P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Security and edge

Outbound web filter (forward proxy): what it is and how it is attacked

Checks and records everything staff and servers send out to the internet.

Also known as

  • forward proxy
  • secure web gateway
  • SWG
  • web filter
  • web proxy

Typing any of them into the editor finds this object.

Why it matters on a security diagram

It is often the only place outbound traffic is recorded, which makes it the place data leaving is noticed. It also holds a signing certificate that every company machine has been told to trust.

How it gets attacked, and what reduces it

How it gets attacked

  • Traffic routed around it entirely
  • Blending in with ordinary web traffic so nothing looks unusual
  • The signing certificate it uses to open encrypted traffic, which every company machine already trusts

What reduces it

  • Route outbound traffic through it by policy, not by hoping
  • Protect its signing certificate as you would a domain controller, since every company machine already trusts it
  • Alert on traffic that leaves by any other path

Where it sits

Group
Security and edge · The things that sit in front of something else and check what is trying to reach it.
Whose side, by default
Ours · Belongs to the organisation the diagram is about.
Catalogue identifier
web-filter

Reviewed . CC BY 4.0.

Others in security and edge

The security and edge group lists all 11 of them side by side.

Outbound web filter on your own diagram

Open the editor, press N, and type forward proxy. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker