50 likes | 218 Views
Information Security Team. Web Security Appliance Overview. Current Architecture. Deployed WSA infrastructure with WCCP WCCP (Web Cache Communication Protocol) provides a layer 2 redirection capability http://en.wikipedia.org/wiki/Web_Cache_Communication_Protocol
E N D
Information Security Team Web Security Appliance Overview
Current Architecture • Deployed WSA infrastructure with WCCP • WCCP (Web Cache Communication Protocol) provides a layer 2 redirection capability • http://en.wikipedia.org/wiki/Web_Cache_Communication_Protocol • Transparent to most web applications and browsers • 60 web sites were placed in bypass mode after go live. • Bypass allows all traffic to that site to be excluded from security review • Ongoing analysis is underway to determine root cause • All sites are vendor or location specific with DNS, routing, or other connectivity modifications
Content Analysis and Blocking • Content Analysis • Industry term for monitoring web content, performing analysis, and rendering a reaction • Additional content analysis can be performed at many levels • Current phase manages malware and phishing based analysis • Next phase might global management of porn, gambling, hate, and hacker content. • Discussion on blocking ad delivery to internal clients
Future Architecture • Conversion to full layer 3 proxy mode • Consideration will be given to user authenticated HTTP access • Content blocking exception process • Additional catalog exclusion considerations • As new sites and catalogs create risk and exposure to the organization they’ll be placed on the consideration list for global deny • Data Loss Prevention will be considered as an add on module for this infrastructure