AiVibe

Cybersecurity & Compliance

Web Application Firewall (WAF)

A security control that inspects HTTP and HTTPS traffic between clients and a web application or API, blocking requests that match attack patterns such as SQL injection, cross-site scripting or abusive bot activity.

A WAF operates at the application layer, typically as a reverse proxy, a cloud or CDN service, or a module in a web server or load balancer. It evaluates requests against rule sets covering known attack signatures, protocol anomalies, rate limits and IP reputation, and can block, log or challenge suspicious traffic. The OWASP Core Rule Set is a widely used open-source rule set that works with engines such as ModSecurity.

Organisations deploy WAFs to protect internet-facing applications and APIs, to apply temporary virtual patches while a vulnerability is fixed in code, and to mitigate application-layer DDoS and bot abuse. PCI DSS version 4.0 requires public-facing web applications to be protected by an automated technical solution that continually detects and prevents web-based attacks, a role WAFs commonly fill.

A WAF is a compensating layer, not a substitute for secure code. Rules need tuning to the application to avoid blocking legitimate users or missing attacks, and attackers use encoding tricks to evade signatures, so many deployments start in detection-only mode before blocking. WAFs cannot see business-logic flaws such as broken access control, and encrypted traffic must be decrypted at the WAF for inspection.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Terms that refer to Web Application Firewall (WAF)

Ask AiMuruga can explain Web Application Firewall (WAF) for your plant, product or security programme, and draw how it fits.