Listing Thumbnail

    Reblaze - AWS WAF, DDOS, Bot Mitigation (SaaS Contract)

     Info
    Sold by: Reblaze 
    Reblaze is a cloud-based, fully managed website, web apps, and API security solution. An all-in-one platform that includes WAF, DDoS protection, Bot management, API security, anti-scraping, CDN, load balancing, real-time traffic control, and more.

    Overview

    Reblaze is an Enterprise web security solution purpose built for cloud native environment, providing fully managed protection for sites, web applications, services, and APIs. It is a unified web security solution for AWS, providing a next-gen WAF, DoS and DDoS protection, advanced Bot Management, API Security, scraping and data theft prevention, CDN, load balancing, and more.

    Reblaze deploys in a dedicated Virtual Private Cloud (VPC), geolocated immediately in front of the customer's network. Traffic is scrubbed as it passes through the VPC; hostile traffic is blocked, while legitimate users and customers have full access. (Latency is minimal: around 0.5 ms.)

    Reblaze runs natively on AWS Platform, extending and completing AWS's security features. Reblaze's next-generation threat detection converts AWS Security into an autonomous system that reacts immediately to every type of attack: Reblaze identifies hostile traffic, and AWS Security immediately blocks it at the edges. The solution is fully managed; customers enjoy the benefits of always-up-to-date web security with no effort required from their staff. Reblaze includes continual machine learning for accurate, adaptive threat recognition.

    Reblaze provides full real-time reporting in its UI. It also integrates with a wide variety of SIEM/SOC solutions, to support your existing workflows.

    Highlights

    • Web and API protection (WAF, DDOS, Bot Mitigation) purpose built for AWS, easily adapting to any topology and running in your VPC. Providing highest level of privacy
    • Advanced Bot management, stopping evasive bots. Advanced mobile SDK
    • Extended visibility of web traffic, dashboard with drill-down capabilities

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Reblaze - AWS WAF, DDOS, Bot Mitigation (SaaS Contract)

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (2)

     Info
    Dimension
    Description
    Cost/month
    Standard
    5 Websites/Apps, 1TB/month traffic, 100 Mil/month requests, 1 Region
    $5,440.00
    Advanced
    10 Websites/Apps, 2TB/month traffic, 200 Mil/month requests, 1 Region
    $7,440.00

    Vendor refund policy

    This product does not have a refund policy

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Reblaze offers several different support levels, starting from business support to a fully managed solution. Contact us to learn more. Support Portal: https://reblaze.zendesk.com/ , Email: support@reblaze.com , Phone: +1 (888) 615-5996, for regional offices please see:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Log Analysis
    Top
    100
    In IT Business Management

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    1 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Web Traffic Filtering
    Dedicated Virtual Private Cloud (VPC) deployment for traffic scrubbing and hostile traffic blocking
    Threat Detection
    Next-generation machine learning-based threat detection system with autonomous response capabilities
    Security Integration
    Native AWS platform integration with extended security features and immediate edge blocking
    Bot Management
    Advanced bot management with evasive bot stopping and mobile SDK protection
    Traffic Monitoring
    Real-time comprehensive traffic reporting with dashboard and drill-down capabilities
    Threat Detection
    Advanced AI and machine learning algorithms for real-time identification and blocking of cyber threats targeting APIs
    DDoS Mitigation
    Automated detection and prevention of distributed denial-of-service attacks without performance degradation
    Traffic Monitoring
    Real-time visibility and analysis of API traffic patterns, anomalies, and usage metrics across multiple deployment environments
    Machine Learning Defense
    Intelligent threat detection system capable of identifying zero-day exploits and preventing API abuse through adaptive learning mechanisms
    Security Coverage
    Comprehensive protection framework ensuring confidentiality, integrity, and availability of sensitive API data across cloud, hybrid, and on-premise infrastructures
    Bot Traffic Detection
    Advanced analysis of incoming web requests to identify and block malicious bot activities
    Threat Pattern Recognition
    Comprehensive protection against vulnerability scanners, web scrapers, DDoS tools, and forum spam tools
    Security Rule Management
    Dynamically updated rulesets written and maintained by specialized security experts
    Web Request Filtering
    Automated blocking mechanism for identifying and preventing malicious automated traffic
    Threat Behavior Analysis
    Systematic evaluation of incoming web requests to detect and mitigate potential automated attack patterns

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    1 AWS reviews
    |
    1 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Pablo Frejlich

    Exceptional resilience and protection well-suited for medium to large businesses

    Reviewed on Jul 17, 2023
    Review from a verified AWS customer
    ">

    What is our primary use case?

    All of the organizations where I implemented this product had a primary objective to safeguard the platform against undesirable traffic, including protection against DDoS attacks, filtering out phishing attempts, preventing SQL injection, and other types of intrusions.

    What is most valuable?

