Skip to content

Penta Security ( WAPPLES ) 智慧型 Web 應用程式和 API 保護

Penta Security 是一家韓國的網路安全公司,成立於1997年,專注於提供全方位的安全解決方案,涵蓋應用程序安全、數據加密和物聯網(IoT)安全等領域。其核心產品之一是 WAPPLES ,一款領先的 Web 應用防火牆(WAF),以人工智能技術為基礎,能有效地保護網路應用免受各類攻擊。

WAPPLES 特色:
1. 基於邏輯分析引擎 (Logical Analysis Engine)
採用了 Penta Security 自主研發的邏輯分析引擎(Cocep™),與傳統基於簽名的防禦方法不同,它能通過分析攻擊模式的行為邏輯來檢測威脅,大幅降低誤報率並提高檢測準確性。

2. 全面的攻擊防護能力
提供針對各類 Web 攻擊的防護功能,例如:

  • SQL注入攻擊
  • 跨站腳本(XSS)
  • 文件包含漏洞
  • DDOS 攻擊
  • 網站篡改防護

3. 易於部署和管理
支持多種部署方式,包括內嵌模式、旁路模式和混合模式,以滿足不同網路環境的需求。它還具有用戶友好的管理界面,便於監控與配置。

4. 實時監控與報告
提供詳細的報告和分析功能,用戶能夠通過儀表板即時掌握應用安全狀況。

5. 高效能與擴展性
無論是處理大量流量還是面對複雜的攻擊場景,WAPPLES 都能保持穩定的性能,並適應企業需求的增長。

WAPPLES 的核心優勢:
1. 高準確率的威脅檢測

  • 邏輯分析引擎(Logical Analysis Engine)
  • 與傳統的簽名基礎檢測不同,WAPPLES 採用了 Penta Security 自主研發的邏輯分析引擎(Cocep™)。該技術通過分析攻擊行為的邏輯而非依賴固定簽名,能夠更準確地檢測新型和變種攻擊
  • 低誤報率與漏報率
  • 相較於依賴模式匹配的傳統 WAF,邏輯分析減少了誤報和漏報的發生,提升了檢測的可信度

2. 全面覆蓋的安全功能
支持防禦多種類型的攻擊,包括但不限於:

  • SQL 注入
  • 防止未經授權的數據庫操作
  • 跨站腳本(XSS)
  • 保護用戶端免受惡意腳本影響
  • 文件包含漏洞(LFI/RFI)
  • 阻止惡意文件的調用或執行
  • DDOS 攻擊緩解
  • 提供針對應用層的分佈式拒絕服務攻擊的防護
  • Zero-day 漏洞防護
  • 通過行為分析檢測未知威脅
  • 支持 API 安全性保護,適應現代化應用架構需求

3. 易於部署與靈活性

  • 多樣化部署模式
  • 內嵌模式(Inline mode)
  • 提供即時防護,適合高安全要求場景
  • 旁路模式(Bypass mode)
  • 適合測試或輕量化的部署需求
  • 支持混合雲與虛擬化環境
  • 無需修改現有架構
  • 快速集成,降低部署成本和時間

4. 高性能與穩定性

  • 低延遲設計
  • 即使在高流量環境中,也能保證網路性能不受明顯影響
  • 高併發支援
  • 適合應用在高流量電子商務網站或大型組織中

5. 可視化管理與實時監控

  • 提供直觀的儀表板,用戶可以快速了解安全狀態
  • 支持詳細的報告功能,包括攻擊趨勢分析和威脅統計數據
  • 實時報警功能,幫助安全團隊即時響應潛在威脅

6. 合規性支持

  • 符合主要安全標準和法規的要求,例如:
  • PCI-DSS(支付卡行業數據安全標準)
  • GDPR(歐盟通用數據保護法規)
  • ISO 27001

7. 成本效益高

  • 降低運營成本
  • 通過高效的威脅檢測和低誤報率,減少了對安全事件的誤處理需求
  • 軟硬體靈活選擇
  • 支持硬體設備、軟體解決方案以及雲端部署,滿足不同預算需求

8. 合規性支持

  • 協助企業滿足多項合規性要求(如GDPR、HIPAA、PCI DSS等)
  • 提供審計和合規報告,簡化法規遵循的流程

9. 品牌信譽與技術支持

  • 領先的市場地位:Penta Security 作為亞太地區網路安全領域的領導者,擁有良好的品牌信譽和豐富的行業經驗
  • 專業的技術支持:提供全天候技術支持,確保系統穩定運行

WAPPLES 作為一款功能強大的 Web 應用防火牆(WAF),適用於多種行業和場景,特別是那些依賴網路應用的企業和組織。以下是一些主要的應用場景和適用行業:
1. 金融業:金融機構如銀行、證券交易所和保險公司,面臨著高風險的網路攻擊,特別是針對網上銀行、支付網關和用戶數據的攻擊。WAPPLES 提供針對 SQL 注入、跨站腳本(XSS)等常見攻擊的防護,保護用戶數據和交易系統的完整性與機密性。
例如:網上銀行平台、數字支付系統、金融 API 安全

2. 電子商務:電子商務平台經常遭受針對交易數據、用戶信息的攻擊,以及分佈式拒絕服務(DDoS)攻擊。WAPPLES 支持高流量環境,能有效保障用戶交易的安全性,防止用戶數據被竊取或篡改。
例如:線上商店、會員管理系統、第三方支付網關

3. 政府與公共機構:政府網站和服務平台經常成為網路攻擊的目標,例如信息洩露、網站篡改或攻擊公共服務系統。WAPPLES 提供網站篡改防護功能,並能確保系統的穩定性和敏感數據的保密性。
例如:公共服務網站、國民數據平台、政府內部應用

