Implement SSL certificate automation management for WAF protection

ZoTrus WAF Automation Gateway

Download Brochure: English Русский 中文版

For website administrators, they who are not satisfied with the WAF device they purchased also need to apply for an SSL certificate from the CA and deploy the SSL certificate to the WAF device, which is tossed once a year. Our product is a WAF device that automatically applies for and deploys SSL certificates and supports https encryption, which can not only meet the needs of WAF protection for web servers, but also automatically realize https encryption, including RSA algorithm https encryption and SM2 algorithm https encryption.

Our solution does not require users to apply for an SSL certificate from a CA and configure it on a WAF device like traditional WAF vendors, but automatically configures dual SSL certificate on a WAF device, and the WAF device fee includes the cost of 5-year dual-algorithm SSL certificates. We have integrated the SSL certificate automation management service and traditional WAF equipment into a new product - WAF Automation Gateway, which allows the Gateway to automatically apply for SSL certificates and deploy SSL certificates to achieve https encryption and WAF security protection, and to let the original web server automatically realize WAF protection and https encryption without change.

1. Product Introduction

ZoTrus WAF Automation Gateway is another innovative product that protects website security based on the HTTPS Automation Gateway that has passed the commercial cryptography product certification to increase WAF protection function, which is the first in China, and is a new generation of WAF equipment that integrates WAF protection, https encryption acceleration, https offloading and forwarding, SM2 algorithm module, SSL certificate automation, load balancing and other functions, while realizing high-quality web application firewall to protect website security. It automatically supports WAF protection in the HTTPS encryption mode, because website security requires both WAF protection and HTTPS encryption to ensure the transmission security of confidential data on the website, and it is the HTTPS encryption of the adaptive encryption algorithm, and the SM2 algorithm is preferred to achieve HTTPS encryption. ZoTrus WAF Automation Gateway innovatively provides both WAF protection services and HTTPS encryption automation services, while ensuring the data "in-transit" encryption security and "onshore" protection.

ZoTrus WAF Automation Gateway

The biggest features and characteristics of the ZoTrus WAF Automation Gateway are zero application for SSL certificates, zero installation of SSL certificates, automatic implementation of WAF protection with HTTPS encryption, adaptive encryption algorithms. The browsers that support SM2 algorithm and SM2 Certificate Transparency use the SM2 algorithm to implement https encryption, browsers that do not support SM2 algorithm use ECC algorithm to implement https encryption. This is an innovative solution with client-cloud integration, the WAF Automation Gateway has a built-in SM2 ACME Client, which automatically connects with the ZoTrus Cloud SSL System to complete the automatic application, deployment, and renewal of dual SSL certificates, ensuring zero change of the business system to achieve https encryption automatically, to provide WAF protection with https encryption service uninterrupted for business systems with up to 255 different domain names.

ZoTrus WAF Automation Gateway

2. Main Functions

There are three core functions of ZoTrus WAF Automation Gateway: (1) WAF protection; (2) Support SM2 HTTPS encryption; (3) Automate HTTPS encryption. It is not only a WAF device but also an HTTPS encryption automation gateway, no need to apply for an SSL certificate from the CA, automatically configure a dual-algorithm SSL certificate, automatically realize the WAF protection with HTTPS encryption, and the original web server has zero change, just deploy the WAF Automation Gateway before the original server, it can automatically realize WAF protection with https encryption, and provide WAF protection services and https encryption automation services 24 hours a day, 365 days a year. It is recommended to deploy the default dual-machine deployment, which is hot standby for each other. When it is available, the two gateway work at load balance mode, and when it is not available, one gateway can take over all work.

ZoTrus WAF Automation Gateway

The WAF protection function of ZoTrus WAF Automation Gateway is developed and optimized based on the open-source ModSecurity system, and supports common web application firewall functions, such as: blocking SQL injection, blocking cross-site scripting (XSS), preventing attacks using local file inclusion vulnerabilities, preventing attacks using remote files (including vulnerabilities), preventing attacks using remote command execution vulnerabilities, blocking PHP code injection, blocking malicious access that violates HTTP protocol, Prevent attacks by exploiting remote proxy infection vulnerabilities, Shellshock vulnerabilities, Attack attempts using Session ID unchanged, Malicious website scanning, Source code or error information leakage, Honeypot blacklists, IP blocking based on IP address attribution, etc. And up to 12 different types of custom rules are supported to achieve personalized protection, such as allowing an IP to access a specific website and website directory.

