SlideShare a Scribd company logo
Modernizing Applications by Replacing F5 with the NGINX Application Delivery Controller and Signal Sciences
Modernizing Applications by
Replacing F5 with
NGINX Application Delivery
Controller
and Signal Sciences
Who are we?
Karthik Krishnaswamy
Director, Product Marketing,
NGINX
James Wickett
Head of Research,
Signal Sciences
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern
Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story:
AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
5
What is Signal Sciences?
6
Next Gen Web Application Firewall
• Native integration with NGINX Plus
• OWASP coverage plus
◦ Application DDoS
◦ Account takeover
◦ Application abuse
◦ Rate limiting
◦ Bad bots
◦ Virtual patching
• Minimal tuning needed
• 95% of customers in
blocking mode
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story: AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
Industry Trends Disrupting F5
8
Legacy Modern
Development
Methodology
Waterfall Development DevOps
Application
Architecture
Monolithic Applications Microservices
Compute Infrastructure Bare metal/VMs Containers, Cloud
Attack Vectors OWASP Top 10 API
abuse, Bots
Account Takeovers, L7 DDoS
“The market is moving away from [F5], and is not coming back”
– Tip Chowdry, Analyst, Global Equities Research
Trend 1: Dev Ops
9
Close to 50% organizations are implementing DevOps – Forrester
Benefits of DevOps
• Rapid innovation due to high
feature velocity
• Improved agility
• Greater stability and reliability
Dev Ops: NGINX Plus vs F5
10
Where F5 comes up short:
• Takes weeks to resolve IT tickets to get a
simple application update deployed
• Still very manual process of stepping
through UI
• VLANS, IPs, and other networking config
exposed for each virtual server
Why NGINX Plus is the better choice:
• Fully automatable, no need to file IT tickets
• Works with all DevOps tools
• No VLANs or IPs per virtual server
“It takes 2 weeks to get an F5 modification from the networking team. You know how long it
takes us to change NGINX? It takes 30 seconds to make the change in GitHub, and then we
run the Ansible script. Ta-da, production.”
– Engineer at large telco company
Trend 2: Public Cloud
11
Benefits of Cloud:
• Efficiency: Consumption based
resource allocation and pricing
• Improved agility
• Easy to achieve scale
73% of organizations have at least one application in the cloud*
*2018 Cloud Computing Survey by IDG
Public Cloud: NGINX Plus Vs F5
12
Where F5 comes up short:
• SaaS companies taking business, no need to load
balance Exchange servers if using Office 365
• More expensive than hardware appliances, don’t
want to cannibalize hardware sales
• 5 Gbps throughput limit with pre-built AMIs
• Throughput limits requires license upgrade, can’t
scale up or down as needed
Why NGINX Plus is the better choice:
• Biggest NGINX Plus customers are SaaS
companies
• NGINX Plus is cloud-native software
• 40% AWS deployments use NGINX Plus
• No throughput limits, site licensing to scale up
and down as needed
“We need to manage applications on top of any infrastructure platform, including AWS,
Microsoft Azure, and other cloud platform providers. NGINX Plus provides us the flexibility to
deliver applications across different infrastructure options.”
– Nate Johnson, CEO and Founder at Reliam
Trend 3: Microservices
13
86 percent expect microservices to be the default architecture within five years.*
*Global Microservices Trends Report by LightStep
Benefits of Microservices:
• Resilient applications
• Reusability and Scalability
• Improved agility
Microservices: NGINX Plus vs F5
14
Where F5 comes up short:
• No container option
• No true Kubernetes Ingress Controller solution
• Heavyweight, not portable
Why NGINX Plus is the better choice:
• Can run in containers, top downloaded
application on Docker Hub
• Supported Kubernetes Ingress Controller
• Lightweight and portable
“As we moved to microservices we’ve realized that we needed a much smarter way of
routing pages to our applications...We realized that NGINX Plus, with its better support, with
its DNS resolving, and the advanced metrics that we get now is the way forward. NGINX Plus
allowed us to get to the final mile.”
– John Cleveley, Senior Engineering Manager, BuzzFeed
15
16
Sources: Gartner, Verizon
Trend 4: Web App Attacks Are the
#1 Source of Data Breaches
Web App Attacks
POS Intrusions
Miscellaneous Errors
Privilege Misuse
Cyber-Espionage
Everything Else
Payment Card Skimmers
Physical Theft / Loss
Crimeware
Denial Of Service
908
525
197
172
155
125
86
1
49
56
20%10% 40%30%Percent of Breaches
Less Than 5% of data
center security budgets
are spent on AppSec
17
A New App Landscape
18
Legacy WAF is an Outdated Technology
• WAFs of the 1990s were simple, designed for
monolithic web applications
• WAF was added as a bolt-on functionality to choke
points in the network: CDN & load balancers
• Expensive to operate and maintain with hundreds
of rules to tune and adjust for false positives
“A multi-cloud strategy will become the common strategy for 70%
of enterprises by 2019, up from less than 10% in 2017.”
– Gartner
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story: AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
The Visibility Problem
20
You Can’t Respond to What You Can’t See
• Black-box decisioning with no way to
determine accuracy
• No developer or operations access
• Minimal integrations into today’s
DevOps toolchains
“We can see requests getting blocked but we don't know why.
The samples just show the Ruleset name and not the actual
reason
for blocking the requests.”
– WAF User
21
The Scalability Problem
22
Difficult to Deploy and Manage with Depreciating
Value Over Time
• Rely on inline architecture which is
slow and inefficient
• Require endless new signatures and tuning
• Can’t support multiple CDNs
• Are expensive to deploy and maintain
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern
Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story: AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
See
24
Self-Serve Security Data Makes Your
Team Security Self-Sufficient
• Insights and real-time attack data on
Who, What, When, Where and How
• Make security a developer tool
• See attacks on production apps and
APIs via existing DevOps toolchains
Secure
25
95% of Signal Sciences Customers Are
in Blocking Mode Across All Attack Types
in Production
• Power Rules go beyond OWASP injection
attacks
• Signal Sciences NLX performs network
learning to surface suspicious
events across our network
• SmartParse performs dynamic, application-
specific detections
Scale
26
Easy Deployment and
Management with the Fastest
Time-to-Value in the Industry
• Architecture agnostic
• Installs in minutes
• Requires no ongoing
maintenance as apps change
CLOUD
CONTAINERS
CONFIG
MANAGEMENT
WEB
SERVERS
PLATFORMS
LANGUAGES
API
SERVERLESS
27
See, Secure, and Scale across:
Active Protection Everywhere
Any Attack
OWASP Injection Attacks
PLUS:
Application DDoS
Brute Force Attacks
Application Abuse & Misuse
Request Rate Limiting
Account Takeover
Bad Bots
Virtual Patching
Any DevOps Toolchain
INCLUDING:
Generic Webhooks & Any
Custom
Tools via Full RESTFul/JSON
API
Any App
Cloud Containers, PaaS
& Serverless
Web Servers & Languages
Gateways & Proxies
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story: AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
1. NGINX Plus Behind F5
29
• Easiest way to introduce
NGINX Plus into your network
• F5 layer 4 load balances to
NGINX Plus
• Can start small with one
application being behind
NGINX Plus and then expand
2. NGINX Plus Alongside F5
30
• Parallel NGINX Plus
deployment
• Good architecture if adopting
public cloud while still keeping
private datacenter
• Can also start small with one
application being behind
NGINX Plus and then expand
3. NGINX Plus Instead of F5
31
• F5 completely decommissioned,
use NGINX Plus for all load
balancing
• Previous 2 architectures are
intermediaries to this eventual
goal
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story: AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
Micro Load Balancers
33
• Load balancer per application
• Load balancer per customer for
SaaS providers
• Configuration stored along with
application in GitHub
• Fully portable
Kubernetes Ingress Controller
34
• NGINX runs in 2/3rs of
Kubernetes environments.
• Lightweight footprint makes it
ideal for containerized
environments
Application Delivery Module for NGINX Controller
35
Key Capabilities of Application Delivery Module
36
• Load balancer management
at scale
• Real-time monitoring & alerting
• Simplified configuration
management
• Customizable dashboards
• Best practice recommendations
• Multi-cloud support
Learn more: nginx.com/products/nginx-controller
API Gateway
37
• 40% of deploy NGINX instances
are used as API gateway
• Capital One handles 12 billion
transactions per day with
NGINX API gateway
• F5 BIG-IP cannot be used as an
API gateway
API Management Module for NGINX Controller
38
Key Capabilities of Application Delivery Module
39
• API Definition & Publication
• Rate Limiting
• Authentication & Authorization
• Real-time monitoring & alerting
• Customizable dashboards
• Multi-cloud support
Learn more: nginx.com/products/nginx-controller
Hybrid SaaS Architecture:
Fast Local Decisions Plus the Power of Cloud
40
• Optimized local detection via SmartParse, eliminating
false positive decisions
• Decisioning is enriched by Cloud Engine intelligence –
not signatures
• Fail-open design avoids app downtime shut-downs
and blocked access
Signal Sciences and NGINX Plus
Signal Sciences Beat Out F5 and All Other WAFs
42
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story:
AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
44
“Moving to the next generation of F5 hardware was
going to cost more than $1M per data center. NGINX
Plus gave us 50% more transactions per server, for one-
sixth the price. We’re now 100% hardware free.”
– Senior Networking Leader, AppNexus
45
Gartner Peer Insights
What our customers are saying
Unlike the majority of WAF products out there, Signal Sciences does not need hundreds of stateful rules to function
properly. We were able to get Signal Sciences up and running within a few days and only required 10 or so rules to
get configured and running in full-block mode.
– Head of Information Security, Infrastructure & IT, Finance Industry
Signal Sciences is by far the only security product I've used that was not only simple to install, but also simple to use.
We went from a POC to purchase in just weeks (usually it takes months) and once we installed it, we instantly put
the WAF into blocking mode as it did such a good job without false positives.
– Senior Security Engineer, Communications Industry
Web Application Firewalls have historically been a tricky piece of technology to leverage in existing environments;
Signal Sciences' approach means less operational overhead in getting it working and more time being spent
leveraging the data it provides.
– Security and Risk Management, Healthcare Industry
Reviews from enterprise peers—verified by
Gartner
Introduction
Industry trends that are
disrupting F5
Challenges with legacy WAF
solutions
Resolving Challenges with Signal
Sciences – WAF For the Modern Era
Three options to gracefully move
away from F5
Beyond F5
Customer success story: AppNexus
Summary
1
2
3
4
5
6
7
8
Agenda
Summary
47
• F5 BIG-IP is the aging veteran of the tech industry
• The market has moved away from F5, and they have not kept up
• Embrace DevOps, Cloud and Microservices by replacing F5 with
NGINX ADC and Signal Sciences
• Three ways to replace F5 BIG-IP with NGINX Plus
• AppNexus saved over 50% while getting the benefits of a software solution
by replacing F5 BIG-IP with NGINX Plus
Download Our Free Ebook
48
• How to migrate F5 BIG-IP configuration and iRules
to NGINX, with detailed examples
• How to pick out a standard x86 server
• How to install and configure Linux
• Why you should go with a software load balancer,
and not hardware
Download now: nginx.com/resources/library/f5-big-ip-nginx-migration-guide/
Q&A
Try NGINX Plus free for 30 days: nginx.com/free-trial-request
Try NGINX Controller ADC free for 30 days: nginx.com/products/nginx-
controller/#free-trial-controller

