Skip to main content
Book 07 · SecurityPage 47 of 50

Web Application Firewall

WAF

Pronunciation
WAF
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/web-application-firewall

In short

A web application firewall (WAF) inspects HTTP requests before they reach a web application and blocks malicious ones, such as SQL injection, based on rules.

What is a web application firewall?

A traditional network firewall decides by IP address and port, so it lets any request to port 443 through. A WAF works at the application layer: it reads the URL, headers, cookies and body of each HTTP request and compares them with rules that recognize attack patterns, such as ' OR 1=1 in a query parameter or a <script> tag in a form field.

WAFs are usually deployed as part of a CDN or reverse proxy, such as Cloudflare, AWS WAF, Azure Front Door or Akamai, or as a module such as ModSecurity with the OWASP Core Rule Set. Besides attack signatures, they offer rate limiting, bot detection, blocking by country or reputation, and custom rules for a specific application.

A useful feature is virtual patching: when a vulnerability is announced in software you run, a WAF rule can block exploit attempts within hours, buying time until the real fix is deployed. WAF logs also show what attackers are trying, which helps prioritize security work.

A common misconception is that a WAF makes an application secure. Rules can be bypassed with encoding tricks and can't understand business logic, such as one user reading another user's orders. They can also produce false positives that block real customers. A WAF is a useful extra layer, but secure code, input validation and parameterized queries remain the foundation.

Key takeaways

  • A WAF filters HTTP requests at the application layer.
  • It blocks patterns such as SQL injection, XSS and abusive bots.
  • It often runs in a CDN or reverse proxy; ModSecurity is a common engine.
  • Virtual patching blocks new exploits until code is fixed.
  • It complements secure code; it can be bypassed and can block real users.

Readers ask

What is the difference between a WAF and a firewall?

A network firewall filters traffic by addresses, ports and protocols. A WAF understands HTTP and inspects the content of web requests to block application attacks such as SQL injection and XSS.

Do I need a WAF?

It is a good extra layer for public websites and APIs, especially to block bots and buy time for urgent patches. It doesn't replace secure coding, dependency updates and proper authorization checks.

What is virtual patching?

Blocking attempts to exploit a known vulnerability with a WAF rule, before the application itself is fixed. It reduces risk during the time between disclosure and deploying the real patch.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings