SkypeShield has launched a new application firewall solution for securing guest and anonymous requests when entering corporate networks.
The need for the new solution arose because, as part of the Skype for Business (Lync) topology, requests are sent anonymously to the front server in the corporate network without being authenticated or inspected. Once allowed, these requests, which might contain malicious code, can pass through DMZ firewalls with no control.
The application firewall has the following security layers:
- Request rewrite – session termination in the DMZ and rewrite of the request that is sent to the domain
- Protocol level sanitization – inspecting the traffic to validate the structure of the traffic as expected by the protocol
- Application level inspection – validating that the data content matches what is expected by the server
- Device pre-authentication – performing device validation before allowing any request to enter the domain
