AppSecure is a suite of next-generation application security capabilities for Juniper Networks SRX Series Services Gateways that deliver security threat visibility, enforcement, control, and protection over the network.
Need Help?
AppSecure is a suite of next-generation security capabilities for Juniper Networks SRX Series Services Gateways that utilize advanced application identification and classification to deliver greater visibility, enforcement, control, and protection over the network.
By working in conjunction with the other security management services of the SRX Series, AppSecure provides a deep understanding of application behaviors and weaknesses that prevent application borne security threats that are difficult to detect and stop. As an integrated service on the world’s fastest services gateways, AppSecure provides the scalability to meet the requirements of the most demanding environments. AppSecure runs on the Branch and Data Center SRX Series Services Gateways.
Application Visibility with AppTrack
By collecting byte, packet, session, and time, statistics while accurately identifying hundreds of applications, AppTrack gives network administrators detailed analysis of application data. AppTrack quickly and easily provides visibility into the types of applications traversing through the SRX Series gateway and allows classification based on risk level, user ID, zones, source, and destination addresses, as well as volumes.
This information can be used to assess adherence to application usage policies, to help address bandwidth management, or to simply report on the most active users and applications. Juniper STRM Series Security Threat Response Managers can generate reports based on AppTrack application log data that extend their flexible and extensible methods to analyze data from a centralized location and take action.
Application Enforcement with AppFW
AppFW allows administrators to create fine grained application control policies to allow or deny traffic based on dynamic application name or group names rather than static IP/port information. This application security management and enforcement service is designed to simplify application security policies by using application white lists and black lists, as well as to define what actions to perform on matched traffic while taking default action against all other traffic.
Application Control with AppQoS
With the increased use of web-based customer relationship management (CRM), enterprise resource planning (ERP), and other business tools, network administrators need a way to prioritize business critical traffic over the network. AppQoS provides the ability to meter and mark traffic based on the application security policies set by the administrator. This allows lower priority Web traffic to continue when network bandwidth allows, but ensures that mission critical traffic is delivered when usage levels surge. AppQoS is currently supported only for on SRX Series Services Gateways for the data center.
Application Protection with AppDoS
AppDoS distinguishes attacking botnet traffic from legitimate client traffic based on application-layer metrics and remediates against botnet attacks. Employing a multi-stage approach that includes server connection monitoring, deep protocol analysis, and bot-client classification, AppDoS provides the ability to detect subtle changes in traffic patterns and client behaviors that could indicate an application-level denial-of-service (DoS) attack. Once suspicious activity is detected, AppDoS can issue an alert, block offending IP addresses, or completely drop irregular sessions and packets. AppDos is typically deployed with the SRX Series’ integrated IPS service to increase application security against malicious attacks.
Application Security with IPS
IPS tightly integrates Juniper’s latest and most advanced application security features with the network infrastructure to provide threat mitigation and protection from a wide range of attacks and vulnerabilities. IPS subscribes to the results of application identification and contextualization to determine the appropriate protocol decoding and attack objects to use for the permitted incoming traffic that will be processed by the IPS software services module.
| Feature | Benefit |
|---|---|
| Application awareness and classification | Enables all AppSecure capabilities by exposing application information to advanced, next-generation security services for increased visibility, control and protection. |
| Nested application support | Provides enhanced protection against modern evasion techniques that utilize trusted services. |
| User-role based policies | Superior protection and easier policy management as user and user groups reduce the number of policies and rules needed to account for other elements such as location, device, and IP address. |
| SSL inspection | Combined with AppSecure, provides visibility and protection against threats embedded in SSL encrypted traffic. |
| Purpose built platform | Delivers unrivaled performance and flexibility to protect service provider, enterprise and data center environments. |
| Junos OS service integration on SRX Series | Provides consolidation and optimization of application-aware security services for maximum scale. |
|
| Part Number | Description |
|---|---|
| SRX1XX-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX100 and SRX110 |
| SRX210-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX210 |
| SRX220-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX220 |
| SRX240-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX240 |
| SRX550-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX550 |
| SRX650-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX650 |
| SRX1400-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX1400 |
| SRX3400-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX3400 |
| SRX3600-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX3600 |
| SRX5600-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX5600 |
| SRX5800-APPSEC-A-1 | 1-year subscription for AppSecure and IPS updates for SRX5800 |
| SRX1XX-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX100 and SRX110 |
| SRX210-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX210 |
| SRX220-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX220 |
| SRX240-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX240 |
| SRX550-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX550 |
| SRX650-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX650 |
| SRX1400-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX1400 |
| SRX3400-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX3400 |
| SRX3600-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX3600 |
| SRX5600-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX5600 |
| SRX5800-APPSEC-A-3 | 3-year subscription for AppSecure and IPS updates for SRX5800 |
| SRX1XX-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX100 and SRX110 |
| SRX210-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX210 |
| SRX220-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX220 |
| SRX240-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX240 |
| SRX550-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX550 |
| SRX650-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX650 |
| SRX1400-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX1400 |
| SRX3400-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX3400 |
| SRX3600-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX3600 |
| SRX5600-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX5600 |
| SRX5800-APPSEC-A-5 | 5-year subscription for AppSecure and IPS updates for SRX5800 |