    The most significant impact came from the implementation of bot filtering and defenses against SQL injection and script injection in general. It stands out as the primary focus because, in contrast to DDoS attacks which, while devastating, are relatively infrequent, the continuous scanning of ports and persistent attempts to gain unauthorized access to the platform happen daily. This is where the solution excelled, offering finely tuned filtering capabilities for specific types of traffic and country-specific IP ranges. 

    What needs improvement?

    There is a potential improvement regarding simplifying the complexity of rule creation. It would be beneficial if it had a workflow or a feature that could fine-tune settings based on high-level requirements. For example, setting up traffic filters for specific regions or closing certain ports without the need to manually translate these into rules.

    For how long have I used the solution?

    I have been working with it for eight years.

    What do I think about the stability of the solution?

    We haven't encountered any failures. It is a highly resilient product that can handle significantly larger workloads and high volumes of traffic with ease.

    What do I think about the scalability of the solution?

    I witnessed the level of protection they provide, especially during a digital attack that spanned across entire continents and was directed at us. It became evident just how intelligently the product is engineered. It effectively scaled to shield our platform while still allowing legitimate traffic to reach our servers. From that perspective, the scalability of the product is truly exceptional.

    How are customer service and support?

    My overall experience was highly satisfying. In the particular incident when we faced a major attack on our platform, which happened several years ago, we spent several hours on the phone with them until they effectively neutralized the attack and filtered out all the traffic originating from a very specific geographic location. Also, in every other instance where we needed support, whether it was for configuring roles or for immediate assistance during an attack, their response has consistently been rapid and highly effective. 

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup process is quite straightforward. Its complexity largely depends on the intricacies of your platform. If your platform spans multiple sites across the globe, requiring configuration of multiple instances and traffic routing, it can become more intricate. From our experience, even in companies with extensive platforms, the configuration process remains relatively simple. Once the instances are spun up and the initial configurations are in place, you can use their console application to set up your site or sites for traffic management. This involves configuring the sites and uploading SSL certificates. Even for those not well-versed in the intricacies of networking layers and rules, the out-of-the-box configurations already provide solid protection.

    What about the implementation team?


    What's my experience with pricing, setup cost, and licensing?

    We found the cost to be a bit on the higher side, starting at approximately three to four thousand dollars for a small configuration. It is worth mentioning that these figures might not be current. Additionally, they are open to negotiations, and we were able to secure a substantial discount. They even offered extended trial periods lasting three, four, or even six months, essentially providing the product for free during that time. This flexibility in pricing certainly works in their favor and contributes to the appeal of considering them for the long term.

    What other advice do I have?

    The suitability of this product depends on the specific circumstances of the business. If you're a small business owner running a simple operation I wouldn't recommend opting for it, as it might be a tad pricey for an entry-level scenario. To the best of my knowledge, they didn't offer a free tier the last time I checked, so the initial cost for even the most basic configuration might be a bit steep for a small-scale setup. There are alternative products available, some of which offer free or very affordable options. These alternatives often come with reduced functionality compared to what this product offers, but they can serve as cost-effective replacements. For instance, Amazon provides a basic Web Application Firewall (WAF) as part of their services, which, while not as robust as what this product offers, provides a level of protection for your online services. For medium to large businesses seeking robust support and a comprehensive product to safeguard their platform, this product is a solid choice as it generally offers above-average satisfaction and a comprehensive range of features that can effectively protect your online assets. It ultimately depends on your unique needs. I would rate it nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Shivendra S.

    Offers flexibility with a kill switch for bypassing Reblaze if needed and provides a reliable Layer 7 defense against attacks

    Reviewed on Jun 27, 2023
    Review provided by PeerSpot
    ">

    What is our primary use case?

    We are using it for Web Application Firewall, Layer 7 Firewall. It protects us from denial-of-service attacks, cross-site scripting, as well as injection attacks. 

    It also has a good bot management system that informs us in advance about IP addresses that are not good for us, so we do not cater to their requests. It's like a Layer 7 defense for us.

    What is most valuable?

    The best thing about Reblaze, for us, is that it has been a game changer because previously, we were using Google's Web Application Firewall, but it wasn't up to the mark. 

    First things first, it's pretty easy to look at the current state of affairs when it comes to the attack scenario and the attack surface of our website and applications. 

    Second, the ease of writing rules is pretty standard because the Reblaze GUI helps us in creating and testing tools and even changing their hierarchy. For example, if we want to test a particular payload for a development service first and then for a SQL injection, we can easily change the priority of the rules in Reblaze. 

    Third, the support we have received from the staff has been really, really good. I do not wish to name them, but yes, there are a few people who have supported us a lot because they have a Slack channel and dedicated personnel within that channel. If anything goes wrong and if Reblaze is the cause, they troubleshoot for us. 

    So not just the technical bells and whistles within Reblaze, but the support from the staff has been really, really good.

