Solution Brief | AWS and CloudGuard AppSec
This solution brief outlines CloudGuard AppSec, a cutting-edge application security solution powered by machine learning and contextual AI. It provides precise prevention of OWASP Top 10 attacks and other sophisticated threats, including automated bot attacks and API vulnerabilities. With easy deployment and minimal administration, CloudGuard AppSec ensures robust protection for evolving applications. Download the solution brief to learn how CloudGuard can enhance your app security.

CloudGuard AppSec represents a new paradigm in application security. Leveraging machine learning and a patent-pending contextual
AI engine, CloudGuard learns how an application is typically used, profiles the user and the app content, and scores each request
accordingly. This approach has proven to eliminate false positives while maintaining the highest standards of application security. Easy
to deploy to production environments in a matter of hours, CloudGuard AppSec delivers application security that can keep up with
even the fastest DevOps team.
AppSec Powered by Contextual AI
The AI engine conducts a risk analysis of each
request and automatically adapts to changes
by continuously profiling the user, application,
and content.
Protect Applications as they Evolve
Analyzing each request in context and
assigning a risk score provide precise
prevention – eliminating false positives and
preventing OWASP Top 10 attacks and more.
Prevent Automated Attacks
Protect applications from sophisticated bots,
leveraging JavaScript injections to perform
client-side behavioral analysis (using biometric
activity, keystrokes, and more).
Stop Attacks Against APIs
Ensure that APIs are being used correctly with
automated validation using OpenAPI schema
files.
Benefits
CloudGuard AppSec provides automated web application and API security powered by AI and ML engines, providing maximum security
with minimal administration.
Applications drive business. As they evolve and grow, more APIs are exposed, which expands the attack surface. Cyber criminals attack
web applications and APIs using methods such as SQL injection and automatic scripts, known as bots. These attacks are damaging and
costly. Unfortunately, existing application security technologies, such as web application firewalls (WAFs) rely on outdated techniques
such as threat signature mapping. These approaches often generate unacceptably high false positive rates—WAFs just can’t keep up.
Secure critical applications and APIs with
Check Point CloudGuard AppSec
Check Point on AWS
Challenges
Today’s applications and APIs are under attack
The Check Point Solution
Automated Web Application and API Protection
AMAZON CONFIDENTIAL Last Updated: January 2019
Features
Check Point on AWS Check Point is an APN Advanced Technology Partner with Networking and Security Competencies. CloudGuard delivers unified and
automated cloud native security on AWS multi-cloud environment, including network security and threat prevention, security posture
management, workload and API protection, cloud intelligence, and threat hunting. CloudGuard natively integrates with over 50 Amazon
AWS services and security solutions, including AWS Security Hub, VPC Flow Logs, Amazon GuardDuty, and Amazon CloudWatch.
Get started with Check Point solutions on AWS Visit AWS Marketplace (t.ly/8UR3) to purchase or start a Free Trial today.
Large Financial Institution
Check Point on AWS | Secure critical applications and APIs with CloudGuard AppSec
Contextual Score-Based Decision Engine
By examining several parameters in detail and combining them to form an accurate risk score,
CloudGuard AppSec eliminates false positives. A final risk score is determined with input from multiple
engines including transaction risk, user behavior risk, crowd behavior risk, and content risk. Combining
the risk analysis of multiple engines results in a more accurate decision, with understanding of the
context. It allows security admins to operate comfortably in Prevent Mode, without the worry of
blocking legitimate requests.
The Confidence to Run Application Security in Production
Unfortunately, many application security products are only deployed in monitoring mode or passive
mode because their users get too many false positives. Not CloudGuard AppSec: 90% of customers run
the solution in prevent mode with the accuracy needed to reduce operational overhead by providing a
high level of threat prevention precision. Most customers run CloudGuard AppSec out-of-the box with
fewer than 10 exception rules.
The Burden of Maintenance
The security team was burdened by
maintaining security policies as well as
old deployment models in their legacy
application security product. They
wanted to have all of their cloud assets
and security products managed and
deployed in the same way.
Deployed Everywhere
at Scale
Using AWS auto-scaled instances, the
organization runs containers managed
by external systems. CloudGuard
AppSec integrated into both systems
perfectly, running as a container that
can be auto-scaled in any environment.
Continuous Security
The organization’s developers
constantly change and update their
applications. CloudGuard AppSec
automatically adapts to these changes
and requires significantly less
maintenance than their previous
application security solution.
Solution Brief
AMAZON CONFIDENTIAL
Last Updated: June 2021