4. 企業內部系統:現代企業依賴多種內部網路應用(如 ERP、CRM),這些系統面臨來自內部和外部的潛在威脅。WAPPLES 提供 API 安全保護、漏洞防禦等功能,確保內部數據和業務邏輯的安全。
例如:業務系統(ERP/CRM)、內部協作平台、API 接口

5. 教育機構 : 大學和教育機構經常遭遇針對學生信息系統和研究數據的攻擊。WAPPLES 可幫助教育機構保護在線課程平台和學生管理系統,防止數據洩露和服務中斷。
例如:線上學習平台、學生和教職工數據庫

6. 雲端應用與服務:提供商雲端環境中的 SaaS、PaaS 和 IaaS 平台需要應對動態的威脅,並確保多租戶數據的隔離性和安全性。WAPPLES 支持虛擬化和混合雲部署,為雲應用提供靈活且高效的安全解決方案。
例如:雲平台 API 安全、虛擬化環境保護、多租戶數據安全

7. 健康與醫療行業:醫療機構需要保護患者數據(如電子病歷)免受未授權訪問,同時保證系統的連續性。WAPPLES 的高準確率威脅檢測功能,可有效阻止數據竊取與篡改行為。
例如:電子病歷系統(EMR)、在線預約平台、醫療數據交換

8. 大型活動與娛樂行業:資料流密集的娛樂網站或大型活動網站經常面臨高流量和惡意攻擊。WAPPLES 提供流量管理和分佈式拒絕服務攻擊防護,確保用戶瀏覽體驗順暢無憂。
例如:流媒體平台、票務系統、粉絲互動平台

WAPPLES的多元部署選項集核心優勢:
1. 客戶需求:本地部署(On-Premises):某些客戶對於數據安全性、合規性或內部 IT 策略有嚴格要求,可能無法使用基於雲端的服務(例如 Cloudflare 或 AWS 的解決方案)。對於這類客戶,本地部署的解決方案是滿足其業務需求的關鍵。

2. WAPPLES 的靈活部署模式:

  • 支援多模式:不僅具備 SaaS 模型的雲端部署能力,還支持本地部署(On-Premises),滿足不同業務場景的需求。
  • 本地部署選項:提供硬體設備 (HW) 和軟體設備 (SA) 兩種形式,客戶可根據自身 IT 基礎設施與需求靈活選擇最適合的方案。

3. 專業的安全功能:WAPPLES 的核心競爭力在於其針對 Web 應用的成熟防護功能,能有效抵禦多種網路威脅,同時滿足各項合規要求,是客戶提升安全性的理想選擇。

WAPPLES 的卓越檢測準確性、全面攻擊防護能力、操作便捷性及部署靈活性,使其成為企業應對多變網路威脅的最佳解決方案。特別是對於追求高效能與穩定性的企業,WAPPLES 是值得信賴的首選防線。

關於 Penta Security
Penta Security 是全球網絡安全、數據安全和物聯網安全領域的領先供應商,擁有 27 年的專業經驗,被 Frost & Sullivan 評為亞洲頂級網絡安全公司。自 2009 年以來,其 Web 應用防火牆 WAPPLES 連續 16 年在韓國市場保持領先地位,並自 2016 年起在整個亞太地區佔據主導市場。此外,Penta Security 也在歐洲、中東及北美市場有所布局。

關於 Version 2 Digital
資安解決方案 專業代理商與領導者
台灣二版 ( Version 2 ) 是亞洲其中一間最有活力的 IT 公司,多年來深耕資訊科技領域,致力於提供與時俱進的資安解決方案 ( 如EDR、NDR、漏洞管理 ),工具型產品 ( 如遠端控制、網頁過濾 ) 及資安威脅偵測應 變服務服務 ( MDR ) 等,透過龐大銷售點、經銷商及合作伙伴,提供廣被市場讚賞的產品及客製化、在地化的專業服務。

台灣二版 ( Version 2 ) 的銷售範圍包括台灣、香港、中國內地、新加坡、澳門等地區,客戶涵 蓋各產業,包括全球 1000 大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企業及來自亞 洲各城市的消費市場客戶。

Cloudbric Managed Rules for IP Reputation Management

In establishing security through solutions such as firewalls, IP Reputation is a crucial metric for identifying and blocking malicious traffic. It assesses the risk of an IP using factors such as traffic volume, traffic type, presence of malware, and whether the IP has been involved in illegal activities like hacking or phishing. Managing IP Reputation is an important aspect of web security as traffic can be allowed or blocked based on the credibility of IPs, which is determined by their history.

Cloudbric Managed Rules for IP Reputation Management

Penta Security provides a solution for managing IP Reputation through “Cloudbric Managed Rules.”

🛡️ Malicious IP Protection

Cloudbric Managed Rules for AWS WAF – Malicious IP Protection was created to protect the websites and web applications against the traffic originating from various threat IPs. It utilizes the Threat DB of Cloudbric Labs, which collects and analyzes the threat intelligence from 700,000 websites in 148 countries to create a Malicious IP Reputation list and respond to the Malicious IP traffic.

🛡️ Anonymous IP Protection

Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection provides integrated security against Anonymous IPs originating from various sources including VPNs, Data Centers, DNS Proxies, Tor Networks, Relays, and P2P Networks. It utilizes the Anonymous IP list, managed and updated by Cloudbric Labs, to detect and respond to Anonymous IPs that can easily be exploited for malicious purposes and prevent threats such as geo-location based fraud, DDoS, or license and copyright infringements.

 

Cloudbric Managed Rules for AWS WAF

Cloudbric Managed Rules for AWS WAF is created based on the security technologies and expertise of WAPPLES which has protected the web services for enterprises since 2005. Cloudbric Managed Rules have recently proven its performance by displaying a detection rate of 97.31% against other Managed Rules, which has been validated through a report (Penta Security Cloudbric Managed Rules – Comparative Effectiveness of the API Security-Related Managed Rule Groups for AWS WAF) published by an independent third-party IT testing, validation, and analysis organization, The Tolly Group.

