Mykonos Web Security
How it works | Features | Tech Specs | How to Deploy | Case Study | Datasheet | Request Demo
Frequently Asked Questions
Are you an appliance or software product?
We are a software company and Mykonos Web Security is a software product. Mykonos Web Security is deployed wherever your web applications live. They can deployed in three ways: as software on your hardware, or as a virtual machine, or up in the cloud.
Are you a Web application firewall (WAF)?
No, Mykonos Web Security is a Web Intrusion Prevention System. We protect web applications, but the techniques we use are very different from a traditional signature-based WAF. However, for the purposes of PCI compliance we help companies satisfy PCI 6.6.
Are you a Network Intrusion Prevention System?
No, Mykonos Web Security protects your web traffic and only deals with HTTP and HTTPs protocols.
Do you meet PCI Compliance requirements?
Yes, according to PCI 6.6, Mykonos Web Security helps companies meet the requirements.
What web applications or websites can you protect?
We are application agnostic. You can put Mykonos Web Security in front of any Web application or website because it does not require you to change a single line of code.
Do you use signatures? Is your product signature based?
No. unlike all traditional WAF’s we are not signature-based. We belief that signature based solutions are flawed. They can never detect against the attack that hasn’t been written. Our approach is based on detecting hacker behavior and is built on injecting deceptive detection points into the code that will be appealing to attackers. Hackers identify themselves by “touching” our injected tar traps.
How can you claim that you create “No false positives”?
Quite simple. We are very different from signature-based security products like WAF’s. We inject detection points into the code which a normal user would never see. Therefore, if somebody manipulates one of our detection points, by definition they have to be a malicious user, because the detection points they are touching are fake and not a part of the application – they are deceptive tar traps that detect attackers with no chance of a false positive.
