Cloud Secure Web Gateway (Cloud SWG) Product Overview

  • Achieve the same policy anywhere in the world with cloud services
    With data centers located all over the world, it is possible to implement web security measures, including overseas bases, as well as employee security measures during overseas business trips. We have two data centers in Japan, one in Tokyo and one in Osaka, and we have achieved redundancy within Japan.
  • In addition to the proxy function, high-precision URL filtering and multiple anti-virus services are used to prevent entrances and exits.
    Broadcom's threat intelligence (GIN) provides highly accurate real-time URL filtering and anti-virus scanning services.
  • 追加オプションでセキュリティの向上、運用の負荷を軽減
    サンドボックス機能や、Web分離によるWebの無害化、リスクレベル判定によるリスクに応じたWebサイトの分類を提供します。
  • Provides reporting capabilities
    Multiple reports such as security-specific reports can be provided, eliminating the need to prepare a dedicated server or build a system.
  • Supports various connection types
    Supports connections from PAC files, IPsec, agents, multistage proxies and smart devices.

① Cloud Secure Web Gateway (Cloud SWG) anywhere in the world

  • Deploying data centers in over 40 locations around the world
  • Automatically connect to nearest data center
  • Automatic switching between data centers is also realized when the data center is down
  • Fully redundant with many access points
  • 2 data centers in Japan

Providing two access points in Japan

manufacturers/broadcom/image/
Both main and backup access can be connected to Japanese access points from within Japan.

Please refer to the following for the latest data center list.
https://knowledge.broadcom.com/external/article?legacyId=tech242979

Cloud Secure Web Gateway (Cloud SWG) basic functions

  • Proxy function for 80 and 443 web communication
  • cloud proxy
Provision of basic proxy functions necessary for business
Supported protocol
Supports HTTP and HTTPS, which are basically required (* FTP, SOCKS, etc. are not supported)
Policy settings
User ID, URL, date and time, content type
Using various attributes as triggers, it is possible to easily create detailed policies that match the usage environment.
Advanced security policies can be set according to various combinations.

② Real-time URL filtering

URL filtering/parsing mechanism

Analyzing unknown URLs in near-real time by multi-stage approach of Web Filter

Application Control/Settings when using SNS

SNS can also be managed by operation such as login, profile change, wall post, message transmission, and by user such as policy A and policy B. For example, it is possible to allow public relations to post on the wall on Facebook, but for sales to only view.

Antivirus function

Virus scanning with multiple antivirus engines. If it is a cloud type, the latest pattern file can always be applied

③ Option selection that goes one step higher

Box function

Difference between MASS and MAAS

MASS (Malware Analysis Standard Service)
  • DLL, EXE file
MAAS (Malware Analysis Advanced Service)
  • DLL, EXE file
  • windows installer
  • MS Word
  • MS Excel
  • MS PowerPoint
  • MS Visio
  • Adobe PDF
  • Rich Text Format
  • Android Application Packages
  • iOS Application Archives
  • Debian/iOS

As of August 2017

Isolation function_Selective

Sites with potential threats and uncategorized sites are dealt with by rendering them harmless without blocking.

About the Intelligence Service Risk Level Judgment AI Engine

Dynamic analysis is possible in real time based on a unique algorithm by using dynamic trading.Realization of highly accurate analysis based onmultiple rating standards based on AI system

④ Report function

⑤ Connection type