Application Delivery Controllers (ADCs): The Security Tool You Didnt Know You Needed

Application Delivery Controllers (ADCs): The Security Tool You Didnt Know You Needed

Application Delivery Controllers (ADCs): The Security Tool You Didnt Know You NeededDowntime for even a few minutes can have a major impact on businesses’ bottom line and image. Businesses suffering from server downtime are subject to potential loss in sales, profits, productivity and customer satisfaction. In fact, the U.S. per record cost of data breach averages $194, according to Ponemon Institute.

Another unfortunate result of network outages and downtime is severe data loss, forcing businesses to cope with the cost of recreating data and the cost of notifying users in the event their data is compromised. As customers rely on access to a business’ website for purchases, support, information and services, 100 percent connectivity, 24/7 is imperative to businesses’ customer satisfaction.

Hackers and other security attacks are a source of server downtime and have consequently become a major concern for businesses. Fortunately, there are several preventative measures businesses can take to secure and protect their network against hackers and network infrastructure attacks. For example, application delivery controllers (ADCs), which are used primarily for traffic management and to ensure optimal application performance, are also equipped with security features that protect against the most common types of network attacks, meaning that businesses can utilize tools they already have to protect against oncoming threats.

Protecting Against Hackers

Hackers are a serious security threat for business of all sizes. Hackers are generally exploiting the network to discover the identity of the network content servers. After the hacker physically identifies the servers, he begins to work on cracking the security screen. This type of unauthorized access to sensitive data has the potential to cause serious consequences to businesses.

Fortunately, ADCs are equipped with several security features to protect networks against this type of attach. ADCs enhanced security capabilities prevent hackers from obtaining IP addresses of the network content servers by utilizing the NAT (Network Address Translation). The NAT protects the real IP address of the server that holds outside users in a DMZ, protecting the server from potential harm from the hackers.Application Delivery Controllers (ADCs): The Security Tool You Didnt Know You Needed

Network Infrastructure Attacks

Network infrastructure attacks generate large volumes of traffic to overwhelm the network appliances. These types of attacks are typically a planned and well-synchronized massive generation of incoming traffic that is aimed at the edge devices in a businesses’ network infrastructure. Network infrastructure attacks will penetrate as deep into the network as possible, with razor sharp focus on the network content servers.

ADCs add a layer of protection to the network infrastructure by mitigating attack vectors and monitoring all incoming requests. IPS/IDS and basic firewall functionality ensure that malicious attempts are not passed through to application instances. ADCs lie between the Internet and the application environment, putting them in a prime position to perform these functions.

For a complete implementation that can not only scale and withstand attacks, geographic site load balancers work in conjunction with local application delivery controllers to intelligently distribute user application traffic across dispersed data centers. Real time site monitoring coupled with configurable business-rule driven traffic steering algorithms results in the optimal use of a global data center fabric. In the case of multi-tier applications where an administrator is alerted to server resources requesting other servers through the ADC, and one random server exhibits anomalous traffic patterns, the ADC can block access to the offending server and act as an additional layer of protection against DDoS attacks.

Another common window of vulnerability in terms of application security is Missing Function Access Level Control exploits (a top 10 OWASP web app security concern). When developers create web interfaces, they have to restrict which users can see various links, buttons, forms, and pages but graphic design layers on top of HTML in terms of the web page look and feel often hide the exposed URLs.

ADCs can restrict which hosts and users can access fronted resources, as well as dictate which directories can even successfully be accessed. For most deployments the only successful traffic flow will be one that traverses the ADC for the request and the response, which helps to mitigate the amount of attack vectors that malicious efforts proffer. Additionally, as a reverse proxy, ADCs terminate TCP traffic, acting as a basic firewall in the strictest sense and only allowing explicitly allowed connections to ever make it through to the application infrastructure.

ADCs: A Key Security Tool

ADCs, while usually relied upon to improve the scalability and performance of business-critical applications running on the network, also serve as a key tool against network attacks. By utilizing the security features of ADCs, businesses can protect their networks against hackers and network infrastructure attacks to avoid any downtime while making the most of existing IT tools.

About the Author

Atchison Frazer is the CMO at KEMP Technologies.

Featured

  • AI-Generated Code Poses Major Security Risks in Nearly Half of All Development Tasks

    Veracode, a provider of application risk management, recently unveiled its 2025 GenAI Code Security Report, revealing critical security flaws in AI-generated code. The study analyzed 80 curated coding tasks across more than 100 large language models (LLMs), revealing that while AI produces functional code, it introduces security vulnerabilities in 45 percent of cases. Read Now

  • Unlocking the Possibilities

    Security needs continue to evolve and end users are under pressure to address emerging risks and safety concerns. For many, that focus starts with upgrading perimeter openings and layering technologies—beginning at the door. Read Now

  • Freedom of Choice

    In today's security landscape, we are witnessing a fundamental transformation in how organizations manage digital evidence. Law enforcement agencies, campus security teams, and large facility operators face increasingly complex challenges with expanding video data, tightening budget constraints and inflexible systems that limit innovation. Read Now

  • Accelerating a Pathway

    There is a new trend touting the transformational qualities of AI’s ability to deliver actionable data and predictive analysis that in many instances, seems to be a bit of an overpromise. The reality is that very few solutions in the cyber-physical security (CPS) space live up to this high expectation with the one exception being the new generation of Physical Identity and Access Management (PIAM) software – herein recategorized as PIAM+. Read Now

  • Protecting Your Zones

    It is game day. You can feel the crowd’s energy. In the parking lot. At the gate. In the stadium. On the concourse. Fans are eager to party. Food and merchandise vendors ready themselves for the rush. Read Now

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.