More Related Content

PDF
[115]쿠팡 서비스 클라우드 마이그레이션 통해 배운것들
NAVER D2
 
PPTX
Infrastructure-as-Code (IaC) using Terraform
Adin Ermie
 
PDF
Cluster-as-code. The Many Ways towards Kubernetes
QAware GmbH
 
PPTX
API Security in a Microservice Architecture
Matt McLarty
 
PDF
[오픈소스컨설팅] 서비스 메쉬(Service mesh)
Open Source Consulting
 
PDF
Helm 3
Matthew Farina
 
PPTX
Terraform modules restructured
Ami Mahloof
 
PDF
Kubernetes Application Deployment with Helm - A beginner Guide!
Krishna-Kumar
 
[115]쿠팡 서비스 클라우드 마이그레이션 통해 배운것들
NAVER D2
 
Infrastructure-as-Code (IaC) using Terraform
Adin Ermie
 
Cluster-as-code. The Many Ways towards Kubernetes
QAware GmbH
 
API Security in a Microservice Architecture
Matt McLarty
 
[오픈소스컨설팅] 서비스 메쉬(Service mesh)
Open Source Consulting
 
Terraform modules restructured
Ami Mahloof
 
Kubernetes Application Deployment with Helm - A beginner Guide!
Krishna-Kumar
 

What's hot (20)

PPTX
AWS API Gateway
Muhammed YALÇIN
 
PDF
진정한 하이브리드 환경을 위한 올바른 선택, AWS Outposts! - 강동환 AWS 솔루션즈 아키텍트 :: AWS Summit Seou...
Amazon Web Services Korea
 
PPTX
Docker Kubernetes Istio
Araf Karsh Hamid
 
PDF
Cilium - Bringing the BPF Revolution to Kubernetes Networking and Security
Thomas Graf
 
PPTX
Serverless integration with Knative and Apache Camel on Kubernetes
Claus Ibsen
 
PDF
Docker Explained | What Is A Docker Container? | Docker Simplified | Docker T...
Edureka!
 
