About DayZero

Malware

Trojan Horse

Development

Try Now ButtonSolution Sets

Use SigFree SDK for Web Server Protection, Firewalls, End Point Protection, Memory Analysis, Browser Protection and much, much more.

Web Server Protection

The SigFree Library was deployed as a proxy-based tool for Linux web server protection. In this case, the SigFree Library was ported to Linux. The SigFree SDK for Linux now includes a Linux library.

The implementation summary is as follows:

  • SigFree Library for Linux
    • Port SigFree implementation to Linux platform
    • Implemented as standalone dynamic library
    • With processing speed above 20Mbps
  • High throughput
    • Use epoll event notification mechanism (Linux 2.6)
    • Multithreading
    • Support above 5000simultaneous clients
  • Anti-evasion
    • Detect malicious code in Request-URI, Request Header or Request Body
    • URI unescape
    • Base64 decoding (Authorization header)

Metasploit 3 is used for penetration testing. Malicious code is embedded in Request-URI, Request body, Host Header, Authorization Header or Accept-Language Header.

The SigFree Reverse Proxy was able to detect all malicious requests generated through:

  • 31 exploits targeting web servers or services
  • All 41 Windows payloads and 18 Linux payloads.
  • All 14 x86 encoders
  • All 23 TCP and HTTP evasions

The evaluation results with 5000 simultaneous clients are summarized below:

Web Server Protector

 

Solution Sets