Barracuda CloudGen WAF

Securing Applications and Data in Amazon Web Services

Download PDF

Overview

The Barracuda CloudGen WAF blocks application layer DDoS and other attack vectors directed at web-facing applications hosted in Amazon Web Services, while providing superior protection against data loss. It also has strong authentication and access control capabilities for restricting access to sensitive applications and data, along with the ability to autoscale inside your VPC.

The Barracuda Advantage

  • Barracuda Central Operations Center keeps track of emerging threats
  • State-of-the-art security utilizing full reverse-proxy architecture
  • Malware protection for collaborative web applications
  • Employs IP Reputation intelligence to defeat DDoS attacks
  • Designed to make it easier for organizations to comply with regulations such as PCI DSS and HIPAA
  • Cloud-based scan with Barracuda Vulnerability Manager
  • Automatic vulnerability remediation

Product Spotlight

  • Comprehensive inbound attack protection including the OWASP Top 10
  • Built-in caching, compression, and TCP pooling ensure security without performance impacts
  • Identity-based user access control for web applications
  • Ability to bootstrap and autoscale with automated and clustered deployments using CloudFormation templates
  • Available on the AWS marketplace as a single AMI or as a CloudFormation template
  • Integration with Cloudwatch, S3 and IAM Roles
  • AWS Security Competency Certified

Constant Protection from Evolving Threats

The Barracuda CloudGen WAF provides superior protection against data loss, DDoS, and all known applicationlayer attack modalities. Automatic updates provide defense against new threats as they appear. As new types of threats emerge, it will acquire new capabilities to block them.

Identity and Access Management

The Barracuda CloudGen WAF has strong authentication and access control capabilities that ensure security and privacy by restricting access to sensitive applications or data to authorized users.

Affordable and Easy to Use

Pre-built security templates and intuitive web interface provide immediate security without the need for time-consuming tuning or application learning. Integration with security vulnerability scanners and SIEM tools automates the assessment, monitoring, and mitigation process.

Technical Specs

Technical Specs

Web Application Security

  • OWASP top 10 protection
  • Form field meta-data validation
  • Adaptive security
  • Website cloaking
  • Response control
  • JSON payload inspection
  • XML firewall
  • Web scraping protection
  • Granular policies to HTML elements
  • Protocol limit checks
  • File upload control
Protection against common attacks:
  • SQL injection
  • Cross-site scripting
  • Cookie or forms tampering
Outbound data theft protection:
  • Credit card numbers
  • Custom pattern matching (regex)

DDoS Protection

  • Integration with Barracuda Next-Gen Firewall to block malicious IPs
  • Barracuda IP Reputation Database
  • Heuristic Fingerprinting
  • CAPTCHA challenges
  • Slow Client protection
  • Layer 3 and Layer 7 Geo IP
  • Anonymous Proxy
  • ToR exit nodes
  • Barracuda Blacklist

Supported Web Protocols

  • HTTP/S 0.9/1.0/1.1/2.0
  • WebSocket
  • FTP/S
  • XML

Authentication

  • LDAP/RADIUS
  • Client Certificates
  • SMS Passcode
  • Single Sign-On
  • Multi-Domain SSO

Advanced Authentication

  • Kerberos v5
  • SAML
  • RSA SecurID

Application Delivery and Acceleration

  • High availability
  • SSL offloading
  • Load balancing
  • Content routing

SIEM Integrations

  • HPE ArcSight
  • RSA enVision
  • Splunk
  • Symantec
  • Custom
  • VLAN, NAT
  • Network ACLs

Logging, Monitoring and Reporting

  • Barracuda IP Reputation Database
  • Heuristic Fingerprinting
  • CAPTCHA challenges
  • Slow Client protection

Centralized Management

  • Monitor and configure multiple Barracuda products from a single interface
    • Check health and run reports
    • Assign roles with varied permissions
    • Available from anywhere

Management Features

  • Customizable role-based administration
  • Vulnerability scanner integration
  • Trusted host exception
  • Adaptive profiling for learning
  • Exception profiling for tuning
  • Rest API
  • Custom Templates

