Stock Abbreviation : Topsec      Stock Code : 002212
7*24 hour service: 400-777-0777

Web Application Firewall System

Intelligent protection | Security compliance | Visual display | Complete parallel system

Web Application Firewall System Overview

Topsec Web Application Firewall System(TopWAF) provides web application attack protection, DDoS defense, URL access control, web page anti-tampering, and other functions by built-in thousands of security rules provided by Topsec Alpha Lab (for attack and defense), which provides two-way security filtering for access traffic from customers to web servers and response traffic from web servers to customers, which can effectively resist malicious website tampering, sensitive information leakage, and web server control caused by attacks on web applications. It is a trusted security product for governments, enterprises, universities, and operators to defend against web threats.

Activity & Announcement
Advantages
Intelligent protection

The system adopts human-machine identification technology to intelligently defend against known and unknown web attacks, making web protection more accurate.

Security compliance

To meet the requirements of classified protection, a minute-level web application security protection system is built.

Visual display

The system has graphical display of service traffic and attack behavior to grasp the web security situation in real time.

Complete parallel system

Based on the 64-bit multi-core and multi-channel NGTOS, it is compatible with the TCP/IP protocol stack, avoiding context switches of traditional operating systems and data copying from kernel space to user space, and pushing the system processing efficiency to the extreme.

Application
Tandem Access Reverse Proxy Mode

TopWAF is deployed on the front end of the web server. In this mode, the real IP address is hidden from the access user, effectively securing the web server. In bypass deployment mode, the detection and analysis of web traffic entering and exiting the server are implemented without changing the original topology of the customer. At the same time, the system is linked with Topsec's firewall to block various web attacks in a timely manner and protect website security.

Issues Resolved
  • Effectively prevents security incidents such as malicious tampering of user websites, malicious counterfeiting, leakage of sensitive information, remote control of websites, and vulnerability notification by competent information security authorities due to attacks by hackers.
  • Enables the customers to have a comprehensive and detailed understanding of the status of their websites being attacked by hackers through the analysis of log reports. Websites can also be scanned by the web vulnerability scanner built in TopWAF. O&M personnel can rectify the website vulnerabilities in a timely manner according to the scanning results. Protection policies can also be automatically generated by using the virtual patch function to avoid targeted attacks.
  • Enables customers to intuitively understand the business situation and security situation of the websites with graphical display of service traffic and attack behavior, providing a reference basis for the adjustment of their website services.
  • Meets the requirements for website security in national classified protection of information security.
  • 4.Value to Customers
Value to Customers
Meet the requirements of national classified protection

TopWAP can meet the requirements for website security in the construction of national classified protection of information security.

Defense against unknown threats

Using machine learning technology, the system can implement intelligent modeling based on actual business and automatically generate protection rules, regulate users' submission on websites, and effectively cope with unknown threats.

Protection of sensitive information

The system can filter and protect sensitive information (customizable), and ensure the security of users' personal information by replacement using "*".

Customer reputation safeguarding

The system implements monitoring and recovery of tampering through fingerprint comparison and page caching. At the same time, the system can lock websites at particular time to maintain the government/corporate image.