Today, all browsers are showing HTTP website as "Not secure", HTTPS encryption is a mandatory configuration for the security of a website, of course, it is a necessary function of the WAF device, and the innovation of the ZoTrus WAF Automation Gateway is to automatically configure the dual-algorithm SSL certificate by connecting to the ZoTrus Cloud SSL System to apply for the dual-SSL certificate, validate the domain name, retrieve the issued SSL certificate, install the SSL certificate, and enable the SSL certificate.

The automatically configured ECC SSL certificate is globally trusted and supports the certificate transparency, it is issued by ZoTrus brand intermediate root certificate - ZoTrus ECC DV SSL CA, its root CA certificate is the world oldest ECC algorithm root CA certificate - Sectigo ECC, and the entire chain uses ECC Algorithm, the encryption speed is 18 times faster than the RSA algorithm SSL certificate, to fast access the website by end users.

The automatically configured SM2 SSL certificate is compliant with the Cryptography Law and trusted by all SM2 browsers. It is currently the only SM2 SSL certificate in the world that supports the SM2 Certificate Transparency. It is issued by ZoTrus brand intermediate root certificate - SM2 SSL Pro CA, its root CA certificate is Guizhou SM2 CA that Guizhou CA has the CA license issued by MIIT and SCA, the entire chain uses the SM2 algorithm, the encryption speed is 20 times faster than the RSA algorithm, to fast access the website by end users.

The certificate chain file of the automatically configured dual SSL certificate is the smallest, saving IDC traffic and user mobile phone traffic, saving IDC power consumption and user mobile phone power consumption, and is more environmentally friendly.

There are 12 main functional modules of ZoTrus WAF Automation Gateway:

3. Performance Indicators

ZoTrus WAF Automation Gateway provides an efficient, secure, transparent, easy-to-deploy, zero-reconstruction, fully automatic innovative solution to realize WAF protection with https encryption, which can effectively expand the bandwidth of network devices and servers, increase throughput, and strengthen network data processing capabilities, improve the flexibility and usability of the network, and improve the user experience of users visiting the website.

The WAF protection performance of ZoTrus WAF Automation Gateway has been tested by the authoritative third-party online testing software WAFER, and its attack behavior detection and distinguishing capabilities are all A-level (the highest level), with a true positive detection rate of 97.34% and a false positive rate of 0 (it will not intercept false positive behaviors that are not attacks), which can meet the needs of website security protection applications.

ZoTrus WAF Automation Gateway

The actual protection effect test result shows that the SQL Injection launched a total of 128 attacks and blocked 126 times. There were also 2 false negatives, that is, missed blocks, with a True Positive Rate of 98.44%. For Cross Site Scripting, a total of 149 attacks were launched and 147 were blocked. There were also 2 false negatives, that is, missed blocks, and the True Positive Rate was 98.66%. For Command Injection attacks, a total of 41 attacks were launched and 37 were blocked. There were also 4 false negatives, that is, missed blocks, with a True Positive Rate of 90.24%. For SSI Injection, a total of 24 attacks were launched and 24 were blocked. There are no false negative, and the True Positive Rate is 100%. Other test results are not analyzed one by one. For attacks that are not blocked, the Gateway WAF Module needs to be continuously improved in the WAF protection rules and the rules need to be updated regularly. Of course, customer also need to pay attention to analyzing WAF logs and constantly customize protection rules based on attacks.

ZoTrus WAF Automation Gateway

ZoTrus WAF Automation Gateway provides fully independent and controllable software and hardware integration products, including Open source WAF system, SSL security gateway software system with completely independent intellectual property rights, cryptographic SM2/ECC/RSA algorithm hardware accelerator card certified by CCPC, self-controllable operating system, support CPU chips such as Haiguang, Loongson and Phytium, adopt supporting independent motherboards, support independent network card, etc. The fully autonomous and controllable software and hardware integrated WAF Automation Gateway can meet the application requirements of these industries that have extremely high requirements for information security control.

Each ZoTrus WAF Automation Gateway supports automatic configuration of up to 255 ECC SSL certificates (single certificate) and supports up to 255 pairs of SM2 SSL certificates (one signing certificate and one encrypting certificate), dual-algorithm dual-SSL certificates configuration supports up to 255 website domain names to achieve WAF protection with dual-algorithm adaptive https encryption. How many websites can support for https encryption is limited by the number of new connections, throughput and concurrency supported by the Gateway hardware and cipher cards.

Each ZoTrus WAF Automation Gateway has a warranty period of 5 years, and automatically configures a globally trusted ECC DV SSL certificate and cryptography compliance SM2 DV SSL certificate for no more than 255 website domain names within 5 years. Based on the calculation of 988 Yuan per year for each website’s dual-algorithm and double-SSL certificate, the value of the SSL certificate that is automatically configured is as high as 1.25 million RMB Yuan (=5*255*988, equal to US$172K), and the world’s exclusive super-value WAF protection with https encryption automation solution!

ZoTrus WAF Automation Gateway currently provides 3 products of different specifications, which can be used for cloud high-performance data centers, large and medium-sized enterprise servers, and small organization servers to automatically implement WAF protection with https encryption, especially the application requirements of micro reconstruction to realize WAF protection with https encryption. The product performance index parameters of various models are shown in the table below. For users with different index requirements, products can be customized to meet the requirements.

Model
MG-1-2
MG-8-2
MG-9-2
CPU
Intel Atom
Intel Xeon (dual)
Hygon 5380
WAF Performance
Level A
Level A
Level A
Customize WAF Rule
Yes
Yes
Yes
Regularly upgrade rule
Yes
Yes
Yes
Incl ECC SSL Qty
20
100 / 255
100 / 255
Incl SM2 SSL Qty
20
100 / 255
100 / 255
Dual SSL supply
5 years
5 years
5 years
ECC SSL Type
DV SSL
DV SSL
DV SSL
SM2 SSL Type
OV SSL
OV SSL
OV SSL
Unique Key/Certificate per Website
Yes
Yes
Yes
SSL Certificate Period
90 days
90 days
90 days
Certificate Update Cycle
Every 80 days
Every 80 days
Every 80 days
WTIV Type
EV
EV
EV
SM2 https throughput
800 Mbps
9 Gbps
9 Gbps
ECC https throughput
800 Mbps
9 Gbps
9 Gbps
SM2 SSL Request
30 K/S
120 K/s
60 K/s
ECC SSL Request
40 K/S
130 K/s
90 K/s
Max concurrent
250K
1.5M
1M
Network Interface
6xG
6xG + 4x10G
6xG + 4x10G
Chassis size
155*240*40 (mm)
2U
2U
Power
Single supply 60W
Dual supply 550W
Dual supply 550W
Cert value (5 Years)
490K RMB
2.44M / 6.23M RMB
2.44M / 6.23M RMB
Save HR value (5Y)
120K RMB
600K / 1.5M RMB
600K / 1.5M RMB
Suitable Scope
SME
Colleges and Universities
Large Enterprise
Public Cloud
E-gov Cloud
Large Enterprise
Gov / Financial
E-gov Cloud

4. Deployment Solutions

ZoTrus WAF Automation Gateway supports multiple network deployment methods, supports cluster deployment of multiple devices, supports automatic docking with ZoTrus Cloud SSL System to automatically configure dual SSL certificates required for https encryption for the Gateway, and also supports localized deployment of ZoTrus Cloud SSL System for e-government cloud or public cloud, which automatically issues dual SSL certificates for local cloud users, and the local WAF Automation Gateway device automatically connects to the locally deployed Cloud SSL System. In order to ensure the high availability of the Gateway, dual-machine deployment is strongly recommended to ensure 24*365 uninterrupted provision of WAF protection and https encryption services.