✅ Expertise in Security

Cloudbric Managed Rules for AWS WAF utilizes the latest threat intelligence collected and analyzed by Penta Security’s own Cyber Threat Intelligence (CTI) to respond to web threats against web applications and APIs.

✅ Continuous Security Management

Cloudbric Managed Rules respond to the latest threats and maintain a stable level of security through continuous updates and management by security experts with over 20 years of experience in the field.

✅ Official Partner of AWS

Penta Security is an official launch partner for AWS WAF Ready, provider partner of AWS Activate, and AWS Public Sector Partner, and all Cloudbric products provided in AWS Marketplace by Penta Security have been validated by AWS through the Foundational Technical Review.

 

If you are looking to establish a safe web security environment without the need of security expertise, subscribe to Cloudbric Managed Rules for AWS WAF today!

👉 For more information
👉 To subscribe to Cloudbric Managed Rules

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Anonymous IP: Why You Should Block It and How.

AnonymousIP(1)

In February 2016, the global content streaming service, Netflix, officially announced that it would block all VPNs and proxy use on its platform. This decision came as a response to the abuse of Anonymous IPs, which had been a persistent issue for the service. Although many users would employ Anonymous IPs for privacy and security reasons, some exploited them for illegal purposes. One example was Netflix users using VPNs to bypass the geo-restrictions on contents that are not available in their region. The geo-restrictions were put in place due to licensing agreements, but users soon discovered that accessing the platform through an IP from another country allowed them to stream the geo-restricted content. As a result, Netflix was forced to address the issues related to license and copyright infringement.

 

Anonymous IP utilizes methods such as VPNs, Tor Nodes, Proxies, and Data Centers to mask the IPs and the geolocation to protect the privacy of the user and provide a secure access to the web. However, it is also a double-edged sword that can very well be used for illegal activities such as:

  • Manipulation of public opinion or reviews.
  • Distribution of malware while concealing the distributor’s identity.
  • Bypassing geo-pricing, which violates company policy.
  • License and copyright infringement.
    As such, detecting and blocking Anonymous IPs can be a smart move for companies and organizations of all industries to reduce the risk of cyber threats.
    Many companies and organizations already make use of various solutions to respond to Anonymous IPs. Like Netflix, a significant number of content streaming services and other companies in the media & entertainment industry have adopted Anonymous IP-related solutions to protect their media contents. Some companies use Anonymous IP-related solutions to prevent DDoS attacks carried out by zombie PCs infected via Data Centers. Online game companies block illegal access to geo-blocked servers, and finance companies, including cryptocurrency platforms, prevent fraud by blocking attempts to bypass the geolocation restrictions.
    Such solutions are largely categorized into two types: IP Reputation Database (often referred to as “IP Reputation Checkers”) and IP Reputation Filters. There are pros and cons to both types of solutions, and the choice between them depends on the available resources and the needs of the user.
    IP Reputation Database IP Reputation Filters
    • Focuses on providing detailed information about the IPs.
    • Such information includes the method of creating Anonymous IPs, geolocation data, and domain information.
    • The IP Reputation Database is constantly updated.
    • The user is given more flexibility as the user can utilize the information to configure the security settings as fit.
    • However, a deep understanding of security is required for the user to configure a robust security.
    • Because the IP Reputation Database is constantly updated, the user has to subscribe to the database service, and in many cases, the user may be charged per query.
    • Focuses on providing a proactive security solution by detecting and blocking the traffic based on the Anonymous IP list.
    • IP Reputation Filters are often included in a Web Application Firewall (WAF) solution, and do not provide as much flexibility as the users configuring the security settings themselves.
    • The performance of the IP Reputation Filter may depend on the source of the Anonymous IP list, update cycle, and the performance of WAF.
    • However, users do not need expert-level security knowledge.
    • Security measures can be quickly implemented.
    • Resources required in configuring the security settings are greatly reduced.
    •  
      • Penta Security’s direction in responding to Anonymous IPs is IP Reputation Filters. Penta Security currently provides a managed rule group, Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection, in the AWS Marketplace.
    •  

    AnonymousIP(2)

    •  
      • Taking advantage of the characteristics of managed rule groups for AWS WAF, which enables the user to quickly adopt the security rules predefined by security vendors simply through subscribing to the product, Penta Security provides a quick and easy solution for AWS WAF users to detect and block any threats that can be caused by Anonymous IPs. Penta Security’s Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection is defined based on the Anonymous IP List, which is continuously updated with the latest IP Reputation data, collected and analyzed by Penta Security’s own Cyber Threat Intelligence (CTI). With a cost efficient, pay-as-you-go pricing, users are able to implement a robust security solution against Anonymous IPs without the need for security expertise by subscribing to the product.
    •  
      • Cloudbric Managed Rules for AWS WAF – Anonymous IP Protection is available at

    👉link.

     

     

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

APIs are Everywhere. Are You Protected from API Attacks?

API security has become a major focus in cybersecurity in recent years. The global research firm, Gartner recognized the importance of API security and proposed a new model of web application security, which they named Web Application and API Security (WAAP). API, which stands for Application Programming Interface, is a mechanism that enables two software components to communicate with each other using a set of definitions and protocols. APIs are generally used to provide access to data and services, allowing the developers to build new applications and tools by leveraging existing data and functionality.

 

For instance, if a new food delivery app requires a map to display local restaurants, it would be inefficient for the developers to create a new map and gather all the restaurant data themselves. Instead, they could use an existing map API, such as Google Maps, to retrieve the necessary data for their app.

