Web Application Firewall (WAF)
A security control that inspects HTTP and HTTPS traffic between clients and a web application or API, blocking requests that match attack patterns such as SQL injection, cross-site scripting or abusive bot activity.
A WAF operates at the application layer, typically as a reverse proxy, a cloud or CDN service, or a module in a web server or load balancer. It evaluates requests against rule sets covering known attack signatures, protocol anomalies, rate limits and IP reputation, and can block, log or challenge suspicious traffic. The OWASP Core Rule Set is a widely used open-source rule set that works with engines such as ModSecurity.
Organisations deploy WAFs to protect internet-facing applications and APIs, to apply temporary virtual patches while a vulnerability is fixed in code, and to mitigate application-layer DDoS and bot abuse. PCI DSS version 4.0 requires public-facing web applications to be protected by an automated technical solution that continually detects and prevents web-based attacks, a role WAFs commonly fill.
A WAF is a compensating layer, not a substitute for secure code. Rules need tuning to the application to avoid blocking legitimate users or missing attacks, and attackers use encoding tricks to evade signatures, so many deployments start in detection-only mode before blocking. WAFs cannot see business-logic flaws such as broken access control, and encrypted traffic must be decrypted at the WAF for inspection.
Key points
- Filters HTTP traffic at the application layer.
- Useful for virtual patching while code fixes are developed.
- Requires tuning to balance false positives against missed attacks.
- Complements secure coding but cannot fix business-logic flaws.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- SQL Injection (SQLi)Cybersecurity & Compliance
- Cross-Site Scripting (XSS)Cybersecurity & Compliance
- Distributed Denial of Service (DDoS)Cybersecurity & Compliance
- API SecurityCybersecurity & Compliance
- Payment Card Industry Data Security Standard (PCI DSS)Cybersecurity & Compliance
- OWASP Top 10Cybersecurity & Compliance