Mykonos Web IPS versus WAF
Download PDF
Features & Benefits
Product Features
- Mykonos Software Web Intrusion Prevention System
- Traditional Signature-based WAF
- DETECTION TECHNIQUES
- Signatures
- Q1 2012
- Behavior analysis
- Web intrusion prevention system using deceptive tar traps
- TRACK
- IP address
- Browsers (cookies across multiple IP addresses)
- Browsers (persistent tokens across multiple IP addresses)
- Software/script (fingerprinting)
- PROFILE
- IP address (geo-location)
- Attacker (incident history, browsers, software & scripts)
- Attacker threat level analysis
- Assigns name to attacker (e.g. JoeSmith27)
- RESPOND
- Automated & manual real-time response
- Alerting
- Force log-out and re-authentication
- Force CAPTCHA
- Block IP addresses
- Block attacker (browser, software & scripts)
- Warn attacker (browser)
- Deceptive response – slow connection
- Deceptive response – simulate broken applications
- WEB APPLICATION HARDENING
- Cross site request forgery (CSRF) prevention
- Anti-profiling of application
- Session hijacking prevention
- CAPTCHA inserted into existing workflow
- COMPLIANCE
- PCI 6.6
