home

Articles

Blog

Books

Tools

Links

FAQ Page


XS40 XML Security Gateway



From the publisher website or publicity

XS40 XML Security Gateway

While there is tremendous business value in XML Web services, security remains an unsolved problem and the largest single barrier to adoption. Enterprises require a new pragmatic approach to XML Web services security, one that simultaneously recognizes the uncertainty of new standards, the value of existing infrastructure investments, the organizational challenges and the performance impact of XML security. Because corporations are struggling to deal with resource constraints, diverging business goals and the requirement to assimilate new technology, the XS40 is an easy-to-install and maintain network appliance that satisfies both application and network groups and supports current and pending security standards out-of-the-box.

XML Web Services Security is XML Processing

All XML Web services security functions, such as XML schema validation, XML Encryption, XML Signature, WS-Security and others, require extensive XML processing. The security of the underlying XML processing engine is essential to the security of a web services security solution. Secure XML processing is also very resource-intensive. This often forces organizations to choose between performance and protection, because fully securing XML requires processing power not available in traditional XML engines.

Secure Architecture

Powered by robust XG3™ technology built from the ground up to be secure, the XS40 is the only available solution able to provide full XML Security with the wirespeed performance necessary for real-world applications. XS40 XML Security Gateway is more than just an XML Firewall: it is a carrier-grade XML proxy that can parse, filter, validate schema, decrypt, verify signatures, access-control, transform, sign and encrypt XML message flows as illustrated in the figure below.

"DataPower has strong integration for security and management. ... All of this adds up to the strongest overall current feature set." - Forrester Research, XML Security Gateway Report

With the XS40, enterprises can implement comprehensive XML security practices without the performance penalties or security weaknesses typical of other solutions. The XS40's patent-pending architecture is truly future-proof, with the agility to easily adapt to changing standards, partners and policies.

Third-Party Validation of Security and Interoperability

DataPower's Integration for Management strategy means that the XS40 has the strongest integration with existing enterprise infrastructure. In addition to being widely deployed at the world's largest organizations, the XS40 has been extensively validated and certified for its security, reliability, interoperability and deep integration. See DataPower Standards Interoperability and Product Integration page for a list of just some of these.

Click here XS40 XML Security Gateway datasheet.


 *Feature Description Business Benefit
 *Service Virtualization Mask backend resources to hide internal structures; XML-aware NAT (network address translation). Enable easy access to applications without creating vulnerabilities or versioning headaches.
 *XML/SOAP Filtering XML Firewall filters traffic at wirespeed rates based on content, payload size or other metadata. Easy to use, comprehensive XML Vulnerability protection without new code or performance compromise.
 *Field Level XML Security XML Encryption and Digital Signatures at the message or element level; interoperable WS-Security. Share information selectively or comply with regulations, even in multiparty transactions and semi-trusted environments.
 *Web Services Access Control Use new technologies (like SAML, XACML, WS-Security) or existing systems (like LDAP or SSO) to control access to applications. Full XML security with no application code changes. Centralize access control and improve security.
 *Data Validation Schema validate XML documents at wirespeed rates, protect against XDoS (XML Denial-of-Service Attacks). Improve uptime and performance by ensuring only known-good requests arrive at mission-critical app-servers.
 *XML Routing SOAP Routing Route requests based on content, network parameters or other metadata. Leverage separation of concerns to reduce complexity, improve performance and uptime through efficient resource utilization.

Frequently Asked Questions for the DataPower XS40 XML Security Gateway

Q: What is the XS40 XML Security Gateway?

The XS40 XML Security Gateway is a 1U (1.75" thick) rack-mountable network device purpose built by some of the world's top XML experts to secure XML and Web Services transactions. The XS40 delivers the most comprehensive set of functions including:

XML Encryption

XML/SOAP Firewall filtering


 *XML Digital Signatures
 *XML Schema validation
 *Two-way SSL
 *XML Access Control
 *XPath

Detailed Logging

Q: Why not use existing security infrastructure such as IP firewalls and SSL proxies?

The existing security infrastructure is not and cannot be made XML-aware: much of it was designed and deployed before XML became the "lingua franca" it is today. Indeed, one of the original design goals for SOAP, the foundation of XML Web Services, was to be a server-to-server protocol that could "easily bypass firewalls". That means that monitoring, controlling and policing XML network traffic requires a new kind of device. Of course, the existing IP security infrastructure continues to play an essential role by providing security at the lower layers.

Q: Why not just handle XML security at the application server?

