Frequently Asked Questions
- I have a firewall do I still need ryū?
- Yes you still need ryū because web-applications lie outside of the jurisdiction of firewalls. This is due to the nature of the design of web-applications which need to communicate to the outside world, and because of this web-applications are completely exposed to attacks. Therefore, your firewall cannot protect your web-applications.
- What is the difference between a "deep packet inspector" and ryū?
-
A Deep Packet Inspector breaks down a network packet and attempts to put together
the content being transmitted or received over the network before even beginning
to analyze it. Deep packet analyzers have several drawbacks:
- Packet reconstruction isn't guaranteed to reproduce data correctly
- Reconstruction loses contextual information especially sensitivity information. Can you tell whether the next 10 digits are a telephone number, a credit card number or map coordinates disguised as either 7239672184? Well, neither can a reconstruction engine.
- Deep packet inspectors are subject to timing, rerouting, obfuscation, cryptographic and a litany of other attacks
- What is Trustifier Security Emergency Response Service?
-
No matter how large or small, dealing with the consequences of a compromise is never easy for any organization. We have special services to help with emergency incidences. If you are already subscribed to Trustifier Security Emergency Response Service please call your dedicated hot-line.
If you are not a subscriber and are faced with an incidence please contact us in confidence at 888-233-1596 and state that "it's an emergency".
- How does ryū help me post-compromise incident?
-
ryū can act as a virtual patch for your web application for minor compromise incidents, controlled compromises, or in situations where you have discovered bugs in your Web App but do not have the time or resources to fix them immediately.
If you have had a major incident, we encourage you to call us for a consultation. We will help you to address and recover from all aspects of any security breaches you may have experienced or may be experiencing.
- What impact does ryū have on Web Server Performance?
- ryū is based on Trustifier: a very robust and highly optimised real-time security enforcement engine that has very low impact on server performances. Typical performance impact are less than 5% on CPU usage, less than 1% on memory usage and less than 7% on IO subsystems. Peak impacts have never exceeded 11% in real-life empirical measurements on medium to high volume systems.
- Will ryū show me what attacks occured on my system?
- Yes ryū can show you all classifications of attacks your system is being subjected to.
- Can I deploy ryū in a live environment?
-
Yes, but only recommended as an emergency or urgent measure. ryū is designed to be dropped into a live environment without adversly impacting the server operations.
Having said that, a controlled installation is always a better and more prudent approach. As a security promoting organization we can never over-emphasise care. So, if you have a choice, we strongly encourage you to follow formal change management principles and perform controlled deployments of any and all new technologies.


