Web application firewall (WAF)
A web application firewall (WAF) filters attacks such as SQL injection and cross-site scripting before they reach your application.
Limits of a classic firewall
A classic firewall only controls which ports are reachable. SQL injection, cross-site scripting, automated log-ins and bot traffic use normal web traffic and pass straight through. A WAF checks every request and blocks suspicious access.
Protective functions
protection against typical OWASP Top 10 attacks
rate limiting against brute force and scraping
blocking of known malicious bots and IP addresses
virtual patching of known vulnerabilities until the update is applied
No replacement for secure development
A WAF is one extra layer of protection. It does not replace secure development, regular updates or clean access rights.
Approach
Depending on the infrastructure, the WAF runs on the server or as an upstream CDN service. It is based on established rule sets such as the OWASP Core Rule Set.
New rules start in monitoring mode so that legitimate requests are not blocked by mistake. The WAF logs feed into our monitoring.