G-SERVER    
 


What is the G-Server?
The G-Server is a multi-function Port 80 and Port 443 protection appliance, designed to protect organizations from the dire consequences of Web site content and application attacks in real time. In addition to protecting Web servers from publishing unauthorized, altered or damaged information, the G-Server also efficiently authenticates incoming HTTP requests.

Why do I need the G-Server?
Relying solely on trusted network security products still leaves your organization’s Web site open to sabotage. That means anything from profanity to corrupt pricing to terrorist demands can suddenly appear on your Web site—creating financial risk exposure as well as lasting damage to your organization’s reputation. Gilian’s G-Server verifies that all content exiting your Web server, as well as every functioning Web application, is authentic and unaltered. This protection, which extends even to dynamic content, automatically stops faulty information and corrupted transactions from ever reaching customers, prospects, investors, and business partners.

What is ExitControl™?
The G-Server is based on ExitControl, breakthrough technology that enables you to verify every piece of static or dynamic content leaving your Web server, as well as every Web application, is authentic and unaltered. ExitControl automatically detects any unauthorized changes to your pages and applications and replaces distorted content and transactions with the correct information. ExitControl also provides immediate notification of the problem and tells you exactly where the problem occurred.

How does ExitControl work?
Your Web site’s legitimate producers of Web content create digital signatures for all new or revised Web objects—such as HTML pages, GIF files, or JPEG files. Located at the exit point to your network, ExitControl uses those digital signatures to verify the authenticity of each page leaving your Web server and intercepts any fraudulent content from exiting. As a result, only approved content is allowed to be published. Click here for more detailed technical information about ExitControl.

What is G-AppPROTECT?
Few corporate Web sites have devices to monitor port 80 and 443 traffic . G-Server fills this void with AppPROTECT technology which halts bogus HTTP and HTTPS requests to the Web server, such as attempts to attack or exploit Web server vulnerabilities.

What is G-AppWATCH?
Our G-AppWATCH feature uses the ExitControl approach to automatically ensure all dynamic processes are authentic. That means G-AppWATCH will not allow Web applications to execute if it is determined that there has been an unauthorized change to the application. As a result, G-AppWATCH prevents you from publishing erroneous dynamic content as well as keeps these applications from causing further damage to your internal corporate network.

What about dynamic content?
G-Server protects both static and dynamic content. With dynamic content, the Web server’s output—that is, price totals, stock prices, and so on—depend on multiple, external programs and resources, such as ASP or CGI scripts and databases that contain the information to be built. To verify the integrity of the dynamic output, digital signatures of all processes, scripts and applications are created and compared in real-time. If any change to the application or script is detected, the application is simply not allowed to execute. As a result, not only is the display of corrupted dynamic content prevented, but all related computing resources to which the applications and scripts have access to are protected as well.

What can hackers do if they gain access to your scripts and applications?
Since your Web applications contain gaps that allow hackers easy entry, they can quickly hack your databases, corporate servers, and create backdoors into your network.

If my site goes down, I can restore it within 30 minutes. So, why do I need the G-Server to keep me available?
Downtime costs organizations enormous amounts of money per hour in terms of repairs costs, lost revenues, and damaged goodwill. The bottom line is few companies can afford shutdowns while administrators try to find and fix a corruption. Regardless of the type of attack, the G-Server keeps the Web site available with authentic content. In fact, visitors will not even be aware of a security breach.

Does the G-Server have vulnerability scanning capabilities?
The G-Server now incorporates the eEye Retina scanner, rated #1 by Network World’s review (December 2002). The Retina scanner automatically runs when new content is deployed and when an alert is triggered. As a result, forensics are produced to enable you to not only fix the content issue, but to close up the vulnerability that allowed it to occur in the first place.

What is so special about the Gilian Guarantee?
A lot of security products come with disclaimers that offer no warranty if a Web site attack is successful. Gilian is making an industry-first offer by being the first and only software product company to guarantee the performance of its product. Just purchase the Gilian G-Server product, operate it in accordance with your software license agreement and Gilian guarantees that altered, corrupt, or unauthorized information will never appear on your Web site. If altered content does appear, Gilian will recoup your documented damages up to $25,000.

Who are Gilian’s customers?
Gilian’s customers range from Fortune 1000 financial institutions and insurance organizations, leading healthcare providers, media corporate and manufacturers to technology companies, government agencies, airlines, and others. Customer references are available from Gilian’s sales representatives on request.

     
  Return to Top  
     
  G-SERVER PERFORMANCE and ADMINISTRATION
 


How is the G-Server itself secured?
As a dedicated black box appliance that sits in the DMZ, G-Server implements a proprietary network transparency model: that is, it has no IP Address of its own. This makes it virtually impossible for hackers to detect the presence of the G-Server and thus initiate any direct attack.

