Radware Certain T SSL Accelerator
SSL based client encryption may actually introduce vulnerabilities into the network by preventing traditional IDS solutions from being able to examine any traffic
SSL transactions have been widely accepted by the online community and have become the de-facto standard for conducting online transactions of all types. Today, according to Gartner Research, 40% to 80% of the average site's traffic is SSL based. For the financial industry, it is even higher. While the institutions that have adopted this technology boast their secure transport of mission critical traffic, they unknowingly have also introduced a major vulnerability into their network that can be utilized by the hacker. Hackers realize that encrypted traffic cannot be inspected by many of the security devices already deployed in the network. Suspect traffic traverses the network unimpeded. Once the traffic is decrypted, it is deep in the network and is ready to cause the damage that the hacker was seeking.
The benefits of Smart IDS include:
- All traffic including SSL can be quickly and thoroughly inspected thereby eliminating SSL based attacks.
- IDS performance is optimized as traffic may be distributed by application, src IP and dst IP. Further optimization is achieved by utilizing load balancing and filtering of traffic.
- Cost savings by reducing the amount of IDSs needed in a network. Scalability is based on throughput as opposed to per-segment requirements.
- Only the traffic that needs to be inspected gets sent to the IDS server farm, further reducing the amount of throughput of the IDS.
- Multi-gigabit IDS performance
- High availability of IDSs. If one IDS fails, traffic may be redirected to another resource transparently.
- Scalability is easy and cost effective while being completely transparent to the user.
The benefits from Application Security or DoS Shield solution include:
- Organizations gain an additional layer of security applied to the network.
- Existing network based security devices are optimized as suspect traffic is filtered at the edge.
- Organizations achieve real time attack identification and mitigation.
- Security is optimized for ?normal? and high throughput environments.
- Organizations are protected against the new and damaging attacks as this solution provides instant update capabilities to ensure most current attack identification.
- Full forensics & paper trail enables organizations to learn from attempted security breaches as well as update policies based on past experiences.

Is she who she say's she is?
Certain T offers:
- ASIC SSL Transaction Processing
- Gigabit SSL Encryption/decryption
- SSL Service Fail Over (with WSD)
- Unlimited SSL Scalability 20,000 SSL TPS
- All Network Traffic SSL inspected
- Content Acceleration HTTP compression
- Reverse caching reduce bandwidth
- End-to-End Transaction Visibility
- Compact 1U harware platform