PDF
Ansible Introduction
Robert Reiz
 
PPTX
Canary Releases on Kubernetes w/ Spinnaker, Istio, and Prometheus
Kublr
 
PDF
Kubernetes Secrets Management on Production with Demo
Opsta
 
PDF
Prometheus - basics
Juraj Hantak
 
PDF
Fargate 를 이용한 ECS with VPC 1부
Hyun-Mook Choi
 
PDF
Efficient API delivery with APIOps
Sven Bernhardt
 
PPTX
Devops ppt
Sulekha IT Training
 
PDF
Kubernetes extensibility: CRDs & Operators
SIGHUP
 
PDF
Introduction to Docker Containers - Docker Captain
Ajeet Singh Raina
 
PDF
[OpenStack Days Korea 2016] Track3 - 오픈스택 환경에서 공유 파일 시스템 구현하기: 마닐라(Manila) 프로젝트
OpenStack Korea Community
 
PPTX
Comprehensive Terraform Training
Yevgeniy Brikman
 
PDF
AWS KMS를 활용하여 안전한 AWS 환경을 구축하기 위한 전략::임기성::AWS Summit Seoul 2018
Amazon Web Services Korea
 
PDF
Kubernetes/ EKS - 김광영 (AWS 솔루션즈 아키텍트)
Amazon Web Services Korea
 
PPTX
Introduction to helm
Jeeva Chelladhurai
 
AWS API Gateway
Muhammed YALÇIN
 
진정한 하이브리드 환경을 위한 올바른 선택, AWS Outposts! - 강동환 AWS 솔루션즈 아키텍트 :: AWS Summit Seou...
Amazon Web Services Korea
 
Docker Kubernetes Istio
Araf Karsh Hamid
 
Cilium - Bringing the BPF Revolution to Kubernetes Networking and Security
Thomas Graf
 
Serverless integration with Knative and Apache Camel on Kubernetes
Claus Ibsen
 
Docker Explained | What Is A Docker Container? | Docker Simplified | Docker T...
Edureka!
 
Ansible Introduction
Robert Reiz
 
Canary Releases on Kubernetes w/ Spinnaker, Istio, and Prometheus
Kublr
 
Kubernetes Secrets Management on Production with Demo
Opsta
 
Prometheus - basics
Juraj Hantak
 
Fargate 를 이용한 ECS with VPC 1부
Hyun-Mook Choi
 
Efficient API delivery with APIOps
Sven Bernhardt
 
Kubernetes extensibility: CRDs & Operators
SIGHUP
 
Introduction to Docker Containers - Docker Captain
Ajeet Singh Raina
 
[OpenStack Days Korea 2016] Track3 - 오픈스택 환경에서 공유 파일 시스템 구현하기: 마닐라(Manila) 프로젝트
OpenStack Korea Community
 
Comprehensive Terraform Training
Yevgeniy Brikman
 
AWS KMS를 활용하여 안전한 AWS 환경을 구축하기 위한 전략::임기성::AWS Summit Seoul 2018
Amazon Web Services Korea
 
Kubernetes/ EKS - 김광영 (AWS 솔루션즈 아키텍트)
Amazon Web Services Korea
 
Introduction to helm
Jeeva Chelladhurai
 
Ad

Similar to Modernizing Applications by Replacing F5 with the NGINX Application Delivery Controller and Signal Sciences (20)

PPTX
Replacing and Augmenting F5 BIG-IP with NGINX Plus
NGINX, Inc.
 
PDF
Replacing and Augmenting F5 BIG-IP with NGINX Plus - EMEA
NGINX, Inc.
 
PPTX
Migrating from BIG-IP Deployment to NGINX ADC
NGINX, Inc.
 
PDF
NGINX Controller: faster deployments, fewer headaches
Kangaroot
 
PDF
Driving success in the cloud with NGINX
NGINX, Inc.
 
PDF
Application Security with NGINX
NGINX, Inc.
 
PDF
From Code to Customer with F5 and NGNX London Nov 19
NGINX, Inc.
 
PDF
Application Security with NGINX | APAC
NGINX, Inc.
 
PPTX
Gain multi-cloud versatility with software load balancing designed for cloud-...
Ashnikbiz
 
PDF
Securing Your Apps & APIs in the Cloud
Olivia LaMar
 
PDF
IObit Uninstaller Pro Crack 13.2.0.5 + Key Download 2025
maharajput103
 
PDF
Movavi Screen Recorder Studio 22.5.2 Crack
aladdinkhana47
 
PDF
What's New with NGINX Application Security Solutions
NGINX, Inc.
 
PDF
IDM Crack 2025 Internet Download Manger Patch
wistrendugftr
 
PDF
NGINX: The Past, Present and Future of the Modern Web
Kevin Jones
 
PDF
ITB2017 - Nginx ppf intothebox_2017
Ortus Solutions, Corp
 
PPTX
Scale your application to new heights with NGINX and AWS
NGINX, Inc.
 
PDF
Driving Success In The Cloud With NGINX
NGINX, Inc.
 
PPTX
Controller and Coffee: Deliver APIs in Real Time with API Management
NGINX, Inc.
 
PPTX
Flawless Application Delivery with NGINX Plus
Peter Guagenti
 
Replacing and Augmenting F5 BIG-IP with NGINX Plus
NGINX, Inc.
 
Replacing and Augmenting F5 BIG-IP with NGINX Plus - EMEA
NGINX, Inc.
 
Migrating from BIG-IP Deployment to NGINX ADC
NGINX, Inc.
 
NGINX Controller: faster deployments, fewer headaches
Kangaroot
 
Driving success in the cloud with NGINX
NGINX, Inc.
 
Application Security with NGINX
NGINX, Inc.
 
From Code to Customer with F5 and NGNX London Nov 19
NGINX, Inc.
 
Application Security with NGINX | APAC
NGINX, Inc.
 
Gain multi-cloud versatility with software load balancing designed for cloud-...
Ashnikbiz
 
Securing Your Apps & APIs in the Cloud
Olivia LaMar
 
IObit Uninstaller Pro Crack 13.2.0.5 + Key Download 2025
maharajput103
 
Movavi Screen Recorder Studio 22.5.2 Crack
aladdinkhana47
 
What's New with NGINX Application Security Solutions
NGINX, Inc.
 
IDM Crack 2025 Internet Download Manger Patch
wistrendugftr
 
NGINX: The Past, Present and Future of the Modern Web
Kevin Jones
 
ITB2017 - Nginx ppf intothebox_2017
Ortus Solutions, Corp
 
Scale your application to new heights with NGINX and AWS
NGINX, Inc.
 
