Skip to content

WAPPLES 助力公司企業應對網站與 API 安全挑戰 讓技術團隊快速響應安全需求,進一步降低運營成本

為應對現今日益複雜的網絡威脅,WAPPLES 推出全新一代網站與 API 保護解決方案(WAAP),透過邏輯分析技術,為公司企業提供針對網站應用、API 及流動應用的全面保護,有效抵禦包括零日攻擊在內的各類安全威脅。

領先技術,全面保護

WAPPLES 的核心技術 —— COCEPT™ 邏輯偵測引擎,突破傳統基於簽名的防護模式,憑藉內建的 39 條預設安全規則,實現對已知和未知威脅的高效檢測,全面覆蓋 OWASP Top 10 漏洞,包括 SQL 注入、跨站腳本攻擊(XSS)、跨站請求偽造(CSRF)、應用層 DoS 攻擊等。此外,COCEPT™ 還具備即時安全修補程式功能,幫助公司企業快速修補漏洞,降低攻擊風險。

WAPPLES 不僅針對網站與應用安全進行強化,還特別關注 API 的保護。透過專屬的 XML、JSON 和 YAML 結構解析器,能有效攔截基於 API 的惡意請求及 DoS 攻擊,助力公司企業在提升應用性能的同時保障數據安全。

多元功能,滿足企業需求

WAPPLES 集成了一系列強大的功能模組,從 HTTP 合規性驗證、WebSocket 安全防護 到 URL 加密,均能全面應對日益複雜的網絡攻擊場景。同時,內置的「資料外洩防護技術」支援敏感數據遮蔽與個人身份資訊(PII)防洩漏,協助企業達成合規要求。

為了進一步提升應用交付效率,WAPPLES 還提供「七層負載均衡」、「支援 HTTP / 2」、「SSL 卸載 」等多項進階應用交付功能,確保業務運行穩定順暢。

靈活部署與便捷管理

WAPPLES 支援多樣化部署模式,包括「透明串接」、「反向代理」、「透明反向代理」及「離線監控」,滿足公司企業不同場景需求。此外,其直觀的圖形化管理介面結合自我診斷與警示功能,讓 IT 團隊能快速掌握系統狀態,同時「支援雙重身份驗證(2FA)」與「SSL 證書管理」,進一步增強存取安全性。

關於 Frost & Sullivan
六十年來,Frost & Sullivan 一直致力於幫助投資者、企業領導者和政府應對經濟變化,並識別顛覆性技術、大趨勢及新商業模式,從而帶來持續的增長機會,推動未來成功。 

About Penta Security

Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Penta Security Enhances Asian Market Presence through Strategic Partnership with Version 2 Digital

Penta Security, a leading global provider of web, data, and IoT security solutions, proudly announces its strategic partnership with Version 2 Digital, a dynamic IT company based in Hong Kong. This partnership aims to strengthen Penta Security’s presence in the Asian market by leveraging Version 2’s extensive sales network to distribute WAPPLES, Penta Security’s Web Application & API Protection (WAAP) solution, across Hong Kong, Macau, Taiwan, and Singapore.

Carlos Cheng, Founder and Managing Director of Version 2 Digital, expressed his excitement about the partnership: “We are honored to collaborate with Penta Security, a leader in cybersecurity. This partnership will enable us to bring advanced security solutions to our diverse client base, helping them safeguard their digital assets against the increasing threats in the cyber landscape.”

Ian Choi, Head of Global Business at Penta Security, added, “Partnering with Version 2 allows us to leverage their extensive network and expertise in the IT industry. Together, we aim to deliver unparalleled security solutions and services to businesses and consumers across these regions. We look forward to continuous collaboration to generate synergies not only in the security industry but also in the encryption business sector.”

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Web 應用防火牆 (WAF) 的發展歷程 WAPPLES 的智能 Web 應用防火牆有什麼獨特之處

什麼是 Web 應用防火牆?

Web 應用防火牆 (WAF) 不同於傳統的網絡防火牆。它是一種專為應用層安全設計的解決方案,旨在解決經常被忽視但至關重要的安全架構層面 —— 應用層安全。

為什麼需要 Web 應用防火牆?

