Solution Brief | CloudGuard WAF: Preemptive Contextual Machine Learning

Solution Brief | CloudGuard WAF: Preemptive Contextual Machine Learning

Traditional WAFs struggle with zero-day threats and the false positive/negative tradeoff. CloudGuard WAF eliminates these challenges using patented contextual AI, preemptively blocking OWASP Top 10 threats in real time—without signatures or manual tuning. Ensure precise detection, seamless CI/CD integration, and hands-off security. Download the solution brief now!

Solution Brief | CloudGuard WAF: Preemptive Contextual Machine Learning

There's No One-Size-Fits-All Solution The tradeoff between false positives and false negatives is a major challenge in the use of static signatures. A low security level may result in more false positives, whereas a high security level may increase the chances of false negatives. Precise detection is essential in order to maintain web application & API security. The two main issues with the use of signatures are that they cannot guarantee zero-day protection and they are unable to provide a solution to the false positive/false negative tradeoff. Both can lead to loss of business reputation, financial costs, and data breaches.

CloudGuard WAF Preemptive Contextual Machine Learning

The Cloud Killed Signature Based WAF Many of the web application firewall (WAF) solutions utilized today are based on static signatures. Although still in wide use, this conventional method comes with several substantial restrictions that lessen its efficacy. With signatures for new attacks created only after they have been released, a WAF relying exclusively on them will never have the capacity to safeguard against zero-day attacks before they are published. This is especially relevant given that, for the most part, a security gap generally remains open in the affected code of an application or library for an extended period before the CVE (Common Vulnerabilities and Exposures) report outlining it is disclosed to the public.

idanso Cross-Out

idanso Cross-Out

Contextual Machine Learning for Premptive Protection CloudGuard WAF preemptively blocks attacks, based on patented contextual AI/ML. AppSec embeds security testing directly into the development pipeline, providing real-time protection. The result is enhanced security, accelerated time-to-market, and greater development efficiency, all achieved without compromising on quality or safety.

No More False Positives CloudGuard WAF accurately eliminates false positives by examining various contextual parameters and determining a final risk score with input from multiple ML engines. Using multiple engine risk analysis provides more accurate decision- making eradicating manual tuning and enabling security admins to operate confidently in Prevent Mode without blocking legitimate requests.

Continuous Learning Web apps enter learning mode to gather environment-specific data and business cases, with multiple CPUs storing and synchronizing information hourly. The system identifies the source, HTTP method, HTTP requests, and every key/value pair, quickly completing its learning before users switch to prevent mode.

CloudGuard WAF is The Only Truly Preemptive WAAP Organizations can no longer bear the costs of inadequate security or vulnerability; with more dangerous threats on the horizon, there is an urgent need for an automated, CI/CD-friendly approach to application protection. Leveraging patented Contextual AI, CloudGuard WAF is transforming the way we defend our applications with a proactive, hands-off solution that safeguards against danger without stalling development.

CLOUDGUARD PREEMPTIVE WAAP 2

1 Attack Indication Engine Trained offline based on millions of requests, both malicious and benign.

Key Inputs: IP, User Agent, Client Side Behavior , Fingerprint (cookies) ,User Behavior

Stage 1: Initial Indicators Risk Score • ML enforcement engine searches for attack indicators

in HTTP requests • Engine is trained using millions of malicious and

benign requests • Scores are given to single and combined indicators • Indicators and their combinations are linked to specific

attack families • Aggregated indicator scores = effective & precise

initial attack decision

Supervised Machine Learning Model

2 Advanced Analysys Engine Built in real time in the protected environment based on case specific traffic patterns.

Key Inputs: Application Awareness, User Reputation, Payload Score, URL Score, Parmeter Score

Stage 2: Advanced Risk Assessment • Stage 1 flagged requests are analyzed in contextual

machine learning engine • Additional contexts such as app structure, user

behavior and content interaction are examined • Model is optimized continuously by analyzing patterns

unique to the environment • False positives are eliminated as part of the decision

making process

Unsupervised Machine Learning Model

Contextual Machine-Learning is the Only Effective Response to Modern Attacks CloudGuard WAF is the ONLY solution to preemptively block zero-day and OWASP top 10 threats, in real-time, without requiring signitures or system updates... it's just there!

CLOUDGUARD PREEMPTIVE WAAP 3

CLOUDGUARD APPSEC PREEMPTIVE WAAP 4

Dec 2022 - CloudGuard WAF Recognized as the Only WAF to successfully block a penetration test by Team82 Claroty Team82 has developed a generic bypass for web application firewalls (WAF). Major WAF products including: AWS, F5, CloudFlare, Imperva and Palo Alto were found to be vulnerable. CloudGuard WAF pre-emptively blocked the attack/bypass, within seconds.

SUPPORTED ENVIRONMENTS

CLOUD • Amazon Web Services (AWS) • Google Cloud Platform (GCP) • Microsoft Azure • VMware

CONTAINERS • Docker • Kubernetes • Kubernetes Ingress

CPU’S • X86 (64 bit)

OPERATING SYSTEMS • CentOS • Debian • Red Hat Enterprise Linux • Ubuntu

PROTECTION CATEGORIES

• Cross Site Request Forgery

• XML External Entity

• Remote Code Execution

• Evasion Techniques

• LDAP Injection

• Path Traversal

• Vulnerability Scanning

• SQL Injection

• Illegal HTTP Methods Invalid input to forms and APIs Bot Scraping and Brute Force Attacks

• Over 2800 Web Specific CVEs

Bullet Proof, Agentless Deployment within Seconds

CLOUDGUARD PREEMPTIVE WAAP 5

Worldwide Headquarters 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com

U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233

www.checkpoint.com/cloudguard/appsec/

© 2023 Check Point Software Technologies Ltd. All rights reserved.

CLOUDGUARD PREEMPTIVE WAAP 5

Licensing Model Description SKU CloudGuard (part of Workloads)

100 workload units, 1Y subscription 1 unit = 10M requests (or serverless / containers)

CP-CGWL-SL-100-1Y

Stand-Alone 100M requests 1Y subscription CP-CGAS-100-1Y

100M additional requests 1Y subscription CP-CGAS-100A-1Y

PAYG 1M yearly requests Use Marketplace Listing

Blank Page Blank Page Blank Page Blank Page Blank Page


Item Type: pdf