Driving Success In The Cloud With NGINX
NGINX, Inc.
 
Controller and Coffee: Deliver APIs in Real Time with API Management
NGINX, Inc.
 
Flawless Application Delivery with NGINX Plus
Peter Guagenti
 
Ad

More from NGINX, Inc. (20)

PDF
【NGINXセミナー】 Ingressを使ってマイクロサービスの運用を楽にする方法
NGINX, Inc.
 
PDF
【NGINXセミナー】 NGINXのWAFとは?その使い方と設定方法 解説セミナー
NGINX, Inc.
 
PDF
【NGINXセミナー】API ゲートウェイとしてのNGINX Plus活用方法
NGINX, Inc.
 
PPTX
Get Hands-On with NGINX and QUIC+HTTP/3
NGINX, Inc.
 
PPTX
Managing Kubernetes Cost and Performance with NGINX & Kubecost
NGINX, Inc.
 
PDF
Manage Microservices Chaos and Complexity with Observability
NGINX, Inc.
 
PDF
Accelerate Microservices Deployments with Automation
NGINX, Inc.
 
PDF
Unit 2: Microservices Secrets Management 101
NGINX, Inc.
 
PDF
Unit 1: Apply the Twelve-Factor App to Microservices Architectures
NGINX, Inc.
 
PDF
NGINX基本セミナー(セキュリティ編)~NGINXでセキュアなプラットフォームを実現する方法!
NGINX, Inc.
 
PDF
Easily View, Manage, and Scale Your App Security with F5 NGINX
NGINX, Inc.
 
PDF
NGINXセミナー(基本編)~いまさら聞けないNGINXコンフィグなど基本がわかる!
NGINX, Inc.
 
PDF
Keep Ahead of Evolving Cyberattacks with OPSWAT and F5 NGINX
NGINX, Inc.
 
PPTX
Install and Configure NGINX Unit, the Universal Application, Web, and Proxy S...
NGINX, Inc.
 
PPTX
Protecting Apps from Hacks in Kubernetes with NGINX
NGINX, Inc.
 
PPTX
NGINX Kubernetes API
NGINX, Inc.
 
PPTX
Successfully Implement Your API Strategy with NGINX
NGINX, Inc.
 
PPTX
Installing and Configuring NGINX Open Source
NGINX, Inc.
 
PPTX
Shift Left for More Secure Apps with F5 NGINX
NGINX, Inc.
 
PPTX
How to Avoid the Top 5 NGINX Configuration Mistakes.pptx
NGINX, Inc.
 
【NGINXセミナー】 Ingressを使ってマイクロサービスの運用を楽にする方法
NGINX, Inc.
 
【NGINXセミナー】 NGINXのWAFとは?その使い方と設定方法 解説セミナー
NGINX, Inc.
 
【NGINXセミナー】API ゲートウェイとしてのNGINX Plus活用方法
NGINX, Inc.
 
Get Hands-On with NGINX and QUIC+HTTP/3
NGINX, Inc.
 
Managing Kubernetes Cost and Performance with NGINX & Kubecost
NGINX, Inc.
 
Manage Microservices Chaos and Complexity with Observability
NGINX, Inc.
 
Accelerate Microservices Deployments with Automation
NGINX, Inc.
 
Unit 2: Microservices Secrets Management 101
NGINX, Inc.
 
Unit 1: Apply the Twelve-Factor App to Microservices Architectures
NGINX, Inc.
 
NGINX基本セミナー(セキュリティ編)~NGINXでセキュアなプラットフォームを実現する方法!
NGINX, Inc.
 
Easily View, Manage, and Scale Your App Security with F5 NGINX
NGINX, Inc.
 
NGINXセミナー(基本編)~いまさら聞けないNGINXコンフィグなど基本がわかる!
NGINX, Inc.
 
Keep Ahead of Evolving Cyberattacks with OPSWAT and F5 NGINX
NGINX, Inc.
 
Install and Configure NGINX Unit, the Universal Application, Web, and Proxy S...
NGINX, Inc.
 
Protecting Apps from Hacks in Kubernetes with NGINX
NGINX, Inc.
 
NGINX Kubernetes API
NGINX, Inc.
 
Successfully Implement Your API Strategy with NGINX
NGINX, Inc.
 
Installing and Configuring NGINX Open Source
NGINX, Inc.
 
Shift Left for More Secure Apps with F5 NGINX
NGINX, Inc.
 
How to Avoid the Top 5 NGINX Configuration Mistakes.pptx
NGINX, Inc.
 

Recently uploaded (20)

PDF
Key Features to Look for in Arizona App Development Services
Net-Craft.com
 
PDF
PFAS Reporting Requirements 2026 Are You Submission Ready Certivo.pdf
Certivo Inc
 
PDF
Multi-factor Authentication (MFA) requirement for Microsoft 365 Admin Center_...
Q-Advise
 
PPTX
Presentation about variables and constant.pptx
safalsingh810
 
PDF
Exploring AI Agents in Process Industries
amoreira6
 
PDF
On Software Engineers' Productivity - Beyond Misleading Metrics
Romén Rodríguez-Gil
 
PPTX
Presentation of Computer CLASS 2 .pptx
darshilchaudhary558
 
PDF
Protecting the Digital World Cyber Securit
dnthakkar16
 
PDF
Become an Agentblazer Champion Challenge Kickoff
Dele Amefo
 
DOCX
The Future of Smart Factories Why Embedded Analytics Leads the Way
Varsha Nayak
 
PPTX
The-Dawn-of-AI-Reshaping-Our-World.pptxx
parthbhanushali307
 
PDF
The Role of Automation and AI in EHS Management for Data Centers.pdf
TECH EHS Solution
 
PPTX
Visualising Data with Scatterplots in IBM SPSS Statistics.pptx
Version 1 Analytics
 
PDF
Become an Agentblazer Champion Challenge
Dele Amefo
 
PPTX
Services offered by Dynamic Solutions in Pakistan
DaniyaalAdeemShibli1
 
PDF
Solar Panel Installation Guide – Step By Step Process 2025.pdf
CRMLeaf
 
PPTX
AI-Ready Handoff: Auto-Summaries & Draft Emails from MQL to Slack in One Flow
bbedford2
 
PDF
QAware_Mario-Leander_Reimer_Architecting and Building a K8s-based AI Platform...
QAware GmbH
 
PPTX
slidesgo-unlocking-the-code-the-dynamic-dance-of-variables-and-constants-2024...
kr2589474
 
PDF
Microsoft Teams Essentials; The pricing and the versions_PDF.pdf
Q-Advise
 
Key Features to Look for in Arizona App Development Services
Net-Craft.com
 
PFAS Reporting Requirements 2026 Are You Submission Ready Certivo.pdf
Certivo Inc
 
Multi-factor Authentication (MFA) requirement for Microsoft 365 Admin Center_...
Q-Advise
 
Presentation about variables and constant.pptx
safalsingh810
 
Exploring AI Agents in Process Industries
amoreira6
 
On Software Engineers' Productivity - Beyond Misleading Metrics
Romén Rodríguez-Gil
 
Presentation of Computer CLASS 2 .pptx
darshilchaudhary558
 
Protecting the Digital World Cyber Securit
dnthakkar16
 
Become an Agentblazer Champion Challenge Kickoff
Dele Amefo
 
The Future of Smart Factories Why Embedded Analytics Leads the Way
Varsha Nayak
 
The-Dawn-of-AI-Reshaping-Our-World.pptxx
parthbhanushali307
 
The Role of Automation and AI in EHS Management for Data Centers.pdf
TECH EHS Solution
 
Visualising Data with Scatterplots in IBM SPSS Statistics.pptx
Version 1 Analytics
 
Become an Agentblazer Champion Challenge
Dele Amefo
 
Services offered by Dynamic Solutions in Pakistan
DaniyaalAdeemShibli1
 
Solar Panel Installation Guide – Step By Step Process 2025.pdf
CRMLeaf
 
AI-Ready Handoff: Auto-Summaries & Draft Emails from MQL to Slack in One Flow
bbedford2
 
QAware_Mario-Leander_Reimer_Architecting and Building a K8s-based AI Platform...
QAware GmbH
 
slidesgo-unlocking-the-code-the-dynamic-dance-of-variables-and-constants-2024...
kr2589474
 
Microsoft Teams Essentials; The pricing and the versions_PDF.pdf
Q-Advise
 

Modernizing Applications by Replacing F5 with the NGINX Application Delivery Controller and Signal Sciences