 

APIs are becoming indispensable in modern software development because of its;

  • Interoperability
    • APIs facilitate interoperability between software systems, and by using APIs, applications and services developed by different developers would work together, share data, and provide integrated solutions
  • Modular Development
    • APIs allow complex systems to be divided into smaller and more manageable components, making software development, testing, and maintenance easier. Developers can focus on building and updating specific functionalities.
  • Cross-Platform Integration
    • APIs enable cross-platform integration, allowing applications to work across different devices and environments.
  • Data Access and Sharing
    • APIs define a structured way for data to be exchanged between applications, usually formatted in JavaScript Object Notation (JSON) or Extensible Markup Language (XML). This standardization ensures that both the requesting application and the providing system can easily interpret and process the data.

 

Despite their benefits, not all APIs are built with security measures, and an increasing number of organizations have reported attacks targeting APIs, resulting in significant damage to their services. Such was the case with Duolingo. Duolingo is a company that services a vastly popular language learning application. It is estimated that by the end of Q1 2022, Duolingo’s monthly active users reached 49.2 million. Naturally, due to its massive volume of user data, Duolingo’s user database became a target for hackers. In January 2023, scraped data of 2.6 million Duolingo users appeared on the dark web hacking forum called “Breached.” The scraped data included email addresses, personal names, usernames, and other user profile information.

 

screenshot courtesy of FalconFeedsio

 

It is believed that the hacker acquired the user data by infiltrating Duolingo’s API vulnerability. Duolingo’s API provided access to user information based solely on email or username without asking for any other forms of verification. The API did not take any security measures to ensure that the requests were coming from legitimate users, thus the access to user data was not restricted. This incident would be categorized under two vulnerabilities of OWASP Top 10 API Security Risks: 

  • API2:2023 – Broken Authentication
  • API3:2023 – Broken Object Property Level Authorization (BOLA) 

As API has become a target for hackers, establishing API security became an important task for any organizations or businesses providing services that include APIs. There are already numerous solutions for API security in the market, but the important question to ask is: which of the solutions best fit my environment?

 

As there are a myriad of APIs for different purposes, solutions for API security can also take many different directions and approaches. For instance, some may focus on specific vulnerabilities of APIs, such as Injection attacks or Broken Authentication, while some may focus more on API Discovery. Some may even choose to focus more towards API Gateway. There is no definitive answer to what type of solution is best. Therefore, it is important that organizations and businesses carefully assess their environment and needs before adopting a solution.

 

Penta Security’s direction in establishing API security was to build a solution that focuses on the actual API attacks and vulnerabilities. Penta Security has recently launched a managed rule group for AWS WAF, Cloudbric Managed Rules for AWS WAF – API Protection (API Protection). Taking advantage of the characteristics of managed rule groups for AWS WAF, which enables the user to quickly adopt the security rules predefined by security vendors simply through subscribing to the product, Penta Security provides a quick and easy solution for AWS WAF users to detect and block API attacks. API Protection was created to provide security against the threats of OWASP API Security Top 10 Risk. To respond to the attacks and vulnerabilities of API, API Protection utilizes the API attack data gathered and analyzed by Penta Security’s own cyber threat intelligence (CTI) and establishes security against known API attacks. Furthermore, API Protection provides validation and protection for XML, JSON, and YAML data. API Protection was recently validated to have the highest detection rate among API Security managed rule groups currently provided in AWS Marketplace through a comparative test conducted by a third-party IT testing, validation and analysis company, The Tolly Group.

 

The Tolly Group – 3rd-party IT Testing, Validation, & Analysis

 

With a cost efficient, pay-as-you-go pricing, users are able to implement a robust API security without the need for security expertise, just by subscribing to the product.

Cloudbric Managed Rules for AWS WAF – API Protection is available at 👉link.

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to Utilize Cloudbric Managed Rules to Its Maximum Potential

AWS WAF, according to AWS, is a web application firewall (WAF) that helps protect web applications from attacks by allowing you to configure rules that allow, block, or monitor (count) web requests based on conditions that you define, such as IP addresses, HTTP headers, HTTP body, URI strings, SQL injection, and cross-site scripting. While it is undoubtedly a powerful tool to establish security for your websites and web applications, it requires users to have a certain level of security expertise to utilize the service to its fullest potential.

When the user first adopts AWS WAF, the user is responsible for implementing the security rules¹ for AWS WAF. AWS WAF provides the user with options to either create their own rules or adopt managed rule groups².

How to Utilize Cloudbric Managed Rules to Its Maximum Potential

Without the proper security rule configurations, AWS WAF cannot function or operate properly. Consequently, the users would have to have some level of understanding of how security rules work and what kind of security rules they need.

  1. Security Rules : Statements that define the conditions on how to inspect the HTTP/HTTPS web traffic, or requests, made to the web applications. If the request matches the conditions, it is met with the rule action, such as Allow, Block, and Count, that is configured for the security rule.
  2. Managed Rule Groups : A preset of security rules created by AWS and the Independent Software Vendors (ISV) for the users.

What are Cloudbric Managed Rules?

One such example of managed rule groups that the users can implement for AWS WAF is “Cloudbric Managed Rules.” Cloudbric Managed Rules (CMR) is a managed rule group product provided by Penta Security. 

CMR was created based on the security technologies and expertise of Penta Security’s WAF product, WAPPLES, which has protected web services for various organizations and enterprises since 2005. CMR utilizes Penta Security’s own Cyber Threat Intelligence (CTI), Cloudbric Labs, to provide a safer online environment for AWS WAF users.

Penta Security is not only one of the seven ISVs worldwide that offers managed rule groups for AWS WAF but also the only ISV to enable the Web Application and API Protection (WAAP) model by integrating managed rule groups with AWS WAF. There are a total of 6 different CMR rule groups currently provided in AWS Marketplace, which are able to be implemented on the AWS WAF simply by subscribing to the product.

Cloudbric Managed Rules for AWS WAF Product List

OWASP Top 10 Rule Set
Provides security against threats from OWASP Top 10 Web Application Security Risks, such as SQL Injection and Cross-Site Scripting (XSS) utilizing the logic-based detection engine recognized by world-renowned research organizations such as Gartner and Frost & Sullivan.

