Supported EC2 Features
|
| CloudFront |
- Leverages the Amazon Web Services Firewall for IP-level firewalling
- Utilizes the Amazon load balancer for availability and greater reliability
|
| Elastic |
- Allows on-demand instances to be created for spin-up (to handle demand spikes) or scaled down during periods of low traffic (to minimize costs)
|
| Virtual Private Cloud |
- Enables secure administration of the SecureSpan AMI
|
| CloudWatch |
- Monitors system metrics and node health
- Dynamically routes to new nodes deployed for additional capacity
|
| Instances |
- Supports EC2’s “on-demand” and “reserved” instances
|
Identity & Message-Level Security
|
| Enable Identity-Based Access Controls |
- Authenticate users and applications based on data from existing on-premise identity stores
- Integrate with leading identity, access, SSO and federation systems from Oracle, Sun, Microsoft, CA, IBM Tivoli and Novell
- Ensure only users or applications with valid entitlements can execute specific services, operations or APIs
- Expose two- or three-legged OAuth interactions for delegated authorization to resources
|
| Manage Security for Cross-Domain & B2B Relationships |
- Makes it possible to selectively control how Amazon-based applications are programmatically exposed to partners and other third parties
- Support for credential chaining and credential remapping as well as identity federation
- Integrated Security Token Service issuer featuring support for WS-Trust, WS-Federation, OAuth and SAML-P protocols
- Integrated PKI CA for automated deployment and management of client-side certificates plus integrated RA for external CAs
|
| Enforce WS* & WS-I Standards |
- Support for all major WS* and WS-I security protocols, such as WS-Security, WS-SecureConversation and WS-SecurityPolicy
|
| Secure WSDL, REST & POX Interfaces |
- Selectively control access to interfaces down to an operation level
- Create on-the-fly composite WSDL views tailored to specific requestors
- Enable support service look-up and publication via WSIL and UDDI
|
| Audit Transactions |
- Log any/all message-level transaction information
|
| Utilize State-of-the-Art Cryptography |
- Support for elliptic curve cryptography and FIPS 140-2
|
Threat Protection
|
| Filter XML Content for SOA, Web & Cloud |
- Validate and filter HTTP headers, parameters and form data
- Detect classified or “dirty” words or arbitrary signatures
- Filter SOAP, POX, AJAX, REST and other XML-based services
|
| Protect Transactional Integrity |
- Protect against identity spoofing and session hijacking
- Preserve privacy, confidentiality and integrity of messages/data
|
| Prevent XML Attack & Intrusion |
- Protect against XML, XDoS, OS, SQL injection and external entity attacks
- Protect against XML content tampering and viruses in SOAP attachments
- Deploy a US DoD STIG vulnerability tested XML Gateway technology
|
API Management
|
| Publication |
- Secure, manage, monitor and control access to APIs
- Throttle API usage to ensure backend services are not overwhelmed
|
| Metrics & Reporting |
- Get quick insight into API performance (utilization, availability etc.)
- Track failed authentications and policy violations to identify threats
|
| Security |
- Support for all major WS* and WS-I security protocols
- Support for all major authentication standards, including SAML and OAuth
|
Performance Management
|
| Message Caching |
- Cache responses to common requests, decreasing backend service load
|
| Concurrent Assertion Processing |
- Run multiple assertions concurrently, thereby reducing overall latency when assembling a response from multiple backend services
|
| Accelerated XML Processing |
- Transform messages, based on internal or external XSLT
- Validate messages against predefined external schema
- Leverage high-speed message searching, element detection etc.
|
Traffic Management
|
| Throttling |
- Enable granular rate limiting and traffic shaping based on number of requests or service availability
|
| Class of Service |
- Prioritize application traffic based on quality-of-service preferences
|
| Service Availability |
- Monitor and track EC2-based service performance, health and metrics
- Monitor and track Amazon EC2 uptime SLAs
- Re-route to back-up services, based on availability or latency
|
Policy Management
|
| Composition & Editing |
- Compose policy statements from over 100 pre-made policy assertions
- Branch policy execution based on logical conditions, message content etc.
- Publish policies to popular registries for lifecycle management
- Get API-level access to administration
- Update polices on the fly, with no downtime required
|
| Lifecycle Management |
- Manage policy lifecycle across geographical locations and environments
|
| Customization |
- Quickly create customized policy assertions using a simple Java SDK
|
Service Management
|
| Operations |
- Quickly view audits, events and metrics for Gateways
|
| Policy Migration |
- Migrate policies across development, test, staging and production
|
| Services Reporting |
- Get quick insight into Gateway operations and service-levels
|
| Remote Patching |
- Selectively update any software installed on Gateways
|
| Disaster Recovery |
- Centrally back-up configuration files and policies and restore remotely
|
| Remote Management |
- Integrate existing third-party management tools
|