Hi everyone, welcome to our second videocast with Qrator Labs. My name is Osman Celik, I'm a Research Analyst at KuppingerCole. Today I'm again with Andrey from Qrator Labs. How about making a small introduction, Andrey?
Hi, nice to meet you all here. I'm the Chief Technology Officer at Qrator Labs, the network availability service provider. We have different products for that, but maybe we will discuss it later on.
Yeah, sure. But I think that some people might not watch the first video, so for those of you, please go ahead and watch the first videocast. We discussed the essentials of web application and API protection, and what Qrator Labs offers, and then how we work together as KuppingerCole and Qrator Labs in the last report.
Yeah, and then in this today's video, we are going to discuss what other capabilities might be needed for a more comprehensive approach to web application protection. And on top of that, maybe also API security, because this is something inevitable nowadays. More and more vendors are including the API protection in their portfolio, but it's not only limited to that. I'm sure Andrey has more to discuss and which other capabilities we see in the market today. I believe that Andrey is also able to give us some insight about what they're working on as Qrator Labs.
Yeah, so let's start with the first question then. So we know that the core of the web application starts with the web application firewalls, starts with the web application protection. Could you maybe give us some core capabilities and then how do solutions actually mitigate risks and threats arising from web applications?
Well, to start off, in the whole landscape of threats on the internet, we have three different vectors. So we have DDoS attacks. This is the complete disruption of your service. The attacker wants you down, that all your customers won't be able to reach you, and so this is directly losing of any revenue and so on, especially for e-commerce services.
Second, we have malicious actors who want to penetrate your infrastructure and they don't want to get you down, but they want to extract data to get inside to make some disruption from the inside. So there we have web application firewalls that are specifically for that. And the third one is a data scraping threat, where you can suppose your e-commerce service and someone may steal your current catalog to get it in the big gathering of all the e-shops and maybe get some commission for that and so on and so forth. And scraping user data is the modern world.
So these are basically three different threats and you have to address unfortunately differently because they are executed in very, very different ways. So for example, if we're speaking about DDoS attacks, this is generally high bandwidth attacks. We're speaking about layer 3 and 4 of the OC. So these are the SYN floods, UDP floods, different TCP stack abuses that you can try to get inside, and huge amount of HTTP requests, if you are talking about HTTP service, especially, but mostly most of the services on the internet are web services. So let's speak about HTTP.
So you have a huge amount of HTTP requests that your server infrastructure just can't handle. And so you're technically down for the world. Let's continue. Let's move on to the web application firewall that is used to mitigate unauthorized access and penetration for your infrastructure where the attacker wants to get inside. And they have completely different profile for their attack. They usually get some SQL injection, try this stuff, then they see that it doesn't work. Then they try to get from the other end, maybe some phishing attacks and so on and so forth.
And basically, you have to analyze every request. And there is generally not many of them, because the attacker wants to stay low and stay behind. And speaking of staying low, another thread that I told you about, the third one is the data scraping one, is generally the same as the penetration in regards of staying low.
But here the attacker wants you online, but it wants to get all the data that you have, or maybe user base that you have, products that you provide, and everything that you have inside that you have explicitly available, even behind authorization, second factor, and so on and so forth. But they can get it. And you have to analyze the behavior. These requests per second for these kind of attacks is extremely low, and you have to some fingerprint analyze what the ciphers they use. Is it a browser? Is it a human? Is it a human-based browser?
And nowadays, in the times of artificial intelligence, this becomes a very specific issue to address, because sometimes you just can't separate and tell the difference between the human who browses your site, gets something in the cart, and checks out, and modern AI-based browsers, where a user entered that I want to buy a new t-shirt, and the browser itself goes to your site and fills the cart, and so on. So these are considered good bots, but these good bots might be evil.
So you have to distinguish these kind of threats or attacks, or this kind of So these are completely different threats, and you have to address them equally, because each one of them leads to loss of revenue, mostly, if we're speaking about business. And to address these issues, you have to approach differently as well.
So first, we had DDoS attacks. So you have to deal with a huge amount of traffic, huge volumes of traffic. So nowadays, attacks reach terabits per second, so this is just an insane amount of bandwidth you have to deal with. So from our side, we have a specially designed network to get the attack as close to the source as possible to mitigate, and we estimate the risks, what kind of attack and what bandwidth is going to be there. So we estimate those risks and scale accordingly. So each moment of time, we have to be ready to mitigate terabits of malicious traffic.
For the penetration and getting inside your infrastructure, you don't need terabits of bandwidth capacity, you just have to find specific signatures for the threats that are behind your infrastructure. So there are CVEs that you have to follow, maybe some zero-day exploits that are running around, and you have to update your signature database, and so on. So this is a completely different approach.
