Identify and implement a solution that would provide safe Web Browsing protection from malicious and compromised websites for users of the Company’s flagship Mobile Security security offering. Additionally, provide parental controls web filtering to enable users to block access to porn and other websites with inappropriate content.
Profile:
Leading Mobile Security security vendor with over 5 million users (“customer”)
Industry:
Mobile Security
Deployment Requirement:
Cloud-based implementation with zero-hour malicious website protection, combined with fast query performance
“We required a solution that provided zero-hour or quicker detection and protection for our users from malicious websites, particularly websites targeting mobile users to help differentiate our Mobile Security security offering, as well as the ability to scale to support our rapid growth.”
– Vice President of Technical Services
The Problem:
The customer was looking for ways to differentiate its mobile security offering by adding Web browsing protection against malicious and compromised websites, as well as the ability to provide web filtering/blocking for porn and other websites with objectionable or sensitive content. As the customer’s user base expanded into a number of international markets, there was also a need to provide support for a number of major languages in its key European, Asian and America’s markets. Additionally, the customer was looking for a solution that provided zero-minute malicious protection for mobile-oriented websites with a cloud-based deployment option and a pricing structure that mirrored their business model.
With the increasing amount of malware and web threats targeting mobile users, the customer identified the need for significantly boosting protection for its users from malware and web-based threats targeting Android and iPhone devices by mobile apps and malicious websites.
The customer identified a number of objectives to provide a safer Web experience for its users:
Zero-minute malicious website protection – the primary objective was to provide up-to-the-minute protection against malicious, phishing, and compromised websites, particularly those threats targeting mobile Mobile Security users, including sites hosting spyware, malware, botnets, phishing, fraud and other exploits. | |||
Web filtering – an additional objective was to provide a web filtering offering, positioned as a parental controls service, that enabled blocking of porn, sex, violence and other objectionable or sensitive content, as well as the ability to block streaming video, social networking and other high bandwidth-intensive websites. | |||
International language support – due to the customer’s tremendous success and growth in international markets, coverage and dynamic, auto-categorization support of websites was required for the major languages in the Asian, European and Americas markets. | |||
Cloud deployment with fast URL query performance – the customer required a cloud-based deployment with less than 100 millisecond URL query look-up performance for its users across its international markets, with a small cache of frequently/recently-queried URLs maintained on the Mobile Security to further optimize performance. | |||
Scalability – the customer required a solution that could accommodate significant numbers of users in the initial launch, as well as scale to support the rapid growth projected by the customer for new users and higher adoption rates. | |||
Flexible pricing model – the customer required a pricing structure that mirrored its business model for its user pricing across the various international markets for both its basic offering and premium offerings. | |||
With these objectives and requirements in mind, the customer identified the need for a partner that could provide the technical solution, as well as expertise and a successful track record in the mobile marketplace.
“We recognized that a successful relationship would require a partner that could not only address our technical requirements, but who was equally committed to the business relationship and could provide us with the confidence we needed that they would be a responsive and flexible business partner in the mid- and long-term as well. We were breaking new ground with this offering and bringing a completely new service to the market and we needed a partner who was up for the challenge.”
– Vice President of Business Development
The Evaluation:
The customer conducted an initial high-level evaluation of the coverage and protection of several URL databases before identifying zvelo’s URL classification services for a comprehensive evaluation of the malicious coverage, zero-hour malicious detection, performance, dynamic web content categorization, miscategorized response handling and time-frames, international language support and several other criteria.
The evaluation criteria included:
Malicious Detection and Protection – an evaluation of zvelo’s coverage and detection abilities of malicious websites, particularly for new mobile/Mobile Security-oriented sites, was performed, using a range of proprietary and third-party feeds and URLs. Specific tests were also performed that evaluated the speed at which zvelo detected new malicious websites, as well as the speed at which zvelo detected that previously compromised websites had been cleaned or removed. | |||
Coverage – an evaluation of the zveloDB™ compared with the Alexa™ global top 100,000 list was conducted. Additionally, a coverage test was conducted for specific Asian, European and Latin American countries, in which a comparison of the Alexa top 25,000 list for these markets was performed. | |||
Accuracy – an evaluation of zveloDB’s accuracy was conducted, with an in-depth analysis of over 5,000 URLs collected from actual user traffic. | |||
Performance – an evaluation of the URL query performance for the zveloNET cloud was conducted for users in Asia, Europe and Americas to ensure satisfactory response times. | |||
Response time – an evaluation of zvelo’s ability and timeliness for handling miscategorized URLs was conducted by submitting miscategorized (aka “false positive”) URLs to zvelo and measuring the time it took zvelo to research and correct a miscategorized URL, as well as the support for an automated user submission process for miscats. | |||
Category Mapping for Parental Controls – the customer evaluated zvelo’s ability to provide the required “parental controls” category set by testing a range of URLs for proper category responses. | |||
“We really put zvelo and the zveloDB through its paces in the testing. It was critical that zveloDB have the ability to quickly detect new malicious and compromised websites, as well as the ability to identify when these websites were no longer hosting malware. These were key points to our business model and zvelo really stood up to the test. They have been extremely responsive throughout the entire process and we couldn’t be happier with a business partner.”
