Blocks OWASP Top 10, OWASP API Top 10, bots, account takeover and L7 DDoS from a single inline engine
Mikiri WAF is a Web Application and API protection platform (WAAP) for organizations that cannot or do not want to put application traffic into a public cloud.
Mikiri WAF uses unique technologies for detecting malicious activity, is easily configured via API and Web Interface, and accurately detects attacks.
Mikiri WAF is a modern WAAP that incorporates both the functionality inherent to application-level firewalls and additional threat-mitigation mechanisms, including anti-bot protection and other important defense mechanisms.
FAST AND ACCURATE
Through combined analysis and an intelligent approach, Mikiri WAF quickly and accurately detects attacks on web applications:
- Signature method’s attack detection time from 0.001 sec.
- The time of detecting attempts to download viruses from 0.015 sec.
- Machine learning module’s attack detection time from 0.07 sec.
- API Firewall module’s attack detection time from 0.003 sec.
Measured in internal test conditions. Actual performance depends on hardware, traffic profile and and other conditions.
CHOOSE YOUR PLAN
BUSINESS
Detect unknown attacks and protect APIs
Advanced Web Application and API protection.
ML Analysis. API Firewall.
Common
- On-premises software
- No software restrictions on traffic volume and RPS
- Access to IP Geolocation base and Threat Intelligence feed
- Deployment in a virtual environment as a Docker containers
Installation and scaling
- Reverse proxy operating mode
- Active-Active and Active-Passive clustering
- Fault-tolerant operation of components
- Multi-node installation support
- Multi-tenancy mode
- Canary method: setting up delayed application of new settings for component server groups
Attacks detection
- API Firewall
- ML analysis
- OWASP-class threats protection
- Malicious bots protection
- Anti-bot mode: smart client verification
- Web scraping protection
- Client behavioral activity analysis
- Virtual Patching
- 0-day vulnerabilities exploitation detection
- Retrospective traffic analysis
Request analysis
- HTTP/1.1, HTTP/2, HTTP/3
- WebSocket, gRPC, REST (RESTful), SOAP over HTTP
- HTML5, JSON, XML, GraphQL, multipart/form-data
- Blocking requests based on attack indicators
- Checking RFC compliance requests
- Multiple normalization and deep inspection
- Hardware-supported SSL/TLS termination
Third-party systems integrations
- Third-party Threat Intelligence feeds integration
- Third-party Anti-DDoS services integration
- Third-party antivirus systems integration via ICAP
- Any CAPTCHA service integration
Additional features
- Getting detailed information about an IP address
- Personalizing the page for blocked requests
- Malicious bots protection
- Data Masking
Logs and Events
- Centralized collection of information on detected attacks/anomalies
- Obtaining information about detected attacks/anomalies using the web interface and API
- Obtaining component operation logs using the web interface and API
- Mikiri WAF component operation events to third-party systems integrations
- Obtaining information about the current state of hardware resources of Mikiri WAF servers using the web interface and API
- Obtaining information about detected attacks/anomalies using the web interface and API
ENTERPRISE
Protect before, during and after compromise
because protection does’ n stop with the analysis of request
Enterprise-grade Web Application and API protection.
Response Analysis. Advanced statistics. Vulnerability Scanner.
Everything in Business, plus:
Response analysis
- HTTP/1.1, HTTP/2, HTTP/3
- WebSocket, gRPC, REST (RESTful), SOAP over HTTP
- HTML5, JSON, XML, multipart/form-data
- Blocking responses based on attack indicators
- Blocking attacker access to an already compromised system
Additional features
- Vulnerability detection and attack verification with the integrated scanner
- Collecting request processing statistics (statistics on response codes, blocking types, cache access, BL/WL etc.)
- Collecting traffic statistics (incoming and outgoing traffic)
REQUEST EVALUATION
Deploy Mikiri WAF in your environment and evaluate its application security capabilities.
