HomeDownload TrialWebinarsLibraryCareersSalesBlogsSearch

Oracle Service Bus Appliance

Secure, easy to deploy, ESB appliance from Layer 7 and Oracle


The Oracle Service Bus (OSB) Appliance combines the Enterprise Service Bus (ESB) capabilities of OSB with Layer 7’s recognized leadership in XML security to create a pre-integrated, pre-configured secure SOA integration solution that can dramatically reduce the cost and complexity of a SOA implementation:

  • Ease of Deployment – OSB Appliance is a turn-key, pre-integrated device designed to be installable out of the box – just rack it, assign an IP address, and let the appliance configure itself to run on your network, dramatically decreasing time to deploy
  • DMZ-class Security – With support for all major WS* and WS-I security protocols, as well as the ability to define and enforce identity-driven security policies, OSB Appliance provides a single, secure point of entry to enterprise services
  • Extreme XML Performance – OSB Appliance provides hardware-based acceleration for XML message processing at the edge of the network, allowing organizations to optimize network performance

Deployed on a multi-core, 1U Sun server that features active-active clustering, dual power supplies, mirrored hot-swappable drives and optional Federal Information Processing Standards (FIPS) 140-2 level 3 compliant Hardware Security Module (HSM), OSB Appliance provides a quick, cost-effective solution for DMZ conformance.

OSB Appliance

 

  “The integrated OSB-Layer 7 Appliance allows us to simplify our SOA security architecture through fewer components, while extending our OSB functionality into the DMZ. This opens several new deployment scenarios to us, and reduces our SOA implementation cost and complexity.”
Rick Butler, Chief Engineer for Raytheon Information Security Solutions


