In FortiWeb version 6.0, the Self-Learning module has been rewritten from the ground up.
This new Learning Module is based on Artificial Intelligence, specifically Machine Learning, which was the first WAF (Web Application Firewall) to use this technology.
Unlike other WAFs, the Self-Learning module learns without interruption.
In this case, when new applications are added or previously learned applications change (New Forms, Parameters, URLs, etc.), the Self-Learning module will change according to the changes.
Limitations on Traditional WAFsTraditional WAF learns in the first phase, and then a protection profile based on that learning is applied. If an application changes, WAF does not automatically adapt to those changes. WAFs that base their security on signatures are obligated to avoid as they rely on regular expressions. In addition, it produces many False Positives, increasing the hours devoted to the operation of the WAF platform.
Operation method
Anomaly Detection Phase
FortiWeb detects for each request whether there is an anomaly of what has been learned or not.
For example: always enter a field with a maximum of 8-16 characters.
Phase Threat DetectionIf there is no anomaly, this will allow the request to pass, but if an anomaly is detected, it is analyzed by various Artificial Intelligence Databases trained by FortiGuard Labs, rather than directly blocking it. Only if an attack is detected will the request be blocked. This detection Mode does not rely on signatures, so the probability of blocking legitimate requests (False Positives) is almost completely reduced.
For more information on FortiWeb 6.0 news
https://docs.fortinet.com/fortiweb/release-information
Yorumlar
Yorum Gönder