  • 2. Modernizing Applications by Replacing F5 with NGINX Application Delivery Controller and Signal Sciences
  • 3. Who are we? Karthik Krishnaswamy Director, Product Marketing, NGINX James Wickett Head of Research, Signal Sciences
  • 4. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 5. 5
  • 6. What is Signal Sciences? 6 Next Gen Web Application Firewall • Native integration with NGINX Plus • OWASP coverage plus ◦ Application DDoS ◦ Account takeover ◦ Application abuse ◦ Rate limiting ◦ Bad bots ◦ Virtual patching • Minimal tuning needed • 95% of customers in blocking mode
  • 7. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 8. Industry Trends Disrupting F5 8 Legacy Modern Development Methodology Waterfall Development DevOps Application Architecture Monolithic Applications Microservices Compute Infrastructure Bare metal/VMs Containers, Cloud Attack Vectors OWASP Top 10 API abuse, Bots Account Takeovers, L7 DDoS “The market is moving away from [F5], and is not coming back” – Tip Chowdry, Analyst, Global Equities Research
  • 9. Trend 1: Dev Ops 9 Close to 50% organizations are implementing DevOps – Forrester Benefits of DevOps • Rapid innovation due to high feature velocity • Improved agility • Greater stability and reliability
  • 10. Dev Ops: NGINX Plus vs F5 10 Where F5 comes up short: • Takes weeks to resolve IT tickets to get a simple application update deployed • Still very manual process of stepping through UI • VLANS, IPs, and other networking config exposed for each virtual server Why NGINX Plus is the better choice: • Fully automatable, no need to file IT tickets • Works with all DevOps tools • No VLANs or IPs per virtual server “It takes 2 weeks to get an F5 modification from the networking team. You know how long it takes us to change NGINX? It takes 30 seconds to make the change in GitHub, and then we run the Ansible script. Ta-da, production.” – Engineer at large telco company
  • 11. Trend 2: Public Cloud 11 Benefits of Cloud: • Efficiency: Consumption based resource allocation and pricing • Improved agility • Easy to achieve scale 73% of organizations have at least one application in the cloud* *2018 Cloud Computing Survey by IDG
  • 12. Public Cloud: NGINX Plus Vs F5 12 Where F5 comes up short: • SaaS companies taking business, no need to load balance Exchange servers if using Office 365 • More expensive than hardware appliances, don’t want to cannibalize hardware sales • 5 Gbps throughput limit with pre-built AMIs • Throughput limits requires license upgrade, can’t scale up or down as needed Why NGINX Plus is the better choice: • Biggest NGINX Plus customers are SaaS companies • NGINX Plus is cloud-native software • 40% AWS deployments use NGINX Plus • No throughput limits, site licensing to scale up and down as needed “We need to manage applications on top of any infrastructure platform, including AWS, Microsoft Azure, and other cloud platform providers. NGINX Plus provides us the flexibility to deliver applications across different infrastructure options.” – Nate Johnson, CEO and Founder at Reliam
  • 13. Trend 3: Microservices 13 86 percent expect microservices to be the default architecture within five years.* *Global Microservices Trends Report by LightStep Benefits of Microservices: • Resilient applications • Reusability and Scalability • Improved agility
  • 14. Microservices: NGINX Plus vs F5 14 Where F5 comes up short: • No container option • No true Kubernetes Ingress Controller solution • Heavyweight, not portable Why NGINX Plus is the better choice: • Can run in containers, top downloaded application on Docker Hub • Supported Kubernetes Ingress Controller • Lightweight and portable “As we moved to microservices we’ve realized that we needed a much smarter way of routing pages to our applications...We realized that NGINX Plus, with its better support, with its DNS resolving, and the advanced metrics that we get now is the way forward. NGINX Plus allowed us to get to the final mile.” – John Cleveley, Senior Engineering Manager, BuzzFeed
  • 15. 15
  • 16. 16 Sources: Gartner, Verizon Trend 4: Web App Attacks Are the #1 Source of Data Breaches Web App Attacks POS Intrusions Miscellaneous Errors Privilege Misuse Cyber-Espionage Everything Else Payment Card Skimmers Physical Theft / Loss Crimeware Denial Of Service 908 525 197 172 155 125 86 1 49 56 20%10% 40%30%Percent of Breaches Less Than 5% of data center security budgets are spent on AppSec
  • 17. 17
  • 18. A New App Landscape 18 Legacy WAF is an Outdated Technology • WAFs of the 1990s were simple, designed for monolithic web applications • WAF was added as a bolt-on functionality to choke points in the network: CDN & load balancers • Expensive to operate and maintain with hundreds of rules to tune and adjust for false positives “A multi-cloud strategy will become the common strategy for 70% of enterprises by 2019, up from less than 10% in 2017.” – Gartner
  • 19. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 20. The Visibility Problem 20 You Can’t Respond to What You Can’t See • Black-box decisioning with no way to determine accuracy • No developer or operations access • Minimal integrations into today’s DevOps toolchains “We can see requests getting blocked but we don't know why. The samples just show the Ruleset name and not the actual reason for blocking the requests.” – WAF User
  • 21. 21
  • 22. The Scalability Problem 22 Difficult to Deploy and Manage with Depreciating Value Over Time • Rely on inline architecture which is slow and inefficient • Require endless new signatures and tuning • Can’t support multiple CDNs • Are expensive to deploy and maintain
  • 23. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 24. See 24 Self-Serve Security Data Makes Your Team Security Self-Sufficient • Insights and real-time attack data on Who, What, When, Where and How • Make security a developer tool • See attacks on production apps and APIs via existing DevOps toolchains
  • 25. Secure 25 95% of Signal Sciences Customers Are in Blocking Mode Across All Attack Types in Production • Power Rules go beyond OWASP injection attacks • Signal Sciences NLX performs network learning to surface suspicious events across our network • SmartParse performs dynamic, application- specific detections
  • 26. Scale 26 Easy Deployment and Management with the Fastest Time-to-Value in the Industry • Architecture agnostic • Installs in minutes • Requires no ongoing maintenance as apps change CLOUD CONTAINERS CONFIG MANAGEMENT WEB SERVERS PLATFORMS LANGUAGES API SERVERLESS
  • 27. 27 See, Secure, and Scale across: Active Protection Everywhere Any Attack OWASP Injection Attacks PLUS: Application DDoS Brute Force Attacks Application Abuse & Misuse Request Rate Limiting Account Takeover Bad Bots Virtual Patching Any DevOps Toolchain INCLUDING: Generic Webhooks & Any Custom Tools via Full RESTFul/JSON API Any App Cloud Containers, PaaS & Serverless Web Servers & Languages Gateways & Proxies
  • 28. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 29. 1. NGINX Plus Behind F5 29 • Easiest way to introduce NGINX Plus into your network • F5 layer 4 load balances to NGINX Plus • Can start small with one application being behind NGINX Plus and then expand
  • 30. 2. NGINX Plus Alongside F5 30 • Parallel NGINX Plus deployment • Good architecture if adopting public cloud while still keeping private datacenter • Can also start small with one application being behind NGINX Plus and then expand
  • 31. 3. NGINX Plus Instead of F5 31 • F5 completely decommissioned, use NGINX Plus for all load balancing • Previous 2 architectures are intermediaries to this eventual goal
  • 32. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 33. Micro Load Balancers 33 • Load balancer per application • Load balancer per customer for SaaS providers • Configuration stored along with application in GitHub • Fully portable
  • 34. Kubernetes Ingress Controller 34 • NGINX runs in 2/3rs of Kubernetes environments. • Lightweight footprint makes it ideal for containerized environments
  • 35. Application Delivery Module for NGINX Controller 35
  • 36. Key Capabilities of Application Delivery Module 36 • Load balancer management at scale • Real-time monitoring & alerting • Simplified configuration management • Customizable dashboards • Best practice recommendations • Multi-cloud support Learn more: nginx.com/products/nginx-controller
  • 37. API Gateway 37 • 40% of deploy NGINX instances are used as API gateway • Capital One handles 12 billion transactions per day with NGINX API gateway • F5 BIG-IP cannot be used as an API gateway
  • 38. API Management Module for NGINX Controller 38
  • 39. Key Capabilities of Application Delivery Module 39 • API Definition & Publication • Rate Limiting • Authentication & Authorization • Real-time monitoring & alerting • Customizable dashboards • Multi-cloud support Learn more: nginx.com/products/nginx-controller
  • 40. Hybrid SaaS Architecture: Fast Local Decisions Plus the Power of Cloud 40 • Optimized local detection via SmartParse, eliminating false positive decisions • Decisioning is enriched by Cloud Engine intelligence – not signatures • Fail-open design avoids app downtime shut-downs and blocked access
  • 41. Signal Sciences and NGINX Plus
  • 42. Signal Sciences Beat Out F5 and All Other WAFs 42
  • 43. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 44. 44 “Moving to the next generation of F5 hardware was going to cost more than $1M per data center. NGINX Plus gave us 50% more transactions per server, for one- sixth the price. We’re now 100% hardware free.” – Senior Networking Leader, AppNexus
  • 45. 45 Gartner Peer Insights What our customers are saying Unlike the majority of WAF products out there, Signal Sciences does not need hundreds of stateful rules to function properly. We were able to get Signal Sciences up and running within a few days and only required 10 or so rules to get configured and running in full-block mode. – Head of Information Security, Infrastructure & IT, Finance Industry Signal Sciences is by far the only security product I've used that was not only simple to install, but also simple to use. We went from a POC to purchase in just weeks (usually it takes months) and once we installed it, we instantly put the WAF into blocking mode as it did such a good job without false positives. – Senior Security Engineer, Communications Industry Web Application Firewalls have historically been a tricky piece of technology to leverage in existing environments; Signal Sciences' approach means less operational overhead in getting it working and more time being spent leveraging the data it provides. – Security and Risk Management, Healthcare Industry Reviews from enterprise peers—verified by Gartner
  • 46. Introduction Industry trends that are disrupting F5 Challenges with legacy WAF solutions Resolving Challenges with Signal Sciences – WAF For the Modern Era Three options to gracefully move away from F5 Beyond F5 Customer success story: AppNexus Summary 1 2 3 4 5 6 7 8 Agenda
  • 47. Summary 47 • F5 BIG-IP is the aging veteran of the tech industry • The market has moved away from F5, and they have not kept up • Embrace DevOps, Cloud and Microservices by replacing F5 with NGINX ADC and Signal Sciences • Three ways to replace F5 BIG-IP with NGINX Plus • AppNexus saved over 50% while getting the benefits of a software solution by replacing F5 BIG-IP with NGINX Plus
  • 48. Download Our Free Ebook 48 • How to migrate F5 BIG-IP configuration and iRules to NGINX, with detailed examples • How to pick out a standard x86 server • How to install and configure Linux • Why you should go with a software load balancer, and not hardware Download now: nginx.com/resources/library/f5-big-ip-nginx-migration-guide/
  • 49. Q&A Try NGINX Plus free for 30 days: nginx.com/free-trial-request Try NGINX Controller ADC free for 30 days: nginx.com/products/nginx- controller/#free-trial-controller