現代企業通常使用各種 Web 應用程式,無論是面向公眾的網站還是內部的協作平台,這些應用程式都需要進行細緻且智能的網絡流量檢查,以適應不同的應用和新興的威脅。

傳統的網絡防火牆主要依據網絡層的規則來過濾流量,因此在保護 Web 應用方面非常有限。由於它無法阻擋通過防火牆授權的應用程式發起的攻擊,網絡防火牆難以有效防止應用層的攻擊。

Web 應用防火牆則不同,它能夠深入檢查應用層的資料封包,檢測不正常的 Web 協定和異常行為,識別針對應用層的威脅。

WAF 的核心功能是防範常見的 Web 攻擊,如 SQL 注入、跨站腳本(XSS)等。通過阻擋這些攻擊,WAF 有效地防止敏感資料外洩、未經授權的存取以及網站被篡改或遭遇跨站請求偽造(CSRF)。

Web 應用防火牆的發展歷程

WAF 技術的發展歷經了幾個階段,主要根據其檢測原則來區分。

第一代 WAF:模式匹配檢測

第一代 WAF 通過白名單和黑名單來決定是否允許或阻擋流量。白名單定義合法的流量,黑名單則列出已知的攻擊模式。然而,這種方法常常導致「誤報」,即誤將合法存取視為攻擊。為了減少誤報,系統管理員需要頻繁更新這些名單。

這種方法不僅增加了系統管理的負擔,還容易出現錯誤,導致保護效果不佳。

第二代 WAF:自動化白名單

第二代 WAF 透過自動學習 Web 應用程式的流量行為來建立白名單,然而,這種方法在應對快速變化的 Web 攻擊模式時顯得不足。此外,自動生成的白名單仍需要人工配置,並且黑名單也需不斷更新。

因此,第二代 WAF 並未顯著降低管理員的工作負擔,這促使了第三代 WAF 的誕生 —— 即「智能 WAF」 。

第三代 WAF:基於邏輯的檢測

第三代 WAF 結合了黑名單、白名單和封包分析等多種技術,通過邏輯推理來檢測和分類攻擊。與前兩代相比,這種方法大大降低了誤報率。此外,第三代 WAF 採用基於邏輯的檢測方式,即使面對新型或變異的攻擊,也無需頻繁更新簽名資料庫,能自動進行識別,提升了檢測效率。

這種無簽名的檢測技術減少了系統效能的損耗,使管理員可以專注於策略管理,而不必頻繁維護黑白名單。

WAPPLES – 智能 Web 應用防火牆

WAPPLES 是第三代 WAF 的典型代表之一。它使用無簽名的檢測技術,安裝和維護所需的運行負擔非常低。

WAPPLES 的 COCEP™(內容分類與評估處理)引擎通過邏輯分析來檢測 Web 攻擊。舉個例子,攻擊模式 A 即便經過修改,WAPPLES 也能夠識別並阻擋,而傳統的第一代和第二代 WAF 則無法做到。

假設一個攻擊模式為 [A 是 (水果名稱)]。如果名單中僅包括 [A 是蘋果]、[A 是香蕉] 和 [A 是橙子],那麼 [A 是草莓] 這類變異攻擊將無法檢測到。

然而,若名單中包含 [A 是] 的通用模式,則所有以 [A 是] 開頭的句子,包括無害的 [A 是 (顏色)],都可能被誤判為攻擊,導致大量誤報。

WAPPLES 的 COCEP™ 引擎不僅依賴於簡單的模式匹配,還能通過語義分析來判斷 [A 是] 後面的內容是否具有攻擊性。這樣,WAPPLES 能有效阻擋變異甚至未知的攻擊,提升檢測準確性,同時大幅減少誤報。

因此,WAPPLES 能夠提供更準確的攻擊檢測,並降低誤報風險。

關於 Frost & Sullivan
六十年來,Frost & Sullivan 一直致力於幫助投資者、企業領導者和政府應對經濟變化,並識別顛覆性技術、大趨勢及新商業模式,從而帶來持續的增長機會,推動未來成功。 

About Penta Security

Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Penta Security’s Cloudbric Managed Rules – API Protection Validated for Top-Tier Performance

SEOUL, SOUTH KOREA, September 17, 2024 /EINPresswire.com/ — Penta Security, a leading cyber security company and provider of web application security in the Asia-Pacific region, announced that Penta Security’s latest Cloudbric Managed Rules, API Protection, showed outstanding performance in the comparative test audited by The Tolly Group. 

The Tolly Group is an independent 3rd-party IT testing, validation, and analysis organization, renowned for its global standards and credibility in testing various network equipment and IT solutions.

According to the report published by The Tolly Group on September 13th 2024, Cloudbric Managed Rules for AWS WAF-API Protection, along with two other API security-related managed rule groups, were tested against a total of 1,081 attack payloads categorized under “OWASP Top 10 API Security Risk.” The purpose of the test was to compare the performance of the managed rule groups by measuring their detection rates, under the supervision of Kevin Tolly, Founder of The Tolly Group. Cloudbric Managed Rules for AWS WAF – API Protection demonstrated a 97.31% detection rate, proving its outstanding, top-tier performance.

