L3, L4 and L7 from one layer
Volumetric, protocol and application filtering in a single pipeline. SYN and UDP floods and HTTP requests that imitate real users are handled in the same place, not by three products you have to reconcile.
DEFLECTO is a Layer 7 web application firewall and reverse proxy that absorbs network-layer floods in front of it. Hostile requests are dropped, challenged or starved at the edge. What reaches your origin is the traffic you actually wanted.
Deployed in front of
An outage costs you customers, credibility, and an engineering team stuck firefighting instead of shipping. Modern floods are cheap to rent by the hour and hard to stop with a classic firewall, because most of them look like ordinary traffic right up until they do not.
The uplink fills with junk before a single packet reaches your application. The server is perfectly healthy and completely unreachable at the same time.
Well formed HTTP requests, plausible headers, real TLS handshakes. Any rule blunt enough to block them blocks your customers with them.
A handful of connections held open, requests fed a byte at a time, until worker pools and connection tables are gone. The bandwidth graph stays flat throughout.
The first burst is a demonstration. The message that follows names a price for the second one not happening.
When a client looks suspicious, DEFLECTO does not guess and block it. It hands the client a computational puzzle and waits for the answer. A browser solves it in about the time the page takes to appear, and nobody is asked to identify a bicycle.
An attacker has to solve the same puzzle, once per request, on every machine in the botnet. That is the whole idea. A flood is only viable while requests are free to send, so making each one pay for itself breaks the arithmetic that funds the attack. The traffic does not have to be identified as hostile, it only has to become uneconomic.
No CAPTCHA. Nothing for a human to solve.
From the network edge to the application layer, DEFLECTO refuses attacks across the whole spectrum without slowing down the traffic you want.
Volumetric, protocol and application filtering in a single pipeline. SYN and UDP floods and HTTP requests that imitate real users are handled in the same place, not by three products you have to reconcile.
Traffic enters a globally distributed network, so hostile volume is soaked up close to where it is generated instead of arriving intact at your uplink.
OWASP rule coverage, per-route rate limiting and signatures that are updated continuously. Maintaining the ruleset is our job, not a chore we hand back to you.
The network is watched around the clock. An anomaly reaches an engineer, not a ticket queue that opens again on Monday morning.
Mitigation engages automatically. There is no console to log into, no rule to switch on and no phone call to place while the site is down.
Real-time reporting on what was allowed, what was challenged and what was dropped, with the evidence behind each decision kept alongside it.
Three steps that run continuously and automatically, in milliseconds, without anyone pressing a button.
Every request is inspected at the edge. Patterns, signatures and behaviour are evaluated in milliseconds, long before the request is anywhere near your application.
Hostile volume is absorbed and filtered. Suspicious clients are handed a challenge. Only the requests that earn their way through continue to your origin.
Real users carry on without noticing that anything happened, and you get a report describing exactly what did.
Plans are quoted in legitimate requests forwarded to your origin, and that is the only thing a quota counts. Floods, refused probes and challenged bots are handled for free. Under ordinary per-request billing the invoice arrives precisely because you were attacked, and charging you for somebody else's botnet is not a business we want to be in.
| Traffic | Quota |
|---|---|
| Legitimate requests forwarded to your origin | Counted |
| Volumetric floods absorbed at the edge | Free |
| Requests refused by the WAF | Free |
| Clients handed a proof-of-work challenge | Free |
We do not sell best effort. The contract names an availability figure and a mitigation time, and it names what we owe you if we miss either one.
Both are good reasons to talk. We will look at your exposure, tell you plainly what we would do about it, and if you are in the middle of an incident we can onboard you the same day.