(1) Provide HTTPS encryption automation service for local web servers (websites)

To provide WAF protection, users must deploy the WAF device in front of the Web server, and the WAF device can protect HTTP/HTTPS traffic and forward the normal plaintext traffic and the decrypted plaintext traffic to the subsequent Web server. However, if users purchase a traditional WAF device, users need to apply for an SSL certificate from a CA and manually deploy it on the WAF device, which is very time-consuming and laborious. With ZoTrus WAF Automation Gateway, users do not need to apply for an SSL certificate from the CA, and the ZoTrus WAF Automation Gateway automatically connects to the ZoTrus Cloud SSL service system to automatically configure dual SSL certificates for the user's website, and automatically realizes HTTPS encrypted WAF protection.

As shown in the figure below, after deploying ZoTrus WAF Gateway, you can still keep the domain name resolution to the public IP address of the web server for a few days, and after the gateway is deployed and can work normally, you can stop the domain name resolution of the public IP address of the original Web server, and disconnect the Internet connection line on the web server after the domain name resolution TTL expires, and then ZoTrus Gateway will fully take over the HTTPS encryption and WAF protection.

Gateway routing mode deployment

For customers who have purchased WAF devices, the common way is to deploy the WAF devices in front of the Web server, and manually configure the SSL certificate and private key into the device to implement RSA algorithm or dual algorithm (RSA/SM2) adaptive HTTPS mode WAF protection. As shown in the figure below.

Gateway routing mode deployment

The deployment principle of the ZoTrus WAF Gateway is a solution of zero-transformation, seamless upgrade, and non-interruption for the original system. The core idea is to transfer the SSL certificate deployment and HTTPS encryption and decryption functions of the device that originally installed the SSL certificate to the ZoTrus WAF Gateway. In order not to affect the uninterrupted and reliable operation of the running system, a new HTTPS encryption channel is added for deployment, As shown in the figure below. After the new channel is deployed, the domain name resolution of the old channel can be stopped, or the Internet connection of the old channel can be removed before the SSL certificate of the old channel expires or after the domain name resolution TTL expires. The old channel WAF device can also be left unremoved and can be used as a backup channel for emergency use, but a valid SSL certificate must be manually deployed for emergency use.

Gateway routing mode deployment

If the user wants to continue to use the purchased WAF device after enabling the ZoTrus Gateway, the WAF device can only be deployed behind the ZoTrus Gateway to achieve WAF protection for HTTP plaintext traffic, or the expired certificate in the WAF device can continue to be used to achieve WAF protection for HTTPS ciphertext traffic.

Gateway routing mode deployment

The default deployment mode for ZoTrus WAF Automation Gateway is dual-machine hot standby mode. The dual gateways adopt the master-master mode, that is, Active-Active mode. Both gateway devices act as hosts and process business traffic at the same time, and also serve as backup machines for each other. The two machines share business traffic and do not waste resources. When one of the gateways has a problem and cannot continue to work, the other gateway takes on all the work, thereby ensuring the continuous and reliable operation of the business system. The ZoTrus WAF Gateway is guaranteed for 5 years. If there is a fault within 5 years, it will be replaced free of charge to ensure uninterrupted HTTPS encryption automation services and WAF protection services within 5 years.

(2) Provide HTTPS encryption automation service for web servers (websites) that are not local

For users who not only need to implement WAF protection and HTTPS encryption automation services on local servers, but also have web servers in branches or multiple websites deployed on the cloud that also need WAF protection and HTTPS automation service, ZoTrus WAF Gateway supports both local forwarding mode and remote back-to-origin mode. Regardless of whether the web server (website) is in a foreign computer room or a cloud host, as long as the gateway can access it through the public network or intranet, these websites are back-to-origin origin servers similar to CDN services, and the Gateway can provide WAF protection and HTTPS encryption automation services for them all. Dual gateways provide WAF protection and HTTPS encryption automation services for up to 255 websites, and more websites need to purchase more gateways.

ZoTrus WAF Automation Gateway

In order to ensure the data security of the website system that is not located in the central computer room, the back-to-origin connection from the gateway to the other location server must be encrypted by HTTPS to achieve full-link encryption. ZoTrus Technology provides a self-signed back-to-origin SSL certificate with a validity period of 5 years for back-to-origin websites for free, and the original website does not need to deploy a globally trusted SSL certificate with a validity period of only one year.