API Protection
Provides security against the OWASP API Security Top 10 Risk by establishing a defense system against known API attacks and providing validation and protection for XML, JSON, and YAML data.

Anonymous IP Protection
Provides integrated security against Anonymous IPs originating from various sources including VPNs, Data Centers, DNS Proxies, Tor Networks, Relays, and P2P Networks, responding to threats such as geo-location frauds, DDoS, and license and copyright infringement.

Malicious IP Protection
Provides security against malicious IP traffic based on the Malicious IP Reputation list created using ThreatDB, which is collected and analyzed from 700,000 websites in 148 countries worldwide by Cloudbric Labs, Penta Security’s own Cyber Threat Intelligence (CTI).

Bot Protection
Provides security against malicious bots, such as scrapers, scanners, and crawlers, which negatively impact and damage websites and web applications through repetitive behavior, based on the malicious bot patterns collected and analyzed by Penta Security.

Tor IP Protection
Provides security against Anonymous IP traffic, specifically originating from the Tor network, which can be difficult to detect using an ordinary IP Risk Index, utilizing the Tor IP list managed and updated by Cloudbric Labs.

CMR is continuously updated and managed by the security experts of Penta Security to respond to the latest security threats and maintain a stable security level, boosting the AWS WAF experience for the users.

CMR has also recently been validated to have the highest detection rate through a comparative test conducted by a 3rd party IT testing, validation, and analysis company, The Tolly Group.

OWASP Top 10 Category Test

[Comparative Test Results for OWASP Top 10 Rule Set]

[Comparative Test Results for API Protection]

Optimizing Cloudbric Managed Rules to your environment

Managed rule groups for AWS WAF are designed to provide the users with a basic setup for security and allow the users to add conditions, such as IPs, specific headers, or regions, by creating additional rules when a new threat is identified. This is known as the Blocklist method (also known as Blacklist method). Blocklist method is widely preferred for managed rule groups as it can reduce false positives, but ultimately, the users would have to continue to add more and more rules as they progress, only after the threat or attack has occurred. CMR also utilizes the Blocklist method, but to minimize the burden of adding the rules for the users, CMR provides managed rule groups with maximum security configurations. CMR is continuously updated with the most recent Cyber Threat Intelligence to respond to new threats and vulnerabilities. In doing so, CMR can detect and block more potential threats and attacks compared to any managed rule groups provided in AWS Marketplace, and if a false positive occurs, the users would simply need to override the rule that responded to the legitimate request, instead of having to create a new rule to respond to the new malicious request. Overriding a rule can simply be achieved by clicking a few buttons, and this method can provide more stable security.

Optimizing Cloudbric Managed Rules to your environment

To determine whether a request should be overridden or remain blocked, it is important to analyze your detection logs. Each rule within the managed rule group is defined with a rule action that responds to the request when it matches the condition of the rule. These rule actions include “Allow,” “Block,” and “Count.” Also, the users can adjust the priority of the rule, and the request will pass through the rules in the order of highest priority to the lowest.

If the rule action defined for the rule is Allow, the request will pass through the rule, even if the request matches the conditions defined in the statement of the rule. The request will also not be logged. Allowing a rule will have all the subsequent rules to allow the request as well, so if you want a certain rule to allow the request, it is recommended that the rule is configured to have the lowest priority, as it will minimize the effect it has on the other rules. If the rule action defined for the rule is Block, the request will not pass through the rule, if the request matches the conditions defined in the statement of the rule. The request will then be logged as having been blocked. If the rule action defined for the rule is Count, the request will pass through the rule without being blocked, even if the request matches the conditions defined in the statement of the rule. However, the request will be logged.

When you decide to change the default rule actions defined for the rules, it is recommended that the rule action for the rule is first changed to Count to evaluate the impact. You must analyze your detection logs carefully while keeping your rule action to Count before deciding whether to override the rule. It is also a good idea to run your rules while having the rule action as Count when you are creating your own security rules.

From time to time, CMR will be updated with a newer version. When it is updated with a newer version, you will be notified by AWS Marketplace, and you will be given the option to update the managed rule groups to a newer version or to use the previous version. When a new version of the managed rule group is updated, the updates to the managed rule group will not be automatically applied to the product you are currently subscribed to, as updating to a newer version of managed rule groups may cause the configurations you made to the rules to revert to default state. If you wish to use the newer version of the managed rule group, you can access the AWS WAF management console to change the version of the managed rule group.

AWS WAF Management service, “Cloudbric WMS.”

While CMR was developed to facilitate the process of implementing security rules for AWS WAF, it can still be challenging if you do not have in-house personnel with security expertise. It can be quite unclear as to what threats you must watch out for or which origin IP must be blocked. Analyzing and optimizing the security rules can also be quite difficult if you do not fully understand your infrastructure and environment.

Cloudbric WMS, AWS WAF Managed service, Penta Security, Cloudbric

Cloudbric WMS for AWS WAF

Cloudbric WMS for AWS WAF is a management service developed by Penta Security for AWS WAF users. When Cloudbric WMS is adopted, the security experts of Penta Security analyze your infrastructure and environment to adjust the conditions of the statement and optimize the rules for you. After the optimization of the security rules is completed, you are given access to Cloudbric WMS console, which provides you with an overview of your environment and security status. Cloudbric WMS enables the users to add countries or origin IPs to block through an easy-to-use GUI and provides detailed reports with all the information you need to reinforce your security.

Cloudbric WMS also offers customer support in English, Japanese, and Korean, to respond to any issues or inquiries you may have in operating your WAF.

Penta Security is an official launch partner for AWS WAF Ready, a provider partner of AWS Activate, and an AWS Public Sector Partner. 