Kevin Tolly said, “API Security has been a major focus for many cybersecurity vendors in recent years. To respond to ever-evolving cyber attacks, it is important to stay consistent with the current cybersecurity trends.” He added, “The detection rate of Cloudbric Managed Rules for AWS WAF – API Security shows that Penta Security is well-prepared to respond to the attacks of OWASP Top 10 API Security Risks, and that the company pays close attention to users’ needs and convenience, providing a solid security solution for those without security expertise.”

Penta Security currently provides six types of Cloudbric Managed Rules on the AWS Marketplace, each specializing in a specific area of security, all of which have passed the Foundational Technical Review (FTR) by AWS, validating their performance and functionality. In addition to the Cloudbric Managed Rules, Penta Security offers Cloudbric WMS (WAF Managed Service), an AWS WAF managed service enhances the efficiency and security of AWS WAF by providing optimized WAF security rules in accordance with the unique environment of the user. Cloudbric WMS is also scheduled to launch as a subscription-based SaaS model of Cloudbric WMS on AWS Marketplace by the end of this year.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

Penta Security Applauded by Frost & Sullivan for Its Comprehensive Web Security Solution and Market-leading Position

Accessibility and scalability offered by Penta Security’s WAF allow it to stand out among local customers in South Korea compared to international industry participants that do not support domestic cloud environments. 

Frost & Sullivan recently assessed the web application firewall industry and, based on its analysis, recognizes Penta Security Inc. with the 2024 South Korean Company of the Year Award. The company offers web and data security products and services. Unlike standard intrusion prevention systems or next-generation firewall solutions (an alternative for web firewalls that lack comprehensiveness), Penta Security’s WAPPLES, including WAPPLES SA, and Cloudbric WAF+ include API, SSL, and L7 security protections. Penta Security’s WAPPLES differentiates its WAF from other industry participants through its patented logic-based detection Contents Classification and Evaluation Processing (COCEP™) engine. Unlike WAFs based on signature-matching detection, Penta Security’s WAPPLES does not rely on signature updates and lengthy learning periods. It allows the company to conduct security patching and fix vulnerabilities without delay.

Penta Security balances providing application security with performance as a cybersecurity leader in the South Korean WAF space. Its WAF fits different deployments, such as WAPPLES, the on-premises appliances, WAPPLES SA, the software appliances for Cloud, and cloud-based Cloudbric WAF+, differentiating it in the industry. WAPPLES also supports public and local Asia-Pacific cloud environments. Penta Security outshines competitors due to its ability to understand and meet local customer needs with offerings that exemplify best practices implementation. The company’s advanced API security functions (XML, JSON, YAML, GraphQL protection rules), advanced threat IP and bot reputation check functions, and additional add-ons respond to countless web threats based on malicious IPs.

Ying Ting Neoh, industry analyst at Frost & Sullivan, observed, “Penta Security demonstrates leadership focus and visionary strategy in leveraging WAF industry megatrends in South Korea through its integrations with in-house and third-party security solutions and its commitment to technological innovations that offer customers a comprehensive suite of application security portfolios.”

Penta Security provides round-the-clock support backed by over 200 employees to resolve customer difficulties and service failures through its online communication systems. Besides offering local customers access to advanced technologies, world-class experience, and support, Penta Security’s extensive connections, channel partners, and collaborators expand its reach so it can globally engage with customers. The company makes its application security solutions accessible to different customer segments while aligning them with local customer needs. This further strengthens the company’s leadership position in South Korea’s WAF industry. It successfully maintains its position in the South Korean WAF space, over a 50% market share, due to its broad portfolio and ability to retain optimal network performance after introducing WAPPLES to customers’ environments.

“Owing to steady business performance in recent years, Penta Security has positioned itself as an industry leader in South Korea. The company’s visionary strategy is based on its commitment to implementing best practices and leveraging the cloud industry’s rapid growth to develop cloud-based WAF, a valuable addition to its application security portfolio and growth pipeline,” added Neoh. With its strong overall performance, Penta Security earns Frost & Sullivan’s 2024 South Korean Company of the Year Award in the WAF industry.

Each year, Frost & Sullivan presents a Company of the Year award to the organization that demonstrates excellence in terms of growth strategy and implementation in its field. The award recognizes a high degree of innovation with products and technologies, and the resulting leadership in terms of customer value and market penetration.

Frost & Sullivan Best Practices awards recognize companies in various regional and global markets for demonstrating outstanding achievement and superior performance in leadership, technological innovation, customer service, and strategic product development. Industry analysts compare market participants and measure performance through in-depth interviews, analyses, and extensive secondary research to identify best practices in the industry.

About Frost & Sullivan

For six decades, Frost & Sullivan has been world-renowned for its role in helping investors, corporate leaders, and governments navigate economic changes and identify disruptive technologies, megatrends, new business models, and companies to action, resulting in a continuous flow of growth opportunities to drive future success. Contact us: Start the discussion. Contact us: Start the discussion.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×