So you are still in your infrastructure, you address your requests that are on your infrastructure, and maybe some responses if the attacker bypasses the requests phase, and you have a response, like the whole depth of the database, you have to do something, like erase the data from the response, or maybe just return the error. And for the bot mitigation technique, you just have to profile the user that interacts with your resource.
And this is mostly on the user side, on the browser side, that you have fingerprints, ciphers, maybe some tricks on the network level that you can prove that it's human and not a bot. In general, nowadays, half of the traffic is the bot traffic, and sort of half to maybe 60% of these bots are malicious bots. So you have to find out there are good bots, for example, from big search companies, and even from AI companies that are considered good, but there are definitely, sometimes they are used for malicious behavior, unfortunately.
Yeah, I mean, it was a great and long answer, so I didn't want to interrupt you. But going back to the first points you made, I think that it's important to understand that the traditional tools, web application firewalls tools, were only coming with a positive or a negative security, a combination of security rules. And then on top of that, on average, we would see maybe some coverage for known vulnerabilities, like OS top 10, and then that will be it.
But today, it's not enough. And then that's why we are seeing the next-gen WAPs or web application API protection WAP tools bringing something more to the market. And then I know that for a fact you have separate solutions for the web application and also for DNS protection, for DDoS mitigation, and also for bot protection. Would you maybe elaborate more on about your platform and then how you offer these different tools and then how they orchestrate together?
Well, since we have three different threads, we do address them differently, but we work as a single window for our clients. So our client wants to be available on the network, no matter what, on the internet, no matter what. So generally, all these three products are separate, but they are behind the one black box that our customers don't see at all. And this is the main point to get the service you desire. You may be a good specialist in any of these threads, how to mitigate them, how to deal with them. You might even have different solutions for them.
But if something goes wrong, the problem becomes that you have to debug, you have to trace the problem, what product has the error. Maybe it's false positive, maybe it's false negative. You have to run around between different providers or maybe run around between your colleagues that you have, does the mitigation. And that's in our experience, that's a hectic mess and nothing works by the time and everything like panic and tear their hair off. So when you have a single provider for all these services, that's their purpose to answer you, to resolve all the issues that you have.
And it's their job to get this quickly, as quick as possible. And of course, these kinds of providers and we as such a provider, of course, we have special tools designed to address all the issues that our clients have or might arise even during onboarding procedure. So the single point of truth is the major part of the solution. All right.
So, and then I remember that you have a very nice interface and then that these three tabs are offered for different modules. And then you have the anti-DDoS, anti-BOT and WAF integrated in one solution, right? So it's like one solution in one platform. Yes. So specifically, we're having three different products. They have different aspects to visualize and to present to our customer. And our customers do want to find out, like find different specifics about their attacks, different threats, maybe expert to their CM service and so on.
And to have a deeper overview, we have separate dashboards for each of the product. But sometimes our client just wants to reach us and ask, so this IP address or this client of ours can't reach our service and it's unavailable for them. Please do something. Can I find out what's wrong? So there are two possibilities. Either he can do that in our overall dashboard and find out the reason why his customer was blocked, or he can ask us and we can answer him very clearly what's going on there and why this particular customer was under our investigation. All right.
So maybe I can have my last question like this. So what do you think that what sets you apart in the competition? Because it is now becoming a market standard for WAP vendors to offer DDoS protection for all three, four and seven layer attacks. And then also advanced what mechanism they deliver, we know. So what would you like to say about like, what sets you apart and what are your unique setting points in the market? Maybe we could elaborate this and this could be the final question of today. Sure. Thanks for that opportunity.
And specifically, most of our unique opportunities comes from our architecture, from architecture of our company and architecture of our network stack. So we are quite a small company. That means that we are extremely flexible and can address any arising issues really, really fast. That's the first one. The second one is our technical support that is available 24-7. And you might be sure that you will reach like human, real person. On the other hand, no AI bots, no etc. And these people that you get even from the first line of support are technical guys that do know the stuff behind there.
There is not going to be any like outer response, so on and so forth. If you have a problem, we will solve it as soon as possible. And last but not least is the way we estimate the risks and how we construct, how we expand our infrastructure. So for here, for example, to expand our network, we have a specific tool to find out special places, exact locations where we have to install our infrastructure to address, for example, to address the issue of DDoS mitigation exactly in this region. So these are like three major ones. Yeah. All right.
I think then that was a good conversation and it was a pleasure to have you here, Andrei. And as I said, this was the second of our series, second video of our series. And we are going to continue with our series. And as I would say, stay tuned and join us in our next videos if you want to know more about what Curator Labs offers. And then our discussion about web application and API protection will continue. So thank you very much for joining us and stay tuned. And if you have any questions, please reach out to us. Thank you so much. Thank you.