Skip to content

Web application firewall (WAF)

A web application firewall (WAF) filters attacks such as SQL injection and cross-site scripting before they reach your application.

Limits of a classic firewall

A classic firewall only controls which ports are reachable. SQL injection, cross-site scripting, automated log-ins and bot traffic use normal web traffic and pass straight through. A WAF checks every request and blocks suspicious access.

Protective functions

  • protection against typical OWASP Top 10 attacks

  • rate limiting against brute force and scraping

  • blocking of known malicious bots and IP addresses

  • virtual patching of known vulnerabilities until the update is applied

No replacement for secure development

A WAF is one extra layer of protection. It does not replace secure development, regular updates or clean access rights.

Approach

Depending on the infrastructure, the WAF runs on the server or as an upstream CDN service. It is based on established rule sets such as the OWASP Core Rule Set.

New rules start in monitoring mode so that legitimate requests are not blocked by mistake. The WAF logs feed into our monitoring.

Project enquiry

Back to top