Skip to main content

What is SHIELD Web?

RBI Solutions for Protecting Web Services

SHIELD Web is a web security solution based on RBI (Remote Browser Isolation).

  • It is a security solution that fundamentally blocks attacks through WebAPI tampering and does not allow vulnerability scanning through streaming-based RBI technology.
  • Server-side rendering executes all web content in an isolated environment, delivering only safe screens to the user.
  • To protect web services that are outdated or have vulnerabilities, modifications to the web service are not necessary.
  • It can be applied on the same day just by changing the DNS, and there is no need to modify the existing web service code.
  • By moving away from the existing 'detection and blocking' method, it structurally isolates the attacker from the web server, thereby eliminating the attack surface itself.

SHIELD Web Configuration Diagram

구성도


Core Protection Mechanism

  • Users receive the screen only through SHIELD Web without directly accessing the actual web server.
  • All web content (HTML, CSS, JavaScript, API calls) is executed only in a remote browser isolation environment.
  • The attacker cannot access the original source code, API structure, or parameters.
  • Access to the actual web server is only allowed through the SHIELD Web service, blocking direct external access.
  • Completely hides infrastructure information such as the web server's IP, OS information, and middleware environment from external sources.

Core Values

Complete Web Isolation

  • Run all web content in a remote browser isolation environment
  • All web sessions run in independent virtual containers.
  • The user receives only the rendered screen (pixel stream)

Web Vulnerability Improvement

  • Fundamentally blocking attacks for vulnerability scanning
  • Minimize External Exposure Entry Points
  • Proactive Defense Against Zero-Day Vulnerabilities
  • Can be used as a supplementary control measure for 21 items of web vulnerabilities in the National Intelligence Service.

WebAPI Protection

  • Blocking attacks through API tampering by not exposing the WebAPI structure
  • Parameter Manipulation and Unauthorized Access Prevention

Attack Surface Hiding (Invisible Infrastructure)

  • Web server IP, OS, middleware information cannot be identified externally.
  • Structural elimination of the penetration possibility of targeted attacks such as APT

Easy application and cost reduction

  • Immediate application only with DNS changes, firewall settings, and certificate distribution.
  • No need to modify existing web service code
  • Minimize service installation time and management burden through the SaaS-based SHIELD Web service.
  • Cloud Auto Scaling Support
  • Minimizing the development and management costs of web services that need improvement

Target Application

Public Institutions and Citizen Services

  • Public institutions that must undergo regular security assessments by the National Intelligence Service
  • Public services and government agency websites accessed by unspecified large numbers of people
  • Institutions Struggling with Practical Improvements After ASM Implementation

Finance · Defense Industry · National Defense

  • Financial institutions required to comply with electronic financial supervision regulations
  • Defense and military institutions exposed to advanced targeting attacks such as APT
  • Institutions operating special OS and legacy systems that are no longer patched

Aging Web Service

  • System where source code improvement is difficult due to the termination of the contract with the outsourcing development company
  • Services that cannot be redeveloped due to budget constraints
  • Legacy technology stack (ASP, JSP, PHP, etc.) makes it difficult to onboard new developers.
  • System with insufficient technology transfer due to the departure of the person in charge

Services with a large attack surface

  • Web services that require blocking attacks through WebAPI tampering
  • Systems with vulnerabilities continuously found in regular security checks

Introduction Effect

Strengthening Security

  • Blocking Exposure of Web Vulnerabilities
  • Block unauthorized access to the API, parameter manipulation, and attempts to bypass permissions.
  • Establishing a proactive defense system against zero-day vulnerabilities
  • Improving overall security level by minimizing attack surface
  • National Intelligence Service Web Vulnerability 21 Items Remediation Control Achievement

Cost Reduction

  • Cost Reduction Effects in Web Redevelopment
  • No additional hardware equipment required
  • No initial investment burden with a monthly subscription model.

Quick Application

  • Zero Downtime Deployment Without Service Interruption
  • Immediate protection effect occurs with just DNS changes.

Getting Started