All Cloudbric Products provided in AWS Marketplace have been validated by AWS through the Foundational Technical Review.

AWS Partner

For more information on Cloudbric WMS, please visit: 👉Cloudbric  

You may also refer to the “Cloudbric Managed Rules for AWS WAF Setting Guide” for more details on how to subscribe, implement, and optimize CMR for your AWS WAF.

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How Cloudbric VPN Protects Your Privacy and Data on Public Wi-Fi

Do you want to surf the internet anonymously and protect your data and identity at all times? If yes, you need a VPN service that provides end-to-end encryption and anonymous usage. In this article, we will understand what a VPN is, how Cloudbric protects your privacy, and why you should use Cloudbric VPN.

 

What is a VPN?

A virtual private network, which is often referred to as a VPN, is a network connection where you use an encrypted connection to connect to the public internet. This encrypted connection protects your IP addresses from being tracked on websites and safeguards your data during transit. Moreover, VPNs also help you protect from hackers as the encrypted connections cannot be intruded easily. 

 

Cloudbric VPN

If you are in the market to find the best VPN that lets you browse the internet without any tracking or data collection, you need the Cloudbric VPN for your devices. We offer personalized applications for different web and mobile operating systems to ensure the best user experience when you use our VPN service. 

Cloudbric VPN is created by encryption experts who have built highly secure services for customers in the past. We leverage our expertise from Penta Security and encryption experts to create VPN systems that are safe for usage and provide complete anonymity to our users. You can download our apps from Google Play or the Apple App Store to start today. 

 

Cloudbric VPN Product Page: https://www.cloudbric.com/cloudbric-vpn

Store link

google play

apple app store

 

Before we explore the features of Cloudbric VPN, let’s look at who should use a VPN.

 

Who Should Use A VPN?

Privacy-Conscious Users

VPNs help you protect your data and keep your internet activity private. If you are privacy-conscious or you live in places with heavy surveillance, it is better to use a VPN service. 

 

Remote Workers

Remote workers work from different places, and this can quickly become a remote work challenge when accessing the internal networks of a company. Hence, it is always a better choice to use a VPN when accessing sensitive corporate data while working remotely. 

 

Frequent Travelers

If you are traveling regularly, you may access public Wi-Fi networks at airports or train stations. Such public networks are very easy targets for hackers, and if you connect them without a VPN, your device may get compromised. So, if you are a frequent traveler, always use a VPN. 

 

Users from Censored Regions

Governments across the world censor many websites and restrict access for general users. If you live in any such censored regions, it makes sense to use VPN services so you can access censored websites and surf the internet freely. 

 

People Avoiding Bandwidth Throttling

Many internet service providers can block or throttle internet usage based on IP addresses. When you want to have unthrottled internet usage and bypass ISP throttling limits, you should use VPNs.

 

People Sharing Networks Or Devices

If you share your devices or networks with multiple people but still want to keep your internet footprint anonymous, you can rely on a VPN service. This way, your activity on the device or network will remain private. 

 

Knowing who should use a VPN, you should also know how Cloudbric VPN protects your privacy.

 

How Cloudbric VPN Protects Your Privacy and Data on Public Wi-Fi

Using public Wi-Fi is always a risky thing, but if you have a Cloudbric VPN connection, you are safe. Let’s understand how we protect your privacy and data on such networks. 

 

Encrypted Internet Traffic

Cloudbric VPN relies on the latest encryption technologies and uses them to encrypt internet traffic that goes from your devices to the internet. This is an important feature that protects your traffic even if your network gets compromised anyhow. 

 

Masks IP Address

Our VPN service will route your internet traffic through various internal servers and hide your real IP so no one can trace the request back to you. We also keep your IP address safe when forwarding responses back to your original device.

 

Enhances Security On Unsecured Networks

If you are on an unsecured network, we take all necessary steps to keep your data secured. We create a secure tunnel for your data and connections so that your security is never compromised. 

 

Safeguards Data

Through our strong encryption and data security standards, we safeguard your data. Our VPNs will help you safely log in to websites and access restricted content and financial data.

 

As you know, we protect your data and privacy, so let’s seal the deal by looking at more reasons why you should choose Cloudbric VPN service for your Android and iOS devices. 

 

Why choose Cloudbric VPN?

While there are many more VPN service providers in the world, there are a few that match our standards. With so many choices, it often confuses customers, but don’t worry. In this section, we will explore why you should choose Cloudbric VPN. 

 

Easy to use

Cloudbric VPN apps are designed with a customer-centric mindset. This ensures that our apps are easy to use forever. Using our apps, with just a single click, you can access the internet securely by connecting through our VPN servers. We always encrypt all your online activity with just one click. 

 

Strict privacy protection

Having strict privacy protection is a must for VPNs. We have a no-logs policy, which is enforced strictly. Through this policy, we ensure that no user information is logged, collected, or shared with anyone. No matter what your internet traffic is, it is always protected because of our strict security stance. To make things much more secure, we also use a private DNS service so that your DNS queries never go to public DNS providers. 

 

Fast speed with high-performance protocol

Many VPN service providers provide very little speed to customers, but we don’t do that. We believe in giving our consumers the best speed so that they don’t feel they are accessing the internet through an intermediary service. Our blazing-fast WireGuard protocol provides a secure and fast internet connection to all connected users with minimal latency. Moreover, our connection protocols are highly available, and there’s little downtime to ensure you are always safe. 

 

Advanced security technology

At Cloudbric VPN, everything we do is aimed at increasing the security technology for our services. We focus on security and providing the safest online experience to our customers across the globe. We are utilizing the expertise of our specialists to research new security protocols and approaches to make the internet safer for everyone. 

 

Reasonable price

We believe in providing quality products at a reasonable price to reach more customers and make internet browsing safer for everyone. If you are in the market for a safe yet affordable VPN provider, download our apps and subscribe to Cloudbric VPN services today. 