    What needs improvement?

    There is still some room for improvement when it comes to bot management from Reblaze because they are relatively new compared to other vendors in the town. AWS WAF, the Web Application Firewall from AWS, has a vast database of bad IP addresses due to its long-standing presence in this business. Reblaze, being a new entrant, is still building its database of bad IP addresses and malicious systems. 

    So, Reblaze needs to work on that aspect. But other than that, I don't think scaling Reblaze has been an issue. There were some initial glitches, but they were all sorted out. So currently, I would say that the bot management and the database are areas they should focus on for further improvement.

    For how long have I used the solution?

    We have been using Reblaze for a year now. 

    We did POCs in May last year, and we onboarded Reblaze starting in July 2022. So it's almost a year now. It's a cloud-based system, because it's a SaaS solution. We have pointed our DNS to Reblaze, and Reblaze takes care of vetting the traffic and sending it back to us. 

    What do I think about the stability of the solution?

    Reblaze is quite stable. During the initial phase, there were a few instances where the system went down, but that was mainly because both Reblaze and we were still learning about our environment, their support, and scalability. 

    However, once that phase was behind us, there haven't been any major issues due to Reblaze. We also have a kill switch as a backup. If we notice the load increasing and Reblaze may struggle to handle it, we can bypass Reblaze and direct traffic straight to us. Though we haven't used the kill switch yet, we have had no issues so far. It's been a year, and we plan to renew our contract with them once the current license expires. Overall, we are happy with the product.

    What do I think about the scalability of the solution?

    In our company, I manage the security team, which consists of eight people. Since we have a flat organization where everyone is involved in various tasks, all eight team members are using Reblaze. So currently, nine people are using Reblaze in our company.

    How are customer service and support?

    In terms of support only, I would rate them around eight out of ten. They are doing well. The reason I deducted two points is that they don't provide 24/7 support yet, and most of their team members are based in Israel, where Reblaze originates from. This creates a time gap, and we had to communicate with them asynchronously. We used Slack as a common group to exchange messages, and they would respond accordingly. 

    Initially, we had calls scheduled, sometimes even on weekends because one of their working days falls on Sunday. So we had calls on Sundays as well when they were available. These factors influenced my rating of eight out of ten, considering the time aspect.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    My company chose Reblaze over AWS because we are on the Google Cloud Platform (GCP), not AWS. We cannot use AWS unless we migrate everything to AWS, which is not feasible for us.

    We opted for Reblaze since it was compatible with the Google Cloud Platform.

    How was the initial setup?

    The initial setup was pretty straightforward, to be honest. We had a test environment where we conducted the Proof of Concept (POC). We shared our DNS IP addresses, and the resolution IP addresses of our systems with the Reblaze team. This directed all traffic to Reblaze first, which performed traffic scanning before allowing it to reach our network. 

    So we simply had to change the IP addresses. We did need to purchase some certificates because most of our traffic was encrypted, and Reblaze acted as a man-in-the-middle. We obtained the certificates from LicenseScript, which is free for the test environment. After that, everything started working smoothly.

    What was our ROI?

    Reblaze is worth the money. You will see a hundred percent return on investment. We were using Google's web application firewall, but it wasn't effective at all. We had no other option but to look for alternatives, and Reblaze has proven to be a good choice for us.

    What's my experience with pricing, setup cost, and licensing?

    We negotiated a deal. So, we were able to secure a significant discount of around 40% off the quoted price. However, the precise figures remain confidential.

    What other advice do I have?

    My first question would be if you are currently using any Web Application Firewall (WAF). 

    Let's say, for example, you are using AWS as well. If you are already using AWS, I would advise against switching to Reblaze. Not because Reblaze is not good but because AWS WAF provides more comprehensive protection for your assets. Reblaze is catching up, and they are nearly there, but AWS WAF is currently more advanced. However, if you are using Google's WAF or any other vendor, then I would recommend considering Reblaze as the second-best option. 

    In my opinion, AWS is the number one choice, and Reblaze ranks as the second-best among all the vendors I have tested so far. Reblaze stands out due to its ease of use and the flexibility it offers in customizing rule sets.

    Ten being the best, I would rate Reblaze somewhere between seven and a half and eight. They are still evolving as a product. I have previous experience using AWS WAF in another company, and I know how good it is. If you are in an AWS environment, I would recommend AWS WAF. 

    However, if you are not in an AWS environment or have the freedom to choose, Reblaze is a viable option. You cannot use AWS WAF on platforms like GCP or Azure, for example. That's why I say Reblaze is still developing. Their bot management capabilities are not yet at the same level, and their support is not fully refined either. We had to schedule calls on Sundays and sometimes late at night. But when it comes to value for money, Reblaze is a great choice. It is more cost-effective than AWS WAF and performs better than the other options available to us.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Google
    View all reviews