How complex is the deployment process?
It is extremely simple and straightforward to install since the IP addresses that the Web servers maintain never need to be changed during deployment or later during ongoing maintenance operations. As a stealth appliance that sits on the rack—not on the Web server—there is no need for network configuration. This allows for a rapid and painless installation, with zero impact on organizational workflow.

Won’t the G-Server impact Web site performance?
The G-Server has virtually no impact on Web site performance. It is capable of supporting a wide range of Internet carriers—including T1-T3, E1-E3—without performance degradation. In fact, based on standard performance benchmarks, the G-Server latency performance ranked at the top as a leading-edge gateway product engineered for performance.

Won’t the digital signing process add to my workload and require more time to administer?
No. The G-Server’s signing process can be made completely automatic and transparent. By using the G-Server’s API, you can customize and seamlessly integrate the signing process to fit your existing content authoring workflow. Alternatively, administrators can choose to adopt the G-Server Signing GUI, which provides authorized signers with an easy-to-use, flexible signing wizard to meet their every day signing requirements.

Does the G-Server support SSL sites?
Yes. Two optional configurations are available for SSL implementation:

  1. SSL termination: The SSL session is terminated on the G-Server and transferred to the Web server in clear HTTP. This configuration offloads the SSL effort from the Web server in order to improve overall performance.
  2. Complete SSL: This configuration maintains SSL session encryption all the way to the Web server.

Does the G-Server support a high availability configuration?
Yes. The G-Server can be easily configured with a "hot-swap" standby G-Server that takes over immediately in the event the primary box fails. Other high availability solutions are also possible via simple integration to existing high availability network environments.

     
  Return to Top  
     
  Comparison of G-Server with Other Solutions  
 


What makes the G-Server different from other security solutions?
The G-Server provides guaranteed protection regardless of the attack method or data layer, providing the last line of defense that closes all Web site security gaps. No other security solution today can sit transparently on the network and ensure that Web sites always serve genuine information, all while maintaining Web site performance.

How is the G-Server different from:

A network firewall?
While network firewalls are a necessary element in a Web site’s security architecture, they leave open the two main ports (80 and 443) that service HTTP and HTTPS traffic. Consequently, they offer little value in securing the integrity of the Web site applications and content. Not only does the G-Server protect your Web server from publishing unauthorized, altered or fraudulent information, it serves as a multi-function Port 80 and Port 443 protection appliance that quickly and efficiently authenticates incoming HTTP and HTTPS requests.

Intrusion Detection Systems (IDS)?
IDS attempt to detect malicious network activity usually through sniffing the network traffic and comparing each packet with a database of known attack signatures. However, it is usually weeks, if not months, before administrators can acquire and apply patches to known vulnerabilities. This leaves a huge window of opportunity open for hackers to take advantage before the patch can be applied. By contrast, the G-Server is an active corrective mechanism as well as a monitoring tool that delivers protection regardless of the attack method. All verification, recovery and blocking of damaged or unauthorized content is done proactively, in real-time and on-the-fly.

Application firewalls?
Application firewalls address browser and HTTP attacks that manipulate application behavior for malicious purposes. While application firewalls are designed to protect applications from possible hacking attempts on the application layer only, the G-Server delivers its static and dynamic content protection regardless of the data layer. In addition, application firewalls have no ability to protect static content and do not prevent altered content from being displayed. Further, unlike the G-Server, application firewalls need to be carefully programmed—and constantly reconfigured—to specify application procedures whenever a new page is loaded on the Web server.

GAP firewalls?
The concept of GAP technology is to create some type of physical separation between two networks. It consists of a switch that allows a computer or a resource to connect to either one network or another but not to both at the same time. The GAP appliance terminates all TCP/IP connections using a physical air gap. It can prevent some application-level attacks because only scanned data with known commands are passed to the internal system. While the technology is complementary to that of the G-Server, GAP firewalls have no ability to protect static or dynamic content and do not prevent altered content from being displayed.

Anti-virus and malware?
Protection from computer viruses and other forms of “malware” such as worm or Trojan horse attacks is important but has limitations. Most anti-virus solutions rely on signature-based technologies that must be updated constantly. These solutions, similar to IDS, are also unable to block many stylized attacks that are the most common attacks mounted against Web servers. The G-Server delivers its protection regardless of the attack method and does not rely on patch updates.

Access control?
Granting and preventing Web server access to users is an important function. However, unlike the G-Server, this process offers little or no protection against attacks that come in via HTTP and HTTPS traffic over the always-open ports 80 and 443.

Return to Top

 
       
  Return to Top    
       
 
© Gilian Technologies Inc., 2001-2003, all rights reserved. GILIAN, GILIAN TECHNOLOGIES, GILIAN TECHNOLOGIES (and design), the G-LOGO, EXITCONTROL, G-SERVER, G-APPPROTECT and G-APPWATCH are trademarks or registered trademarks of Gilian Technologies, Inc. in the United States and other countries. Marks owned by other companies may be used on this Web site for identification purposes, and Gilian does not claim rights in such marks.
This site is designed and maintained by Lee Advertising.