Editor's Notes

  • #4: - We will
  • #5: - We will
  • #6: Our portfolio consists of our flagship product NGINX Plus. This is where it all started. It’s a versatile software solution that’s a load balancer, API Gateway, content cache and web server. Based on Popular Open source product, NGINX Plus offers enterprise grade support and features that enable you to deliver applications and APIs in a reliable and secure manner without compromising performance. Extend same Controller is our management plane that lets you configure and deploy NGINX Plus as a load balancer for application delivery and as an API gateway to manage your APIs. NGINX controller’s ADC module lets you configure, validate and monitor your load balancers at scale. NGINX Controller’s API Management module let’s you define, publish, secure, monitor and analyze your APIs. There’s an upcoming service mesh module However you want to configure NGINX Plus, you can do it using Controller. Controller provides deep analytics, configuration and control capabilities. It supports a policy based approach to management, The only all-in-one load balancer, content cache, and web server solution Earlier this year The NGINX Application Platform is a suite of products that together form the core of what organizations need to modernize their infrastructure and move to microservices. The NGINX Application Platform includes NGINX Plus for load balancing and application delivery, the NGINX WAF for security, and NGINX Unit to run the application code, all monitored and managed by the NGINX Controller. Note: Please mention that this is a vision and not all the pieces are available yet, such Controller controlling Unit. released enhancements all around the application platform.
  • #8: - We will
  • #9: Age of digital
  • #10: According to Amazon, DevOps is the combination of cultural philosophies, practices, and tools that increases an organization’s ability to deliver applications and services at high velocity: evolving and improving products at a faster pace than organizations using traditional software development and infrastructure management processes. This speed enables organizations to better serve their customers and compete more effectively in the market. It’s an approach that breaks down silos between dev and ops teams. They work very closely during app development and especially during rolling out releases and deployments. What are the benefits of this approach: Because of this close collaboration, teams are able to introduce new features very quickly. They are able to achieve high feature velocity which in turn results in rapid innovation. Amazon deploys code every 11.7 seconds! Nordstrom went from twice per year to monthly for their mobile apps. No submitting tickets to IT for infrastructure needs. Through use of a variety of tools such as Chef or Puppet as well as automating common config, deployment and testing tasks, they are able to improv e agility and respond quickly to the needs of their customers. This also results in greater stability and reliability. Going back to the DevOps culture, early detection and rapid correction of erriors
  • #11: Toolchain integration, Config is more complex, allocate IP address to create a new virtual server. NGINX Layer 7 to multiplex connections on a single IP address
  • #12: Efficiency: On-Demand instances let you pay for compute capacity by the hour or second (minimum of 60 seconds) with no long-term commitments. You can access as much or as little as you need, and scale up and down as required with only a few minutes notice. Agility: In a cloud computing environment, new IT resources can be obtained and deployed with just a few clicks. \which means you reduce the time it takes to make those resources available to your developers from weeks to just minutes. This results in a dramatic increase in agility for the organization, since the cost and time it takes to experiment and develop is significantly lower. It’s also easy to improe scale
  • #14: Microservices is an approach to software architecture that builds a large, complex application from multiple small components that each perform a single function, such as authentication, notification, or payment processing. Each microservice is a distinct unit within the software development project, with its own codebase, infrastructure, and database. The microservices work together, communicating through web APIs or messaging queues to respond to incoming events. You break down a monolith into a number of miroservices – each performing a single function. What are the benefits of this approach: Resilience: Better fault isolation; if one microservice fails, the others will continue to work.  whole system is not impacted or goes down when there are errors in an individual part of the system. The Circuit Breaker pattern wraps a protected function call in a circuit breaker object, which monitors for failures. Once a failure crosses the threshold, the circuit breaker trips, and all further calls to the circuit breaker return with an error, without the protected call being made at all for a certain configured timeout. Reusability and Scalability: Better scaling - different parts of the system can be scaled independently Improved agility: Software built as microservices can be broken down into multiple component services, so that each of these services can be deployed and then redeployed independently without compromising the integrity of an application. That means that microservice architecture gives developers the freedom to independently develop and deploy services. Different teams can be working on different components simultaneously without having to wait for one team to finish a chunk of work before starting theirs . This shortens cycle times.
  • #15: Big-ip with a separate container that programs BIG-IP to route stuff
  • #19: When you look at the legacy WAF solutions that are on the market today – there are several issues that lend them to be inadequate in solving this problem. Initially they were developed over 15 years ago to support monolithic and static web applications that rarely ever changed. Traditionally delivered via bolt-on functionality to network-based choke points such as CDNs and Load Balancers. They require heavy tuning and are very prone to false-positives……and lastly, they are expensive to own and operate. The menu of options has grown for building web applications. A monolithic security solution won’t work for microservices and multi-cloud architecture. Cloud adoption is growing quickly – confirm with prospect their cloud strategy.
  • #20: - We will
  • #21: Other quote: Overall, If I subscribe to this ruleset, all of it seems like a Blackbox and requests are getting magically blocked, which is not good." WAF User December 2017
  • #24: - We will
  • #25: Visibility is a critical factor.....and now for the first time developers can see real-time information on Who, what, when, where , and how their applications are being attacked or abused. This now facilitates a holistic application security strategy – where we can use pre-production scanning information where we’re looking to vulnerabilities at the code level – AND PAIR this with live production attack data to make better decisions on where we need to spend time ruggedizing our application. In the end allowing security to be a tool used during the development process.
  • #26: Power Rules - A powerful platform with an intuitive user-interface to to define, monitor, and take action any application or API transaction, providing visibility into feature abuse and misuse, account takeover (ATO), bad bots, as well as basic functions like whitelisting, blacklisting and virtual patching. Power Rules are not signatures, and are not needed for OWASP attack coverage, which comes standard out of the box with Signal Sciences SmartParse without any rule configuring or tuning. Signal Sciences NLX – Signal Sciences Network Learning Exchange proactively looks at all malicious traffic across the network. NLX has the unique capability to recognize attack patterns to identify potential threats before they become malicious elsewhere in our customer network. This collective data provides great insight into all attacks that are happening to all customers. Having this collaborative information provides unique insight into attacks that are happening, and have happened across the world. SmartParse – a proprietary detection method designed to make instantaneous decisions in line to determine if there are malicious or anomalous payloads present. By evaluating the context of the request and how it would actually execute, we’re able to make highly accurate decisions. SmartParse is tested at scale with over 150 billion weekly production requests, requires no tuning or configuration, and virtually eliminates false positives. SmartParse is used in the detection of all Signals. When it comes to actually securing an application – as in identifying the bad actors and block them – nobody does it better than Signal Sciences. 95% of our customers have us deployed in full blocking mode. This is a result of our ability to deliver a more sophisticated and dynamic detection engine via SmartParse……but also by enabling business logic-based Power Rules and the Signal Sciences Network Learning Exchange which looks for suspicious events across our network and delivering that to our customers.
