| |
|
| pawaaWEBB – Innovation in Web Security |
|
|
|
WITH ‘DLP-ON-DEMAND’ |
|
pawaaWEBB is a powerful data protection tool which provides security that, until now, was non-existent in web applications. Through this breakthrough in the data security space, we provide DLP-on-Demand, a concept that is changing the playing field and providing companies with the ultimate control and data protection solution. |
|
| |
| Policy Enforcement |
|
pawaaWEBB goes far beyond the simple authentication mechanism by offering complete control, protection and freedom. pawaaWEBB authenticates the user and it enforces the same IT and security policies on managed and unmanaged computers, within and outside the network, thus ensuring uniform security. Having secured the desktop, as per the user policy, pawaaWEBB ensures that only safe applications can be run on the desktop. The user can only visit the URLs that are permitted by the policy. Also hardware such as USB, Bluetooth, CD/DVD are safe guarded so that data leaks cannot occur during the session. The web application within the organization is configured to only communicate with pawaaWEBB and to drop other browser connections. |
| |
| Monitor, Control and Mask |
|
While on pawaaWEBB, user behavior is monitored and controlled. Detailed logs of user activities are sent back to the server for audit trails, forensic analysis and report generation. These activities include applications launched during the pawaaWEBB session, clipboard activities, screenshots, bandwidth usage, print, URL clicks, etc. Apart from monitoring and controlling user activities and the computer hardware, pawaaWEBB can also mask certain parts of the web pages for certain user groups without having to modify the back end applications and database. |
| |
|
|
|
|
|
|
|
pawaaWEBB – HIGHLIGHTS
• Goes beyond simple authentication and access controls
• Policies enforced on-Demand
• Sensitive data is handled as per IT policy
• Integrates with any web application without modifications
• Complete control over user behavior and data security
• Combination of DLP and IRM
|
|
|
|
|
|
|
|
|
|
|
|
| pawaaWEBB – How it works |
|
|
|
INNOVATION IN WEB SECURITY WITH ‘DLP-ON-DEMAND’ |
|
pawaaWEBB works in the client-server architecture, as a wrapper around the web browser, which is used to enforce the corporate IT policies. Through the combination of pawaaWEBB and pawaaFILE, all user behavior is tracked, monitored and controlled, and corporate policies can be enforced even on unmanaged computers. Any files downloaded are protected through the pawaaFILE format. This unique approach provides complete control, protection and freedom, unmatched by any existing DLP solution. |
|
| |
| MECHANISM |
|
User Authentication: The corporate web portals are configured to connect only with pawaaWEBB. Therefore, when the user tries to access the portal, he is connected to a DLP gateway for authentication through the corporate AD/LDAP. |
|
Policy Creation: The user and group policies are created on the server and assigned to user or user groups. Once the user is authenticated using the pawaaWEBB client, the DLP gateway provides the policy for the user to view. This policy specifies what the user can and cannot do at the desktop while accessing the corporate data using pawaaWEBB client. |
|
Policy Enforcement: The pawaaWEBB client acts as per the policy and allows only the white listed applications and the permitted corporate web applications to run. As per the policy set, it dictates how the information can be handled with those applications. pawaaWEBB client also enforces the hardware policies such as USB, Bluetooth, IR and CD/DVD. |
|
Controls User Behavior: The policy also specifies how the user behavior is controlled at the desktop. According to the policy, user activities such as save, save as, print, clipboard, screenshot, file upload, file download, fields on a form, etc. are monitored and controlled. |
|
Data Masking: Without making any modifications to the web application or the network architecture, pawaaWEBB allows certain users to view the data differently by masking the sensitive data based on the user policy. |
|
pawaaFILE: pawaaWEBB automatically converts any files downloaded or reports generated from the web application in to a pawaaFILE format. |
|
Report Generation: All user activities are reported back to the DLP gateway for the audit trail and compliance purposes. |
| |
 |
|
| |
|
| pawaaWEBB – Firefox add on |
|
|
|
pawaaWEBB currently works only on the Windows operating system with Internet Explorer. However, Pawaa Software will soon release a Mozilla Firefox Add-On, which will work on all operating systems and offer the same functionalities provided by the current pawaaWEBB agent. |
|
Similar to the functioning of the current pawaaWEBB agent, when the user tries to access the corporate web portal from Firefox, he will be prompted to install the pawaaWEBB Add-On, if not already installed on the Firefox browser. Once the Add-On is installed, the user will be authenticated and the IT policies will be enforced. |
|
The pawaaWEBB Add-On provides users the flexibility to seamlessly move between protected and unprotected websites, unlike the desktop pawaaWEBB agent. |
|
| pawaaWEBB - Top 10 reasons |
| |
|
| |
|
- pawaaWEBB: Protection beyond user authentication and access controls
- pawaaWEBB: Integration with AD/LDAP/Open Authentication/Web Service
- pawaaWEBB: Extend corporate IT & Security policy to home or hotel computer
- pawaaWEBB: Controls user behaviour before information is displayed on the browser
- pawaaWEBB: Controls hardware and applications while accessing confidential data
- pawaaWEBB: Controls any type of file that can be uploaded or downloaded
- pawaaWEBB: Data Masking based on the user policy
- pawaaWEBB: Audit trail for all user activities on the web (copy, screenshot, print, save as etc.)
- pawaaWEBB: No changes to existing web application, architecture or network
- pawaaWEBB: Total protection for files downloaded by converting to pawaaFILE format
|
|
|
|