You are on page 1of 13

Securing Applications & APIs in

Hybrid Multi Cloud & Cloud Native


Environments
Pankaj Gupta
Darshant Bhagat

21 MARCH, 2019

1 © 2016 Citrix | Confidential


BDM Deck for Customers
Awareness & Preference
92%
of reported vulnerabilities
are in apps, not networks.”
National Institute of Standards & Technology

2 © 2018 Citrix | Confidential


Applications and APIs are
most valuable & vulnerable assets

43% Organizations have experienced


application breaches

We Live in
An App & API 62% are not very confident about
their application security

Economy
41% Organizations feel that web applications
& legacy apps have highest security risk

26% Organizations are doing little to


nothing for application security

3 © 2018 Citrix | Confidential Source- Cyber Security Insiders, Application Security Report 2018
Securing Applications & APIs in Hybrid Multi Cloud
Empowering your SecOps & DevSecOps

Comprehensive App Security Next Gen Ready


All the way from L3 to L7 protection For APIs, cloud native apps & DevOps
L3 & 4: Firewall, DDoS Integrated Security Built-in API protection (DDoS, Bots & app logic attack)
TLS/SSL
L7 : WAF, DDoS, Auth, Content Inspection
Across the Portfolio Extend security to Micro- Services w/ operational
consistency
Service Chaining Simple to deploy & manage ML based Zero Day attack detection*
OWASP top 10 for SQL Injection & XSS & more with common code base Bot Management
IP Reputation Service You are ready for the future with Citrix
App Security Analytics

Best in Class Price/Performance


Purpose built for hyper scale
SSL offload for Firewall, IDS and AV Make your infrastructure security perform
25-50% better SSL price/ performance for TPS & Throughput better with lower cost
4 © 2018 Citrix | Confidential NSS validated no.1 price performance for WAF
Visibility into Application Security
Security Insight in Citrix ADM

• How secure are my applications?

• How many attacks are mitigated by Citrix WAF?

• How frequently are applications being attacked?

• Which are the most prominent attacks?

• Which locations are these attacks are coming from?

• Is there a trend to these attacks?

5 © 2018 Citrix | Confidential


Use Cases

Protect Your Public & Reduce AV, DLP & IPS


Internal Web Apps Cost for Inbound Traffic

Reduce AV, DLP, NGFW Secure Inbound &


Cost for Internet access Outbound APIs
6 © 2018 Citrix | Confidential
Securing Public & Internal Web Applications
Evolving Threat Vectors
Malicious Sources

Script Injections

DDoS

Botnets

Unauthorized Access

Application Layer Attacks

APIs Attacks & Misuse

Data Exfiltration & Theft

Need for Comprehensive App Security for Evolving Threat Vectors

7 © 2016 Citrix | Confidential


Securing Web Apps - A Comprehensive Approach
Citrix Solution

DDoS Protection SSL Encryption


Layer 3 to Layer 7 Best price/performance, latest Ciphers/Standards

IP Reputation Based Web Application Firewall


Protect against malicious sources Best price/performance, Highest Security Efficacy

Authentication L3 Firewall
Extensive Integrations, Multi-factor, SSO Tier 2 Segmentation, Access Control

Comprehensive Protection with Simplicity & Lower TCO


8 © 2016 Citrix | Confidential
Reduce AV, DLP & IPS Costs With TLS Termination on Citrix ADC

Before After
Higher Cost in Larger AV, DLP & IPS Reduce AV, DLP & IPS cost with Citrix ADC

AV IPS

ADC AV IPS ADC


TLS termination
Local TLS termination Local TLS termination
by Citrix ADC
requires higher capacity AV requires higher capacity IPS

DLP
DLP

Local TLS termination


requires higher capacity DLP

9 © 2016 Citrix | Confidential


Reduce AV, DLP & FW Costs With TLS Citrix ADC for Your
Workforce Accessing Internet

Before After
Higher Cost in Larger AV, DLP & NGFW Reduce AV, DLP & NGFW cost with Citrix ADC

Local TLS termination AV


AV requires higher capacity AV

Citrix
NGFW NGFW Internet
Internet ADC
TLS termination
Local TLS termination by Citrix ADC
requires higher capacity NGFW

DLP Local TLS termination DLP


requires higher capacity DLP

10 © 2016 Citrix | Confidential


Secure Inbound & Outbound APIs

Protection from DDoS, Bots, Data


theft, App Layer attacks & Auth.
Content Routing,
Quota Management

Citrix ADC
API Security APIs

Outbound API Control,


Filtering

Ready for the API economy. API Security at lower TCO. Leverage Existing Deployments.
11 © 2016 Citrix | Confidential
Securing Applications & APIs in Hybrid Multi Cloud
Empowering your SecOps & DevSecOps

Comprehensive App Security Next Gen Ready


All the way from L3 to L7 protection For APIs, cloud native apps & DevOps
L3 & 4: Firewall, DDoS Integrated Security Built-in API protection (DDoS, Bots & app logic attack)
TLS/SSL
L7 : WAF, DDoS, Auth, Content Inspection
Across the Portfolio Extend security to Micro- Services w/ operational
consistency
Service Chaining Simple to deploy & manage ML based Zero Day attack detection*
OWASP top 10 for SQL Injection & XSS & more No bolt-on security Bot Management
IP Reputation Service You are ready for the future with Citrix
App Security Analytics

Best in Class Price/Performance


Purpose built for hyper scale
SSL offload for Firewall, IDS and AV Make your infrastructure security perform
25-50% better SSL price/ performance for TPS & Throughput better with lower cost
12 © 2018 Citrix | Confidential NSS validated no.1 price performance for WAF
13 © 2016 Citrix | Confidential

You might also like