 

Before we come to an end, let’s look at some common misconceptions about VPN usage.

 

Common Misconceptions about VPNs

Free VPN is as Good as a Paid One

Many people think that all VPNs are the same, and there is no need to get a paid VPN service. But this is quite wrong. A free VPN will lack encryption and privacy, moreover it may log user data which can be used to trace requests back to you. 

 

VPNs Slow Down Internet Speeds Drastically

Yes, VPNs slow down internet speeds, but they don’t make a big difference. If you use a paid VPN service like Cloudbric provides highly optimized servers for customers, so there is a minimal speed reduction.

 

Conclusion

In today’s interconnected world, protecting your online privacy and data is essential, especially on public Wi-Fi networks. Cloudbric VPN offers a reliable, secure, and user-friendly solution to safeguard your internet activity. With advanced encryption, IP masking, and a no-logs policy, Cloudbric VPN ensures your data remains private and inaccessible to hackers or surveillance. 

Unlike free VPNs, Cloudbric VPN delivers unmatched protection without compromising speed or performance. Whether you’re browsing, accessing sensitive corporate data, or bypassing geo-restrictions, Cloudbric VPN empowers you to surf the web securely and anonymously. 

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Next-Level Protection against Malicious IPs with Cloudbric Managed Rules

In the rapidly evolving digital landscape driven by the rise of digital transformation (DX), companies are increasingly shifting their business and operations to be more software-centric. This shift has brought application development to the forefront, making robust cybersecurity—especially web security—a critical requirement. At the core of web security, IP-based rules have long been a foundational method for controlling access and mitigating threats. However, as cyber threats grow in complexity, traditional IP-based rules face significant limitations. Cloudbric Managed Rules (CMR) offers an advanced solution to overcome these challenges and provide comprehensive protection, including support for X-Forwarded-For (XFF) header validation.

What Are IP-Based Rules? 

IP-based rules are a foundational security mechanism that allows or blocks access based on IP addresses. These rules are widely used in network and web security systems for the following purposes:

    • Regulatory Compliance: Certain industries require restricted access to ensure regulatory adherence by permitting only specified IP ranges.
    • Threat Protection: Proactively block malicious IP addresses, such as those used by hackers or bots.

 

Key Use Cases for IP-Based Rules 

Network Load Management

IP-based rules can help mitigate server overload caused by distributed denial of service (DDoS) attacks by proactively blocking suspicious IPs.

Geo-Restricted Services

Organizations can control service accessibility by allowing only specific IP ranges based on geographic regions, addressing regional licensing or compliance requirements.

Integration with Web Application Firewalls (WAFs)

Modern WAFs incorporate databases of known threat IPs to automatically block malicious traffic, creating a secure environment.

 

The Limitations of IP-Based Rules and How Cloudbric Managed Rules Address Them

Limitations of Traditional IP-Based Rules

IP-based rules are a widely used method for managing web application traffic, offering simplicity and efficiency. However, they come with several limitations that reduce their effectiveness in modern, complex environments:

  1. Source IP Dependency
    Traditional IP-based rules rely heavily on the source IP address of incoming traffic. This dependency poses challenges when proxies, load balancers, or VPNs are involved, as these intermediaries mask or spoof the origin IP. This masking reduces the accuracy of malicious IP detection.
  2. Resource Intensiveness
    Processing a high volume of requests, especially in environments with frequent malicious traffic, can strain system resources such as CPU and memory, impacting overall performance.

How Cloudbric Managed Rules Overcome These Challenges

Traditional IP-based methods detect malicious activity by comparing the source IP of an incoming request against a database of known threat IPs. While effective in straightforward cases, this approach struggles with the limitations mentioned above.

Cloudbric Managed Rules enhance this process by performing additional inspections of X-Forwarded-For (XFF) headers, a common HTTP header that reveals the original client IP address when proxies or load balancers are used. By analyzing the XFF header, Cloudbric can accurately identify the true origin IP and cross-check it against Penta Security’s proprietary database, ThreatDB.

ThreatDB provides a robust, dynamic repository of known malicious IPs, offering higher accuracy and fewer false positives than traditional static databases.

 

Overcoming These Challenges with Cloudbric Managed Rules

Cloudbric Managed Rules is a next-generation security solution designed to address the limitations of traditional IP-based rules by offering the following features:

Enhanced Accuracy with Flexible IP Detection

Traditional IP-based detection often faces challenges in identifying the true source of traffic, especially in environments involving proxies, VPNs, or other intermediaries. Cloudbric Managed Rules enhances detection by leveraging sophisticated methodologies that account for these complexities.Unlike the default approach of other managed rule groups, which may lack the ability to fully validate traffic originating from such masked sources, Cloudbric’s solution provides a broader perspective, ensuring more comprehensive threat detection.

Key Offerings

  1. Malicious IP Protection
    • Blocks malicious IP traffic based on ThreatDB’s globally curated threat intelligence.
    • Prevents attacks from malicious bots, hackers, and phishing attempts.
  2. Anonymous IP Protection
    • Detects and mitigates threats from anonymous IP sources, such as VPNs, proxies, and Tor networks.
    • Prevents DDoS attacks and unauthorized content usage.

 

 

Conclusion

Cloudbric Managed Rules provides a comprehensive solution for modern web security challenges. By combining advanced IP detection with continuous threat intelligence and a robust detection engine, it empowers organizations to:

  • Protect networks and applications from malicious and anonymous IPs.
  • Maintain operational stability.
  • Meet regulatory compliance requirements.

 

For more information, explore the AWS Marketplace Penta Security Official Page.

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

[Penta News] Penta Security Revamps Brand Identity to Strengthen Global Market Presence

Penta Security Revamps Brand Identity to Strengthen Global Market Presence

 

Penta Security has undertaken a comprehensive reorganization of its product brand identity (BI) to enhance its competitiveness in the global market.