While application servers can be used to implement some security functions, this is not a scalable enterprise-wide answer to the wider XML Web Services security challenge. One reason is that the processing demands of advanced XML security standards make it impossible to fully secure a high-volume XML transaction environment without dedicated hardware. Another is the difficulty of keeping multiple application servers up-to-date with XML security patches and corporate policies, a task greatly eased by establishing a single gateway - an XML proxy - through which XML transactions enter and exit the corporate network.

Q: Security devices must sit in-line. How can I be sure the XS40 won't introduce performance bottlenecks or a single point of failure?

All functions of XML security (encryption, signatures, filtering, and validation) rely heavily on computationally intensive tasks such as XML parsing, XPath and XSLT. The XS40 uses a patent pending technology invented by DataPower to address the unique demands of secure XML processing. XML Generation Three™ or XG3™ is the core processing technology used within the field-proven XA35 XML Accelerator and all of DataPower's XML-Aware products. It enables wirespeed security functions not possible with any competing approach.

From careful thermal design to absence of failure-prone hard disks, the XS40 is designed for reliability by people responsible for some of the world's most reliable products - the network equipment that runs the world's phone networks and major Internet backbones. In the unlikely event of a unit failure, the failover mechanism instantly takes over to transfer traffic to another unit and ensure that no connectivity interruption occurs.

Q: How is the XS40 typically deployed?

The most typical configuration involves the use of the XS40 as an XML proxy, sitting inline and scanning all incoming and outbound XML traffic. In this way it can dynamically apply all necessary encryption, filtering, digital signing and other required security functionality at the edge of the network. The approach dramatically improves performance, security and maintainability.

Q: Why would a company want an XML security gateway?

As enterprises deploy sophisticated XML-enabled applications, they face several security vulnerabilities:

Legacy systems are not even aware of XML - Current TCP-oriented security approaches aren't XML-Aware and consequently cannot shield against malicious traffic. SSL is not the solution for web services security.

Schema Validation and other XML security practices are Resource-Intensive - The performance overhead of complex XML processing leads many companies to disable Schema validation and other XML security functions for performance reasons. Like homeowners whose burglar alarm is off because it takes too long to turn on, they are vulnerable to many XML threats.

XML is being used to connect the most valuable resources - The very value of XML Web Services comes from the fact that valuable back-end servers are being connected, but that is also its greatest weakness from a security standpoint.

XML Web Services Access Control - In environments where authorized users and trading partners may change daily, authenticating partners' identity and authorizing actions is crucial but difficult with custom code or legacy systems.

The XS40 XML Security Gateway works with existing infrastructure to create a practical solution that is:

Fast - Industry leading performance means no slow-downs of critical transactions and no security compromises.


 *Future-Proof - Patent-pending policy architecture provides the ultimate flexibility to adapt to evolving standards and changing corporate policies.
 *Secure - Comprehensive set of security functions is powered by DataPower's own field-proven technology.

Q: Does the XS40 work with existing firewalls, routers or load balancers?

Absolutely! The XS40 is designed to complement your existing network infrastructure by adding a layer of intelligent infrastructure to the enterprise network. The XS40 is an IP-addressable device designed to be deployed downstream from firewalls and alongside load balancers, and serve as a secure SOAP intermediary or XML proxy.

Q: In addition to security features (XML filtering, encryption, signing and validation) what other functionality does the XS40 support?

The XS40 also functions as an intelligent content switch or XML router capable of directing XML requests to the appropriate resource. This flexible XML routing can be based on the content payload or network-level criteria (such as IP address or URL).

Keywords
access control
data validation
DataPower
enterprise security
LDAP
NAT
network address translation
SAML
Security Gateway
security management
SOAP
SOAP filtering
SOAP security
SSO
two-way SSL
web gateway
web services
web services security
wirespeed
WS-Security
XACML
XG3
XML
XML and SOAP
XML aware
XML decrypt
XML digital signature
XML encryption
XML firewall
XML message
XML network traffic
XML parser
XML proxy
XML routing
XML schema
XML security
XML standards
XML verification
XML vulnerability
XML web services
Xpath
XS40


Related Articles
IT News Round-Up
ArcSight Common Event Framework
Silex WiFi Security
NeoAccel Enterprise Security
Enterprise IT Threat by Burton Group
Citadel Seals Deal with GroupCaptiva

Other tools that may interest you by area:-

XML tools

Web tools

Web Services tools

Security tools

Internet Security tools

Vendor: DataPower


See our Sarbanes-Oxley compliance, load testing and Financial Glossary pages.
Articles   Books   FAQ Page   home   Jobs   Links   Reviews Page   Tools  
Booklist   books   Measurement   Testing   Tools