface that contains an IP address associated with a VLAN.
DefensePro is designed to intercept HTTP requests and to redirect them
to a content inspection server farm. The first assumption in designing a
DefensePro network is that the DefensePro device resides on the path
between the clients and both the Internet and the content inspection
servers. This is required since DefensePro needs to intercept the clients'
requests going to the Internet and to manipulate the packets returning
from the content inspection servers to the clients.
Except when using local triangulation or transparent proxy, all traffic
must physically travel through the DefensePro device. This includes
traffic from the users to the Internet and from the content inspection
server farm back to the users.
If there are users statically configured to use a content inspection server,
they should be configured to the DefensePro virtual address. This address
is the access IP address for the content inspection servers. This address
is used only for statically configured users.
NHR
A Next-Hop Router (NHR) is a network element with an IP address
through which traffic is routed.
Server Cracking
Protection
Radware’s Server Cracking Protection is a behavioral server-based
technology that detects and prevents both known and unknown
application scans and brute-force attacks.
This behavioral protection is part of Radware’s DefensePro Full Spectrum
Protection Technology. The technology includes:
•
An adaptive behavioral network-based protection that mitigates
network DoS and DDoS attacks
•
Adaptive behavioral user-based protections that mitigate network
pre-attack probes and zero-day worm propagation activities
•
Stateful signature-based protections against exploitation attempts of
known application vulnerabilities.
See also Server Cracking Protection Profiles.
Server Cracking
Protection Profile
A Server Cracking Protection profile provides application level protection
that identifies excessive frequencies of error responses from various
applications. The profile initiates blocking of hacking sources, while
allowing legitimate traffic to pass through.
Application scanning and authentication brute force attempts are usually
precursors to more serious exploitation attempts. An attacker tries to
gain access to a restricted section, or to find a known vulnerability by
sending a list of legitimate-looking requests and analyzing the responses.
Both cracks and scanning attempts are characterized by a higher than
usual error responses from the application to a few specific users.
Server Protection Profile Server Protection Profiles are designed to defend from network and
application attacks targeting network servers or services, such as:
•
SYN Flood protection using SYN Cookies
•
Connection limit
•
Server Cracking
•
HTTP Page floods
Term
Definition
Содержание DefensePro 6.02
Страница 1: ...DefensePro User Guide Software Version 6 02 Document ID RDWR DP V0602_UG1201 January 2012 ...
Страница 2: ...DefensePro User Guide 2 Document ID RDWR DP V0602_UG1201 ...
Страница 20: ...DefensePro User Guide 20 Document ID RDWR DP V0602_UG1201 ...
Страница 28: ...DefensePro User Guide Table of Contents 28 Document ID RDWR DP V0602_UG1201 ...
Страница 116: ...DefensePro User Guide Device Network Configuration 116 Document ID RDWR DP V0602_UG1201 ...
Страница 256: ...DefensePro User Guide Managing Device Operations and Maintenance 256 Document ID RDWR DP V0602_UG1201 ...
Страница 274: ...DefensePro User Guide Monitoring DefensePro Devices and Interfaces 274 Document ID RDWR DP V0602_UG1201 ...
Страница 302: ...DefensePro User Guide Real Time Security Reporting 302 Document ID RDWR DP V0602_UG1201 ...
Страница 308: ...DefensePro User Guide Administering DefensePro 308 Document ID RDWR DP V0602_UG1201 ...
Страница 324: ...DefensePro User Guide Troubleshooting 324 Document ID RDWR DP V0602_UG1201 ...