The company offers a wide range of cybersecurity products and services, including the optimized encryption framework D.AMO, the intelligent WAAP solution WAPPLES, and the cloud security SaaS platform Cloudbric. These products have established Penta Security as a leading player in the Asia-Pacific cybersecurity market across multiple sectors.

 

 

Celebrating its 20th anniversary this year, D.AMO is an optimized encryption framework that provides comprehensive security for all layers of IT systems across diverse environments. It offers integrated data security features such as key management, access control, auditing, and monitoring, ensuring end-to-end data protection.

WAPPLES is an intelligent WAAP (Web Application and API Protection) solution that goes beyond traditional web application firewalls. It provides API security, bot mitigation, and DoS defense capabilities. Powered by its proprietary intelligent detection engine COCEP, WAPPLES achieves a false-positive rate of under 4%, ensuring high precision in detecting web attacks.

Cloudbric is the first SaaS-type security platform in Korea and is a leading brand in the SaaS-type security platform industry. From IoT & End Point security to enterprise web security, we provide services safeguarding all entities requiring an Internet connection. As a SaaS-based solution, Cloudbric provides top-tier security services online without the need for hardware installation, offering unparalleled convenience and scalability.

 

Through this brand identity revamp, Penta Security has unified its product logos and branding, which previously lacked a consistent look due to the staggered release of products since the company’s start in 1997. The new, streamlined designs reflect a modern style, presenting a brand image of “youth and professionalism”. This refreshed identity reflects the company’s core philosophy: all solutions align under a single vision and goal. The unified brand identity is expected to enhance Penta Security’s competitiveness, foster innovation, and support its expansion into global markets.

 

Looking ahead, Penta Security is committed to creating an open world where information can be freely shared and communicated. Stay tuned as Penta Security continues its journey to becoming a global leader in cybersecurity. Thank you for your continued interest and support.

 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Penta Security Launches a Cloud Security Provider WAF Managed Service on AWS Marketplace

 

Penta Security, a leading cyber security company and provider of web application security in the Asia-Pacific region, announced that Penta Security’s Cloudbric WMS has officially launched a usage-based SaaS subscription model on AWS Marketplace in December of 2024.

Cloudbric WMS (WAF Managed Service) is a managed service developed for Cloud Service Provider Web Application Firewalls (CSP WAF), such as AWS WAF.

While CSP WAFs are powerful security tools, as CSP WAFs typically require the users to configure the security rules themselves, it can be quite difficult to utilize the CSP WAFs to their full potential.

To address this issue, Penta Security has developed a managed service that optimizes the security rules and provides a dedicated console to monitor the security status for AWS WAF users. When Cloudbric WMS is adopted, the security experts of Penta Security initially analyze the user’s logs and optimize the rules for maximum efficiency fit to the unique environment of the user.

Once the initial security rule optimization process is completed, the user will be provided access to a dedicated console for monitoring and security rule configurations. Through Cloudbric WMS, the user can gain better insight and control of the security rules for their AWS WAF.

The security rules utilized by Cloudbric WMS is based on the security technologies and expertise of Penta Security’s own WAF, WAPPLES, which has protected the web services for enterprises since 2005 and has recently been validated by a third-party testing firm to have a top-tier detection rate. These security rules are also provided in AWS Marketplace in the form of managed rule groups, which are presets of security rules provided by Independent Software Vendors for AWS WAF.

Taejoon Jung, director of the Planning Division at Penta Security stated, “Cybersecurity is always a difficult subject and an area that requires a certain level of expertise. However, it is our vision to provide an easier solution for security. We expect Cloudbric WMS will boost their AWS WAF experiences simply by subscribing to the service.”

Cloudbric WMS for AWS WAF (PAYG) product is available for subscription in the AWS Marketplace. AWS Marketplace is a curated digital store where users can search, evaluate, purchase, distribute and manage solutions provided by AWS Partners.

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Penta Security Accelerates Expansion into the Middle East Cybersecurity Market from Dubai

Cybersecurity corporation ‘Penta Security’ is actively accelerating its entry into the Middle East security market by participating in key IT events in the region, including the recently held ‘GITEX 2024’ in Dubai.

In October, Penta Security showcased its innovative solutions at GITEX 2024, the largest IT exhibition in the Middle East, and Expand North Star 2024 in Dubai, UAE. Most recently, the company took part in the Dubai Police-KOTRA Global Startup Week, held from November 11 to 14 at the Dubai Police Headquarters R&D Center. This four-day event, co-hosted by the Korea Trade-Investment Promotion Agency (KOTRA) and Dubai Police, featured 19 Korean companies across various sectors, all specially invited by Dubai Police to present their cutting-edge technologies and explore opportunities for future collaboration.

At the event, Penta Security introduced its advanced cybersecurity solutions to an audience of 500 attendees, including key stakeholders from Dubai Police and other related organizations. The company showcased its collaborative security projects with the Korean national police as well as its international initiatives, such as its work on Advanced Metering Infrastructure (AMI) for smart city and smart transportation security across various regions.

Penta Security showcased its advanced solutions designed to address the increasing demand for data encryption and web security in the UAE’s smart city initiatives. These include D’Amo, an encryption platform; Cloudbric, a cloud security SaaS platform; and iSIGN+, an authentication security platform. Together, these solutions provide the foundational security infrastructure essential for driving smart city innovations.

Taegyun Kim, CEO of Penta Security, stated, “The Ministry of Science and ICT has designated the Middle East cybersecurity market as an emerging strategic market in its 2023 ‘Global Competitiveness Strategy for the Information Security Industry.’ The government is providing robust support to help Korean security companies expand into the region. Based on thorough market analysis, Penta Security aims to use the UAE as a launchpad for further expansion into the broader Middle East and Africa markets.” 

About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.

As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.