Models & Options

Models

Level 1

  • m3.medium Container Size
  • Metered Billing, BYOL, PAYG License Type

+ Show more - Show less

  • Features

  • HTTP/S, FTP Protocol Validation
  • Protection Against Common Threats
  • Form Field Meta Validation
  • Bot Protection
  • Web Scraping Protection
  • Web Site Cloaking
  • JSON Protection
  • Response Control
  • Outbound Data Theft Protection
  • Granular Policies to HTML Elements
  • Protocol Limit Checks
  • File Upload Control
  • Logging, Monitoring and Reporting
  • High Availability
  • SSL Offloading
  • Authentication and Authorization
  • Vulnerability Scanner Integration
  • Rest API
  • LDAP/RADIUS
  • Load Balancing
  • Content Routing
  • RSA SecurID
  • CA SiteMinder
  • XML Firewall
  • Adaptive Profiling
  • Antivirus for File Uploads
  • URL Encryption
  • Vulnerability Remediation Service
  • Barracuda Advanced Threat Protection *

Level 5

  • m3.large/m4.large Container Size
  • Metered Billing, BYOL, PAYG License Type

+ Show more - Show less

  • Features

  • HTTP/S, FTP Protocol Validation
  • Protection Against Common Threats
  • Form Field Meta Validation
  • Bot Protection
  • Web Scraping Protection
  • Web Site Cloaking
  • JSON Protection
  • Response Control
  • Outbound Data Theft Protection
  • Granular Policies to HTML Elements
  • Protocol Limit Checks
  • File Upload Control
  • Logging, Monitoring and Reporting
  • High Availability
  • SSL Offloading
  • Authentication and Authorization
  • Vulnerability Scanner Integration
  • Rest API
  • LDAP/RADIUS
  • Load Balancing
  • Content Routing
  • RSA SecurID
  • CA SiteMinder
  • XML Firewall
  • Adaptive Profiling
  • Antivirus for File Uploads
  • URL Encryption
  • Vulnerability Remediation Service
  • Barracuda Advanced Threat Protection *

Level 10

  • m3.xlarge/m4.xlarge Container Size
  • Metered Billing, BYOL, PAYG License Type

+ Show more - Show less

  • Features

  • HTTP/S, FTP Protocol Validation
  • Protection Against Common Threats
  • Form Field Meta Validation
  • Bot Protection
  • Web Scraping Protection
  • Web Site Cloaking
  • JSON Protection
  • Response Control
  • Outbound Data Theft Protection
  • Granular Policies to HTML Elements
  • Protocol Limit Checks
  • File Upload Control
  • Logging, Monitoring and Reporting
  • High Availability
  • SSL Offloading
  • Authentication and Authorization
  • Vulnerability Scanner Integration
  • Rest API
  • LDAP/RADIUS
  • Load Balancing
  • Content Routing
  • RSA SecurID
  • CA SiteMinder
  • XML Firewall
  • Adaptive Profiling
  • Antivirus for File Uploads
  • URL Encryption
  • Vulnerability Remediation Service
  • Barracuda Advanced Threat Protection *

Level 15

  • m3.2xlarge/m4.2xlarge Container Size
  • Metered Billing, BYOL, PAYG License Type

+ Show more - Show less

  • Features

  • HTTP/S, FTP Protocol Validation
  • Protection Against Common Threats
  • Form Field Meta Validation
  • Bot Protection
  • Web Scraping Protection
  • Web Site Cloaking
  • JSON Protection
  • Response Control
  • Outbound Data Theft Protection
  • Granular Policies to HTML Elements
  • Protocol Limit Checks
  • File Upload Control
  • Logging, Monitoring and Reporting
  • High Availability
  • SSL Offloading
  • Authentication and Authorization
  • Vulnerability Scanner Integration
  • Rest API
  • LDAP/RADIUS
  • Load Balancing
  • Content Routing
  • RSA SecurID
  • CA SiteMinder
  • XML Firewall
  • Adaptive Profiling
  • Antivirus for File Uploads
  • URL Encryption
  • Vulnerability Remediation Service
  • Barracuda Advanced Threat Protection *

Support Options

Barracuda Energize Updates

  • Standard technical support
  • Firmware and capability updates as required
  • Automatic application definitions updates