Rufen Sie uns direkt an:

0800 - BITRIX-D
(0800 - 248749-3)
Kostenlos für Deutschland

+7 (9632) 909 337
International

Kostenloses Online-Webinar

Bleiben Sie informiert:

Wir bei Twitter
Wir bei Facebook
YouTube-Channel
Unser RSS-Feed
Bitrix Site Manager v11.0

Security

Bitrix Site Manager provides maximum protection from thousands of threats in the Internet. Every day your website could be attacked many times and it may harm your information.

Why should I protect my website?

  • 82% of websites have had at least one security issue in 2008;
  • E-commerce databases are most likely to be attacked by hackers;
  • Security breaches cost USD 90 USD to USD 305 per lost record;
  • More than 90,000 calls to top 20 US Banks after each phishing attack;
  • More than 200 new hack techniques have appeared during the last 3 years;
  • Unavoidable damage to the enterprise business image due to data leak.


Proactive Protection

Solutions Provided by Proactive Protection

The Proactive Protection system is really an essential supplement to the Bitrix standard security policy. More importantly, up now it comes integrated and is being offered within the Bitrix software products with no extra charges applied! The Proactive Protection includes a great number of technically advanced security mechanisms for web applications. Multiple security levels introduced within the Proactive Protection system eneble you to detect and combat almost all known hack techniques making your internet projects unsusceptible to most present-day web threats.

Sergey Rizhikov, Bitrix, Inc. CEO

"Bitrix Site Manager is a highly secure business tool. Your personal data will always be safe and protected because Bitrix Site Manager uses its brand new security mechanism – Proactive Protection. It has already been tested on thousands of web sites."

-Sergey Rizhikov, CEO Bitrix, Ltd.


The module offers the following protection features:
Control panel to set the protection level
Proactive filter (Web Application FireWall)
One Time Password technology
Protection of authorized sessions
Activity control
Phishing protection
Intrusion log
IP based Control Panel protection
Stop lists
Script integrity control




Industry Vulnerability Chart
Percentage of websites susseptible to security vulnerability, sorted by industry. 
 
Source: White Hat Security, "Website Security Statistics" by Trey Ford.



More than six hundred Russian hackers have been trying to evade the Bitrix brand new Proactive Protection system as part of the "Bitrix Real-Time Hack Competition". The crash test was organized during the "Chaos Constructions CC9 Festival" in the end of August 2009. During the competition hours there have been registered and repulsed more than 25.000 attacks by the Proactive Protection security mechanism, proving its superb reliability. Read more...

Learn more in our Bitrix Software Security presentation! Download now in .ppt or .zip.



Features
Control panel to set the protection level
Proactive filter (Web Application FireWall)
One Time Password technology
Protection of authorized sessions
Activity control
Phishing protection
Intrusion log
IP based Control Panel protection
Stop lists
Script integrity control

Proactive filter (Web Application FireWall)


Web Application Firewal protects the system from most known web attacks. The filter recognizes dangerous threats in the incoming requests and blocks intrusions. Proactive Filter is the most effective way to guard against possible security defects in the web project implementation (XSS, SQL Injection, PHP Including etc.). The filter analyzes entirely all data received from visitors in variables and cookies.

* Note that some harmless actions a visitor may perform can be suspicious and cause the filter to react.


  • protects from most known web attacks;
  • screens a web application from the most importunate attacks;
  • filter exclusion list (with wildcards);
  • recognizes most dangerous threats;
  • blocks site intrusions;
  • protects from possible security errors;
  • keeps the attack log;
  • informs an administrator about intrusions;
  • configurable options of the firewall reaction to intrusion attempts:
    • make data safe;
    • wipe unsafe data;
    • temporarily add the attacker’s IP address to the stop list.
  • latest updates.


Control panel to set the protection level


Any Bitrix Site Manager based web site is always preconfigured for the basic protection level. However, you can improve the site security significantly by selecting one of the Proactive Protection module presets: standard, high or highest. The system will show you hints about any parameter you may need to configure.


  • basic level – assigned to all web projects running without the Proactive Protection module;

  • standard level – enables the most common proactive protection features:
    • the proactive filter (site wide);
    • weekly intrusion log;
    • activity control;
    • high security level for administrators;
    • CAPTCHA protected registration procedure;
    • error logging (errors only).

  • high level is the recommended security level which can be applied to any projects conforming the standard level requirements. This level adds the following features:
    • Kernel module event logging;
    • Control Panel protection;
    • storing sessions in the database;
    • session identifier change.

  • highest level includes special protection tools essential for sites keeping confidential user information (web shops etc.). This level is empowered with the following functions:
    • one time passwords;
    • control script integrity verification.


Intrusion log


The intrusion log registers all events occurring in the system including uncommon, suspicious and malicious events. The log is updated in real time so you can view the events as soon as they have been registered. This feature enables you to discover attacks and intrusion attempts while they occur, so you can riposte immediately and even prevent attacks.



  • immediately registers all system events;
  • logs attacks detected by the proactive filter:
    • SQL injection;
    • XSS attack;
    • PHP including.

  • filter for malicious events;
  • view and analyze events in real time to prevent attacks in future;
  • immediate reaction to malicious events.