  • #27: Signal Sciences support your existing tech stack, and your future tech stack. 50% of our installs are on-prem apps – t’s not just a solution for cloud/DevOps but for your entire footprint – today and in the future. When we talk about Scale – we’re not just referring to our ability to scale dynamically with an application, but also the ability to scale across the entire web presence of an organization. Our flexibility from a deployment perspective allows us to scale from legacy applications all the way to the most current development frameworks. Whether it’s a webserver running IIS…..an application running in Node JS……a Pivotal Cloud Foundry workload…..a kubernetes container…….a Kong API Gateway serverless environment......or an application running is AWS…….we can protect it – all through a single pane of glass.
  • #28: Our approach is centered on delivering Active Protection Everywhere…..See, Secure, and Scale across – Any App, Any Attack, with integration into Any DevOps Toolchain. Signal Sciences can provide visibility and protection for any application regardless of where it sits and the underlying architecture – any cloud, container, Platform as a Service, or architecture. This level of support is unmatched by any other application security solution. Protection against OWASP Injection based attacks is just the tip of the iceberg – which by the way, we can provide right out of the box with ZERO tuning or customization. The real value that our customers express is our ability to also provide business logic protection – such as Application level DDoS, Brute Force Attacks, Account Takeover, and API misuse and abuse as an example. Lastly, being able to seamlessly integrate into any DevOps Toolchain means development teams can obtain information surrounding their applications via tools they already use during the development process.
  • #29: - We will
  • #33: We have seen how NGINX can replace/augment F5. Now let’s take a look at what other capabilities NGINX can offer beyond F5’s functionality,
  • #36: It provides following capabilities: - Simplifies configuration of load balancers at scale Enables a policy driven approach to configuration to ensure consistency and prevent misconfigurations Helps you Avoid performance issues by providing preemptive recommendations Helps you met your SLAs by enabling you to root cause and troubleshoot performance and security issues quickly
  • #37: NGINX Controller is a centralized monitoring and management platform for NGINX Plus. Easily manage multiple NGINX Plus instances from a single, beautiful interface. Uncover performance insights in real time with rich monitoring. Configure application delivery policies from a single point of control. NGINX Controller puts you in strategic command of your entire application.
  • #39: It provides following capabilities: - Simplifies configuration of load balancers at scale Enables a policy driven approach to configuration to ensure consistency and prevent misconfigurations Helps you Avoid performance issues by providing preemptive recommendations Helps you met your SLAs by enabling you to root cause and troubleshoot performance and security issues quickly
  • #40: NGINX Controller is a centralized monitoring and management platform for NGINX Plus. Easily manage multiple NGINX Plus instances from a single, beautiful interface. Uncover performance insights in real time with rich monitoring. Configure application delivery policies from a single point of control. NGINX Controller puts you in strategic command of your entire application.
  • #41: Signal Sciences is doing to the WAF market what next-gen AV and endpoint security solutions like Crowdstrike and Cylance did for the legacy AV/endpoint market – along with a similar architecture. SmartParse – a proprietary detection method designed to make instantaneous decisions in line to determine if there are malicious or anomalous payloads present. By evaluating the context of the request and how it would actually execute, we’re able to make highly accurate decisions. SmartParse is tested at scale with over 150 billion weekly production requests, requires no tuning or configuration, and virtually eliminates false positives. SmartParse is used in the detection of all attack Signals.
  • #42: Build Slide: (3 layered images) External Source: SANS Malicious IP List, Known TOR, GEO IP Lists, Bad Bot List Customer Sources: Custom Lists TOR = The Onion Router, used to obfuscate IP addresses to anonymize your source IP (what server you’re coming from) When traffic reaches the server, the module gets invoked and passes the request to the agent. The agent determines whether the request is malicious or anomalous. It responds back to the module to block or log the traffic based on the mode. All detection takes place at the agent level within your infrastructure. The agent collects meta data about the malicious requests it has processed and shares that metadata with the Cloud Engine. The Cloud Engine processes that metadata for the sole purpose of enhancing the agent. The output from the Cloud Engine is used by the agent locally to perform better detection and make more aggressive blocking decisions. In similar fashion to next gen AV products we perform detection locally but offload the computing needed enhance that detection with a cloud based analytics engine.
  • #44: - We will
  • #45: AppNexus is a technology company that provides trading solutions and powers marketplaces for Internet advertising. They operate the world’s largest independent marketplace for digital advertising and powerful enterprise technology for buyers and sellers of digital ads. AppNexus customers buy and sell ad impressions through a real-time bidding (RTB) application. As a web page loads, each available impression on the page triggers an HTTP retrieval to an AppNexus server, which hosts the ads. Each transaction takes mere seconds, but occurs billions of times every day. AppNexus’ worldwide data centers balance the load of incoming traffic based on network proximity to the client. AppNexus’ success and growth soon revealed problems with its F5 BIG-IP hardware load balancers. With more users being served and greater demand on the RTB application, performance and stability issues began to manifest. The hardware didn't perform up to promised specifications under real-world conditions, and AppNexus experienced high CPU usage and memory leaks. Critical security vulnerabilities required constant patching. F5 simply advised them them to spend more on additional hardware load balancers – specifically $3M extra. Replaced their entire F5 deployment with NGINX. We’re sustaining approximately 75,000 transactions per second through a single instance of NGINX Plus.”
  • #46: Choose your own quotes! “Almost an out-of-the-box solution for a complex footprint. The agent installation took about 10 min, the portal was created in 15 mins, we were seeing true alerts in less than 1hr.” - Enterprise Architect, Manufacturing Industry (Also looked at F5, Imperva) “Best WAF Technology I've Ever Worked With. The Signal Sciences WAF platform has been one of the most effective security technologies I've had the opportunity to work with. It was incredibly easy to implement, required no customization before moving to full blocking mode and does exactly what we need it to do with very little care and feeding. Their technical support is very responsive and always quick to answer a question, fix an issue or escalated to development. Documentation is excellent and their API first approach is incredibly helpful for integrating the platform into existing processes.” - IT, Services Industry “Signal Sciences has been the best WAF experience we’ve implemented: it was easy to see almost immediate results and how much better Signal Sciences was than our previous WAF. Signal Sciences was able to handle traffic that was otherwise unseen, and the configuration options allow us to tweak it perfectly for our environment. Plus, install has been super easy for all of our servers.”— Senior Information Security Analyst, Large Enterprise “Easy onboarding, simple deployment, effective service. Amazing support, amazing product. Signal Sciences WAF has found a permanent place in our environment. It has proven itself as an effective, practical security tool multiple times.” — Knowledge Specialist at Midsize Company “I’ve been really impressed with how Signal Sciences has made the team better developers. We easily have access to constant reinforcement of the data that the software provides — that we’re constantly under attack. Seeing it in a graph makes it real. When we’re making design decisions we now keep security at the forefront of our plans.”— CTO at Midsize Company
  • #47: - We will