Web application firewall
WAF · A protective layer that inspects requests to a website and blocks those matching known attack patterns; it does not fix a weakness, it makes exploiting it harder.
- 01
Why it matters
A web application firewall inspects requests to your site and blocks known attack patterns; it also slows down automated scans and brute-force attempts. Until a flaw is fixed, it can provide temporary protection, a virtual patch. It does not remove the flaw, though, and badly tuned rules can block real users too.
- 02
Example
A flaw is announced in a plugin your site uses, but the update can only be applied at the weekend. Until then a WAF rule blocks the attack pattern for that flaw; after the update the rule is removed.
- 03
Common mistake
Putting off real fixes once a WAF is in place. A WAF can be bypassed; the real solution is fixing the code and software, and the WAF is only an extra layer.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.