Average Ratings 1 Rating
Average Ratings 0 Ratings
Description
The premier hybrid and multi-cloud platform offers an advanced suite of security features including next-gen WAF, API Security, RASP, Enhanced Rate Limiting, Bot Defense, and DDoS protection, specifically engineered to address the limitations of outdated WAF systems. Traditional WAF solutions were not built to handle the complexities of modern web applications that operate in cloud, on-premise, or hybrid settings. Our cutting-edge web application firewall (NGWAF) and runtime application self-protection (RASP) solutions enhance security measures while ensuring reliability and maintaining high performance, all with the most competitive total cost of ownership (TCO) in the market. This innovative approach not only meets the demands of today's digital landscape but also prepares organizations for future challenges in web application security.
Description
open-appsec is an open-source initiative that builds on machine learning to provide pre-emptive web app & API threat protection against OWASP-Top-10 and zero-day attacks.
It can be deployed as add-on to Kubernetes Ingress, NGINX, Envoy and API Gateways.
The open-appsec engine learns how users normally interact with your web application. It then uses this information to automatically detect requests that fall outside of normal operations, and sends those requests for further analysis to decide whether the request is malicious or not.
open-appsec uses two machine learning models:
1. A supervised model that was trained offline based on millions of requests, both malicious and benign.
2. An unsupervised model that is being built in real time in the protected environment. This model uses traffic patterns specific to the environment.
open-oppsec simplifies maintenance as there is no threat signature upkeep and exception handling, like common in many WAF solutions.
API Access
Has API
No
API Access
Has API
No
Integrations
Expel
Yes
F5 NGINX Ingress Controller
No
Indent
Yes
JupiterOne
Yes
Kubernetes
No
NGINX
No
Integrations
Expel
No
F5 NGINX Ingress Controller
Yes
Indent
No
JupiterOne
No
Kubernetes
Yes
NGINX
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
No price information available.
Free Trial
Yes
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
Yes
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
Yes
Online Support
Yes
Types of Training
Training Docs
No
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
No
Vendor Details
Company Name
Signal Sciences
Founded
2014
Country
United States
Website
www.signalsciences.com
Vendor Details
Company Name
open-appsec
Founded
2022
Country
Israel
Website
www.openappsec.io
Product Features
Application Security
Analytics / Reporting
Yes
Open Source Component Monitoring
No
Source Code Analysis
No
Third-Party Tools Integration
Yes
Training Resources
Yes
Vulnerability Detection
Yes
Vulnerability Remediation
Yes
Firewall
Alerts / Notifications
No
Application Visibility / Control
No
Automated Testing
No
Intrusion Prevention
No
LDAP Integration
No
Physical / Virtual Environment
No
Sandbox / Threat Simulation
No
Threat Identification
No
Network Security
Access Control
No
Analytics / Reporting
No
Compliance Reporting
No
Firewalls
No
Internet Usage Monitoring
No
Intrusion Detection System
No
Threat Response
No
VPN
No
Vulnerability Scanning
No
Web Application Firewalls (WAF)
Access Control / Permissions
No
Alerts / Notifications
No
Automate and Orchestrate Security
No
Automated Attack Detection
No
DDoS Protection
No
Dashboard
No
IP Reputation Checking
No
Managed Rules
No
OWASP Protection
No
Reporting / Analytics
No
Secure App Delivery
No
Server Cloaking
No
Virtual Patching
No
Zero-Day Attack Prevention
No
Product Features
Application Security
Analytics / Reporting
Yes
Open Source Component Monitoring
Yes
Source Code Analysis
No
Third-Party Tools Integration
Yes
Training Resources
Yes
Vulnerability Detection
Yes
Vulnerability Remediation
Yes
Web Application Firewalls (WAF)
Access Control / Permissions
No
Alerts / Notifications
Yes
Automate and Orchestrate Security
Yes
Automated Attack Detection
Yes
DDoS Protection
No
Dashboard
Yes
IP Reputation Checking
Yes
Managed Rules
Yes
OWASP Protection
Yes
Reporting / Analytics
Yes
Secure App Delivery
No
Server Cloaking
No
Virtual Patching
No
Zero-Day Attack Prevention
Yes