Web application firewall (WAF)
A web application firewall (WAF) filters attacks such as SQL injection and cross-site scripting before they reach your application.
Why a classic firewall is not enough
A WAF adds protection where a classic firewall stops, because attacks on websites arrive through normal web traffic. A classic firewall only controls which ports can be reached. SQL injection, cross-site scripting, automated log-in attempts and mass requests from bots pass straight through it.
A web application firewall (WAF) checks every request for such patterns and blocks suspicious access.
Protective functions
protection against typical attacks from the OWASP Top 10
limits on requests per time period against brute force and scraping
blocking of known malicious bots and IP addresses
virtual patching: short-term protection against known vulnerabilities until the update is applied
A WAF is particularly effective for log-in pages, forms and interfaces. That is where automated attacks most often try to guess credentials or inject malicious code.
What a WAF does not replace
A WAF is an additional layer of protection. It does not replace secure development, regular updates or clean access rights. It works as one part of a layered security strategy.
Approach
Depending on the infrastructure, we run a WAF on the server or use an upstream service from the CDN provider. It is based on established rule sets such as the OWASP Core Rule Set.
New rules start in monitoring mode. This shows whether legitimate requests would be blocked by mistake, for example forms, uploads or interfaces. Protection is switched on only after fine-tuning. The WAF logs feed into our monitoring.