Network Security Strategy for Visibility and Control

As company J expanded its cloud-based work environment with increased use of SaaS applications, the limitations of its existing network security architecture became clear. As HTTPS-encrypted traffic and CDN environments became more prevalent, it became harder to identify services and monitor user behavior, making existing policies less effective. As a result, company J needed to establish a network security framework centered on visibility into encrypted traffic and user behavior-based security controls.
This case study examines how Company K redesigned its network security architecture around three key pillars with AhnLab TrusGuard: securing visibility, enabling behavior-based control, and maintaining stability.
Securing Visibility Through SSL Inspection
AhnLab TrusGuard decrypts HTTPS traffic and analyzes request information, content, and traffic flows within encrypted sessions. This gives company J visibility into hidden application activity and data flows within SaaS applications.
Application-Based Behavior Control
The application control engine analyzes traffic decrypted by TrusGuard and identifies user actions based on URLs, headers, file types, and request methods.
For example, it can identify file uploads, email attachments, and external sharing attempts, then apply policies accordingly. This enables behavior-based security policies that go beyond simple access control.
Maintaining Service Stability Through SSL Exception Policies
SSL decryption can cause authentication errors or service disruptions in some applications. TrusGuard addresses this with exception policies that selectively exclude those services from decryption, helping maintain both security and service availability.
Download the PDF to learn more about Company K’s AhnLab TrusGuard implementation.
- AhnLab