Network security
About the solution
The first level of protection consists of a stateful firewall installed at the entrance to the internal network and data center. Its role is basic traffic filtering. Also, it is good to have an upgrade in the form of a new generation firewall system (NGFW), which offers much greater functionality than traditional systems. The traditional way of filtering packets at the level of TCP or UDP ports has been replaced by DPI inspection (Deep Packet Inspection). Using the DPI method, both the header of the package and its content, which may carry harmful information, are checked.
IPS/IDS is another system that is recommended to have in the network, due to its ability to detect different types of application attacks, such as SQL injection and XSS. Although signature‑based IPS is most often implemented in these areas, which creates characteristic signatures based on well-known vulnerabilities, recently, the use of anomaly‑based, i.e. behavioral‑based IPS‑a. This solution can, based on deviations from the standard state, detect the appearance of suspicious traffic, i.e. anomalies, which enables blocking of attacks that target previously unknown vulnerabilities in the system. Although IPS can be used as a stand-alone solution, it is increasingly found integrated within NGFW.