One-time passwords


The Proactive Protection module supports one-time passwords for any site users. These passwords are especially recommended to be used by the site administrators since they significantly improve security of the “Administrators” user group.

The concept of one-time passwords empowers the standard authorization scheme and significantly reinforces the web project security. The one-time password system requires a physical hardware token (device) (e.g., Aladdin eToken PASS) or special OTP software.

This technology gives you confidence that only a user to whom a token was issued can authorize on the site. Password theft or interception is absolutely senseless because a password can be used only once. A token is a hardware physical device that generates unique passwords only when a token button is being clicked. Effectively, it means that a token owner is unable to tell the password to third party to allow them authorize as well.



  • empowers web project security;
  • hardware tokens;
  • software OTP;
  • extended OTP authentication: a user must append a one-time password to their normal password;
  • authorization using a login and a compound password;
  • uses two OTP generated consequently by a token;
  • synchronizes the token and server generator counters whenever synchronization is lost.


File integrity control


File integrity control helps an administrator reveal maliciously or mistakenly modified system files. Anytime you can check the integrity of the system kernel, other system or public files.



  • tracks file system changes;
  • verifies kernel integrity;
  • verifies system area integrity;
  • verifies public files integrity.



Verification of the file integrity control script


Before checking the system integrity, the file integrity control script has to be verified for possible changes. When running the script for the first time, enter a desired password containing at least 10 characters (letters and digits), and any keyword (other than the password), and click “Set New Key”.



  • verifies the file integrity control script for changes;
  • protects the script using the keyword and password pair.


Control Panel protection


This type of protection strictly regulates secure networks from which the users are allowed to access Control Panel. All you nave to do is specify the legal IP addresses (or a range). No need to worry about not adding yourself to this list: the system will check your IP automatically.

What effect would this protection produce? Any XSS/CSS attacks become ineffective, interception of authorization data – absolute useless.



  • restricts access to Control Panel from any IP’s except those on the white list;
  • recognizes the user’s IP address automatically;
  • a user can manually supply the allowed IP addresses and the address ranges.


Session protection


Most web attacks are purposed to steal the authorized user session data. Enabling the session protection makes session hijacking senseless. Furthermore, speaking of an administrator’s authorized session, we can say that guarding it using session protection is one of the most essential security efforts.

In addition to the conventional session protection options existing in the user group parameters, the session protection mechanism includes some special, even unique features.

Storing session data in the module database prevents data from being stolen by running scripts on other virtual servers which eliminates virtual hosting configuration errors, bad temporary folder permission settings and other operating system related problems. It also reduces file system stress by offloading operations to the database server.



  • various protection methods:
    • limited session lifetime (minutes);
    • recurring session ID relay;
    • network mask to associate a session with a specific IP;
    • storing session data in the module database.

  • eliminates virtual hosting and OS configuration errors;
  • eliminates bad temporary folder permission settings;
  • reduces file system stress;
  • makes session ID hijacking senseless.


Activity control


Activity Control allows to protect the system from profusely active visitors, obtrusive bots, some DDoS attacks, and prevent password brute force attempts. You can set the maximum allowed activity for your site (e.g. number of requests per second a user can perform).

User activity control is build around the Web Analytics module mechanisms and requires this module to be installed.



  • protects from profusely active users;
  • protects from bots and DDoS attacks;
  • prevents password brute force attempts;
  • allows to set the maximum possible visitor (human) activity quota;
  • registers the excess of activity rate in the intrusion log;
  • blocks visitors exceeding the activity quota;
  • shows a special information page to a blocked visitor.


Stop list


The stop list contains parameters used to restrict access to a site and possibly redirect to a specified page. Any visitor matching the stop list criteria (e.g. an IP address), will be blocked.



  • redirects visitors matching the stop list entries;
  • blocks visitors by their IP addresses;
  • stop list entry management;
  • collects the statistics on visitors matching the stop list criteria;
  • allows to specify the ban duration for users, IP address, network masks, UserAgent’s and the referrer links;
  • shows customizable message to a blocked visitor.


Phishing Protection


Phishing - is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.



Two methods exist to prevent redirect phishing:
  • Detect malicious redirects by the lack of the referring page in the HTTP header
  • Sign links with a digital signature and verify it upon redirect attempt
The following can be used as protection:
  • Show redirection warning to a visitor
  • Unconditionally redirect a visitor to a surely safe site
Recommended for the high security level.

Certificates

Certificates

Bitrix company practices permanent audit and testing of the system protection mechanisms. In order to make these tests unbiased and objective, Bitrix company recruits third-party expert companies for unprejudiced audit in addition to tests performed internally, by the Bitrix engineers. The certificates obtained from the security audit companies confirm the quality of the protection mechanisms and ensure their conformance to information security requirements.

Positive Technologies Certificate

"Protected Web Application"
(Bitrix Intranet Portal 8)

The certificate is issued by Positive Technologies company which has performed the audit of the new security features in Bitrix Intranet Portal. The built-in security fully meet the requirements of Web Application Firewall Evaluation Criteria as established by Web Application Security Consortium.

The implementation quality of the Bitrix Intranet Portal protection mechanisms give users confidence not only in the system kernel reliability, but also in any solution developed on this platform including add-ons and modifications done by the authorized Bitrix partners.

Partner Program
Free Online Training
Support