This deployment method is also suitable for service providers who provide website design, web hosting, and SSL certificate sales, and deploy multiple gateways to provides WAF protection and HTTPS encryption automation services for their own business systems, as well as WAF protection and HTTPS encryption automation services for their customers, regardless of where the customer's website is hosted, only need it is accessible for HTTP or HTTPS.

(3) Cloud platform WAF automatic management cluster deployment solution

For various cloud platforms, such as e-government cloud platforms and public cloud platforms, there are tens of thousands or even millions of websites that need WAF protection and HTTPS encryption, and the only solution can only be done by automation. It is necessary to deploy multiple WAF Automation Gateway to form a cluster array - HTTPS Offloading and WAF System, and multiple WAF Automation Gateway work together to share business traffic and serve as hot standby gateways for each other. When a gateway fails, services running on it will be taken over by other gateways to ensure adequate and timely response to service scheduling. Cluster mode is suitable for the deployment of redundant network environments with an emphasis on extremely high-performance throughput.

Different from other traditional WAF device deployment solutions, the innovation is that it automatically configures dual-algorithm SSL certificates, automatically realizes HTTPS encryption and offloading and WAF protection, and does not need to manually apply for and manually deploy dual-algorithm SSL certificates from CAs after purchasing WAF devices on the cloud platform and renew the application and deployment every year. This solution includes 5 years of automatic application and deployment of dual-algorithm SSL certificates, and 5 years of automatic WAF protection with HTTPS encryption, meeting the requirements of cloud platform commercial cryptography compliance and globally trusted HTTPS website protection applications.

ZoTrus WAF Automation Gateway

(4) Local deployment of Cloud SSL System

By default, the ZoTrus WAF Automation Gateway automatically connects with the ZoTrus Cloud SSL System to enable https encryption after obtaining the dual SSL certificates. For cloud platform customers who want to independently issue their own brand of dual SSL certificates that are automatically deployed to the gateway, they can deploy the ZoTrus Cloud SSL System locally to realize automatic issuance of the dual SSL certificates by the custom-branded dedicated SSL intermediate root certificate. The locally deployed system is called the E-government Cloud SSL System or the Public Cloud SSL System.

The E-government Cloud SSL System is a locally deployed CA system for issuing cryptography-compliant SSL certificates that support SM2 Certificate Transparency. The deployment of the whole system is to realize the completely independent and controllable issuance and management of SM2 SSL certificates for e-government website and the relatively independent issuance of ECC SSL certificates. To achieve independent and controllable issuance of e-government SSL certificates, first of all, there must be an intermediate root certificate for issuing SSL certificates, so that all e-government systems can reliably realize that all e-government systems only trust SSL certificates issued by their own intermediate root certificates, effectively preventing various SSL man-in-the-middle attacks against e-government websites and other fake e-government website attacks.

ZoTrus WAF Automation Gateway

5. Summary

ZoTrus WAF Automation Gateway global exclusive innovation to achieve zero change of the original server to realize WAF protection and https encryption automation, SM2/ECC dual-algorithm adaptive https encryption, just configure website domain name and IP address at startup, immediately enable WAF protection, https encryption and acceleration service, TCP/DTLS secure delivery, automatic preparation of dual SSL certificates, global trust and cryptography compliance, high-speed dynamic caching and compression, connection multiplexing, session persistence and load balancing, etc. While ensuring high performance, it provides the industry's highest performance-price ratio.

The ZoTrus WAF Automation Gateway is plug-and-play, deployed on the front end of the website server, not only provided WAF protection, but also the original website server can be seamlessly upgraded from http to https without any modification, and it is the SM2 https encryption that meets the cryptography compliance, and the ECC https encryption for compatible of all browsers that do not support SM2 algorithm. Its powerful https acceleration and offloading ability provide power support for WAF module, and the after-WAF-protected forwarding function provides additional performance enhancement support for the website server, not only does not increase the burden of https encryption and decryption, but also enhances the external response capability and the ability to process user requests. The seamless switching of zero-reconstruction, zero-maintenance, and zero-impact of the ZoTrus WAF Automation Gateway is the first choice and must for WAF protection, SM2 https encryption automation and system security upgrade from http to https.