– Chief Operating Officer
Following the extensive evaluation, the customer and zvelo agreed to a partnership for the integration and deployment of the zveloDB offering to provide protection against malicious and compromised websites, as well as the underlying database and URL classification services for the customer’s parental controls offering. The customer’s implementation included real-time lookups which provided coverage and automated categorization and malicious detection of new ActiveWeb* sites visited by the collective community of all of users of zvelo’s customers.
The Customer’s Mobile Security Security Offering in Action:
The customer introduced the feature to provide browsing security to its Mobile Security security users and immediately saw a rapid adoption rate across its markets, as well as an increase in users upgrading to premium service packages for the parental controls offering. The heightened awareness of threats posed by malicious websites, mobile Apps and headlines of Android and iPhone attacks are also adding to the increased demand and adoption of the customer’s offerings.
Upon enabling the new features or services, the URLs being accessed by any of the customer’s users are queried by zvelo. If the URL is identified as one of several malicious or compromised categories, the user is blocked from accessing the site. If the URL is identified as being in a category other than malicious, the user’s access to the site is allowed or blocked based on the parental controls filtering policies.
Finally, if the URL is a new, previously uncategorized website, (e.g. www.newwebsite.com), and the URL is not found in the above-mentioned query process, the URL is immediately processed by the zvelo’s real-time Auto-categorization systems to determine the appropriate category (up to 5 categories) and to identify if the website is infected, compromised or contains any type of threat. The www.newwebsite.com URL and its categories are then added to the zveloDB and available for any subsequent queries for the community of users across all of zvelo’s customers.
zvelo’s ability to harness the collective web activity of all of the users of it’s customers provides the basis for the extremely high coverage of the ActiveWeb* and malicious websites. Each additional user increases the breadth of ActiveWeb sites visited and categorized, thereby further increasing the coverage and malicious website detection for all of the collective users.
Ease of Integration, Fast Performance & Scalability:
A key requirement for the customer included ease of integration of the zveloDB, as well as very fast URL query performance. With the zvelo cloud implementation option, the customer simply needed to integrate the lightweight API into its mobile security security offering. zvelo’s global network of fully load-balanced and redundant data centers routes URL queries
to the data center which provides the fastest query performance, ensuring that URL queries to the zveloNET cloud are consistently performed in 50-80 milliseconds or less. Additionally, the customer required the ability to add millions of users at the time of the launch and to support rapid growth as new users were added. With zvelo’s virtualized environment, zvelo was able to quickly scale the capacity to support the initial launch and significant ongoing growth.
“The zveloNET cloud API was simple and very easy to implement. It provides the flexibility and performance we need for users across all of our target markets. And zvelo has surpassed our expectations for supporting our very rapid rollout and ramp of users. As our user base and adoption rate for the web protection services has increased, we have continued to experience excellent URL query performance.”
– Vice President of Technical Services, Customer
Benefits of zvelo:
zvelo’s coverage of 99.9% of the ActiveWeb, in addition to real-time auto-categorization of new websites, provided excellent accuracy for the customer’s mobile security users. And, while zvelo’s malicious website detection capabilities provided zero-hour (and faster) protection against threats posed to mobile users by mobile apps, malicious websites and other web-based threats, the speed at which the customer was able to integrate the zveloNET API allowed for an extensive testing period.
“zvelo has been an excellent partner – with the right technology at the right time, supported by a corporate culture committed to the success of its partners.”
– Vice President of Business Development
The Results:
The customer experienced immediate success for its Mobile Security web protection and filtering services, across all of its international markets.
*ActiveWeb – those websites visited by actual users.