* The Reviewmeister looks at the newest Web app firewall products
endif; ?>If you’re in the market for a Web app firewall, the Reviewmeister has prepared reviews on the newest products. And if you’re not in the market, you might want to think twice, because these are important pieces of any security strategy.
Traditional firewalls do a good job of thwarting many network-level attacks, but do little to address gaping holes in Web applications where intruders commonly attack. These Web application firewalls attempt to thwart Port 80 focused attacks by using blacklist- and whitelist-style input filtering.
KaVaDo’s InterDo was designed with a large distributed deployment in mind. One or more server nodes communicate with the Java-based management console via built-in Secure Sockets Layer (SSL) encryption. The application server nodes run as a set of services (in the Windows environment).
Although there is no central configuration server, administration of all nodes can be done from a single console. Strict password requirements and the ability to set up multiple users with different administrative privileges show that InterDo is serious about keeping its house in order, while supplying security for the Web application.
InterDo uses a positive-model or whitelist approach with some novel architectural concepts. Trusted and untrusted zones are joined by what KaVaDo calls “tunnels,” an abstraction describing a connection between trusted and untrusted IP address and port combinations. Within the metaphor of a tunnel, security policies are segregated into functional areas called “pipes,” several of which can be combined within a single tunnel and selectively applied to one or more applications in a configurable order of precedence. Examples of pipes include general vulnerabilities (URL, header and entity pattern matches), database issues (parameter screening), cookies and HTTP methods. Default pipes do a good job with common buffer overruns, directory traversals and SQL injection. The default settings did not stop form manipulations by default, but it is possible to set up custom tunnels and rules.
InterDo gives administrators a great deal of flexibility in configuring security policies – more so than any other product we tested. On the downside, initial configuration is not easy and is probably best undertaken only after reading the manual very carefully.
There is a “lean mode” that lets administrators monitor and selectively modify certain pipes in real time, and requests that run afoul of the security policies are blocked while these refinements are made. This is a safe and helpful way to manage the complexity of configuring multiple pipes.
Another helpful management feature is the update service that can securely update pipes in real time using SSL and digital signatures.
For the full report, go to https://www.nwfusion.com/reviews/2003/0818rev2.html