Features/Functionality

Identity and Message Level Security
Identity-based access to services and operations
  • Integration with leading identity, access, SSO and federation systems from Oracle, Sun, Microsoft, CA, IBM Tivoli, Novell
  • Enforce fine-grained entitlement decisions authored in an XACML PDP
Manage security for cross-domain and B2B relationships
  • Credential chaining, credential remapping and support for federated identity
  • Integrated SAML STS issuer featuring comprehensive support for SAML 1.1/2.0 authentication, authorization and attribute based policies
  • Integrated PKI CA for automated deployment and management of client-side certificates, and integrated RA for external CAs
  • STS support through WS-Trust and WS-Federation
Enforce WS* and WS-I standards
  • Support for all major WS* and WS-I security protocols, including SOAP 1.0/1.1/1.2, WS-Security 1.1 / 1.2, WS-SecureConversation, WS-SecurityPolicy, WS-Addressing, WS-Trust, WS-Federation, WS-Secure Exchange, WS-Policy and WS-I Basic Security Profile, SAML 1.1/2.0, XACML 2.0
Secure WSDL, REST and POX interfaces
  • Selectively control access to interfaces down to an operation level
  • Create on-the-fly composite WSDL views tailored to specific requestors
  • Out of the box support for popular cloud and SaaS interfaces from Salesforce and Amazon
  • Service look-up and publications using WSIL and UDDI
Audit transactions
  • Log message-level transaction information
  • Spool log data to off-board data stores and management systems
Cryptography
  • Optional onboard HSM, as well as support for external HSMs (i.e., SafeNet Luna)
  • Support for elliptic curve cryptography (conforms to NSA’s Suite B algorithms)
  • FIPS 140-2 support in both hardware (Level 3) and software (Level 1)
XML Threat Protection
Filter XML content for SOA, Web 2.0 and Cloud
  • Configurable validation & filtering of HTTP headers, parameters and form data
  • Detection of classified or “dirty” words or arbitrary signatures with subsequent scrubbing, rejection or redaction of messages
  • Support for XML, SOAP, POX, AJAX, REST and other XML-based services
Transactional Integrity Protection
  • Protect against identity spoofing and session hijacking cluster-wide
  • Assure integrity of communication end-to-end
Prevent XML attack and intrusion
  • Protect against XML parsing; XDoS and OS attacks; SQL and malicious scripting language injection attacks; external entity attacks
  • Protection against XML content tampering and viruses in SOAP attachments
  • DoD STIG vulnerability tested and assured
XML Acceleration
Accelerated XML processing
  • High speed message transformations based on internal or external XSLT
  • High speed message validation against predefined external schema
  • High speed message searching, element detection and content comparisons
Traffic Management
Throttling
  • Granular rate limiting and traffic shaping based on number of requests or service availability across a cluster
Cluster-wide counters
  • Persist message counters across clusters so that rate limiting and traffic shaping can be strictly enforced in high availability configurations
CoS for XML
  • Prioritize XML traffic based on Class of Service/Quality of Service preferences
Service availability mgmt
  • Manage routing to back-end services based on availability/latency performance
Administration
WS-Policy-based graphical policy editor & composer
  • Compose inheritable policy statements from 70+ atomic policy assertions
  • Branch policy execution based on logical conditions, message content, externally retrieved data or transaction specific environment variables
  • Publish policies to popular registries for lifecycle management
  • Service and operation level policies with inheritance for simplified administration
  • Policy lifecycle and migration management across development, test, staging and production, as well as geographically distributed data centers
  • API-level access to administration
  • SDK-level policy creation for simplified policy customization
On-the-fly policy changes
  • Polices can be updated live across clusters with no downtime required
Create custom policies
  • Policy SDK allows for custom policy assertion creation using Java
API Management
API Publication
  • Secure, manage, monitor and control access to APIs exposed to third parties
  • API usage can be throttled to ensure backend services are not overwhelmed; limited by user, time of day, location, etc; and quota managed (i.e., # of uses per user per day)
API Metrics and Reporting
  • Configurable, out-of-the-box reports provide insight into API performance: measure throughput, routing failures, utilization and availability rates, etc
  • Failed authentications and/or policy violations can be tracked to identify patterns and potential threats
API Security
  • Support for all major WS* and WS-I security protocols
  • Support for all major authentication and authorization standards, including SAML, Kerberos, digital signatures, X.509 certificates, LDAP, XACML, etc 
Enterprise-scale Management
Operations Console
  • A single, real time view of all Gateways across the enterprise and cloud showing audits, events and key metrics
Policy Migration
  • Centrally move policies between environments (development, testing, staging, production, etc), settings (enterprise, cloud, etc) or geographies, automatically resolving discrepancies such as SSG licenses, IP addresses, IT resources (i.e., LDAPs may be named differently), etc
Services Reporting
  • Configurable, out-of-the-box reports provide insight into SSG operations, service-level performance, and service user experience
Remote Patching
  • Selectively update any software installed on Gateways, including system files and operating system
Disaster Recovery
  • Centrally back up SSG config files and policies from one or more Gateways/clusters, and remotely restore, enabling full disaster recovery
Management API
  • Remote management APIs allow customers to hook their existing, third-party management tools into the SSG, simplifying asset management
Supported Standards
XML 1.0, SOAP 1.2, REST, AJAX, XPath 1.0, XSLT 1.0, WSDL 1.1, XML Schema, LDAP 3.0, SAML 1.1/2.0, PKCS #10, X.509 v3 Certificates, FIPS 140-2, Kerberos, W3C XML Signature 1.0, W3C XML Encryption 1.0, SSL/TLS 3.0/1.1, SNMP, SMTP, POP3, IMAP4, HTTP/HTTPS, JMS 1.0, MQ Series, Tibco EMS, FTP, WS-Security 1.1, WS-Trust 1.0, WS-Federation, WS-Addressing, WSSecureConversation, WS-MetadataExchange, WS-Policy, WS-SecurityPolicy, WS-PolicyAttachment, WS-SecureExchange, WSIL, WS-I, WS-I BSP, UDDI 3.0, XACML 2.0, MTOM

 

Share: | More

Resources

Datasheet:
Oracle Service Bus Appliance

Download PDF | 196Kb

 

Datasheet:
Layer 7 XML Gateway for Oracle Fusion

Download PDF | 208Kb

 

Case Study:
Oracle Service Bus Appliance

Download PDF | 388Kb

 

Press Release:
Oracle Service Bus Appliance Announcement