Web Application Firewall
WAF
- Pronunciation
- WAF
In short
A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.
What is a web application firewall?
A traditional network firewall decides by IP address and port, so it lets any request to port 443 through. A WAF works at the application layer: it reads the URL, headers, cookies and body of each HTTP request and compares them with rules that recognize attack patterns, such as ' OR 1=1 in a query parameter or a <script> tag in a form field.
WAFs are usually deployed as part of a CDN or reverse proxy, such as Cloudflare, AWS WAF, Azure Front Door or Akamai, or as a module such as ModSecurity with the OWASP Core Rule Set. Besides attack signatures, they offer rate limiting, bot detection, blocking by country or reputation, and custom rules for a specific application.
A useful feature is virtual patching: when a vulnerability is announced in software you run, a WAF rule can block exploit attempts within hours, buying time until the real fix is deployed. WAF logs also show what attackers are trying, which helps prioritize security work.
A common misconception is that a WAF makes an application secure. Rules can be bypassed with encoding tricks and can't understand business logic, such as one user reading another user's orders. They can also produce false positives that block real customers. A WAF is a useful extra layer, but secure code, input validation and parameterized queries remain the foundation.
Key takeaways
- A WAF filters HTTP requests at the application layer.
- It blocks patterns such as SQL injection, XSS and abusive bots.
- It often runs in a CDN or reverse proxy; ModSecurity is a common engine.
- Virtual patching blocks new exploits until code is fixed.
- It complements secure code; it can be bypassed and can block real users.
Readers ask
What is the difference between a WAF and a firewall?
A network firewall filters traffic by addresses, ports and protocols. A WAF understands HTTP and inspects the content of web requests to block application attacks such as SQL injection and XSS.
Do I need a WAF?
It is a good extra layer for public websites and APIs, especially to block bots and buy time for urgent patches. It doesn't replace secure coding, dependency updates and proper authorization checks.
What is virtual patching?
Blocking attempts to exploit a known vulnerability with a WAF rule, before the application itself is fixed. It reduces risk during the time between disclosure and deploying the real patch.
See also
- FirewallNetworking, p. 8A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
- SQL InjectionSecurity, p. 40SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- XSSSecurity, p. 48XSS is a vulnerability that lets an attacker inject malicious JavaScript into a trusted website so that it runs in other users' browsers.
- OWASP Top 10Security, p. 24The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
- Rate LimitingBackend & APIs, p. 37Rate limiting is a technique that caps how many requests a client can make to a server or API within a time window, protecting it from abuse and overload.
- CDNDevOps & Cloud, p. 7A CDN is a network of servers spread around the world that stores copies of website content and delivers it to each user from the nearest location.
Spotted a mistake or something missing on this page?Suggest an edit