
Related Topics
The application security technology of Citrix Application Firewall is based on a
positive security model that ensures correct application behavior. The model is
based on HTTP industry standards and best coding practices for HTML and Java. Application
behavior deviating from the positive security model is treated as potentially malicious
and is blocked by the Citrix Application Firewall.
Through its understanding of good application behavior, the positive security model
does not require attack signatures or pattern matching techniques to detect and
block attacks. It is the only proven approach delivering "zero day" protection
against unpublished exploits. The positive security model:
Next‑generation security requires much more than simple packet‑level inspection.
Complete application security requires deep stream inspection technology that reconstructs
all bi‑directional communications for each user session. Once reconstructed, it
inspects all content to ensure correct application behavior and the validity of
user and machine inputs.
Deep stream inspection technology is based on multiple core technologies, including:
In addition to delivering out‑of‑the‑box protection against all web‑based threats, Citrix Application Firewall provides the ability to tailor security policies for any application, including those using client‑side JavaScript. Citrix's adaptive learning engine can automatically learn the behavior of an application and generate human-readable policy recommendations. The security manager can then selectively apply recommendations to strengthen a security policy and to enable permissible application behavior.
Citrix Application Firewall incorporates multi‑layer cloaking technology to mitigate a hacker's ability to conduct reconnaissance on a target web‑site. It hides sensitive information about an application environment (e.g., application server, database technology, server operating system, internal domain naming, etc.) making it much more difficult for an attacker to devise an effective attack strategy and exploit known vulnerabilities. By cloaking sensitive or revealing information at multiple communication layers, hackers are denied valuable intelligence about an application infrastructure, thus greatly reducing the risk of attack.
| ABOUT US I.T. SUPPORT SERVICES INFRASTRUCTURE SERVICES VIRTUALIZATIONWEB SERVICESBLOGCONTACTSUPPORTSITEMAP |
Capital Network Solutions, Inc. (CNS) located in Sacramento, California is a premier
network services and consulting company. Capital Network Solutions, Inc. has supported
hundreds of clients in the technology arena. Our network and consulting services
are designed to help you achieve a higher level of security, efficiency, reliability
and productivity.
Areas We Provide Service in the Northern California area: Sacramento, CA, Elk Grove,
CA, Folsom, CA, Auburn, CA, Citrus Heights, CA, Stockton, CA,
Davis, CA, Rocklin, CA, North Highlands, CA, Roseville, CA, Loomis, CA, Rancho Cordova,
CA, Fair Oaks, CA, Galt, CA, Carmichael, CA, Woodland, CA