GlossaryAttack surface and pentesting

WAF

Short answer

A WAF (Web Application Firewall) filters and monitors the traffic between the internet and a web application or API, blocking malicious requests such as SQL injection, cross site scripting or abusive bots before they reach the application.

How it differs from a network firewall

A network firewall decides which connections are allowed based on addresses and ports. A WAF inspects the content of web requests and understands how web applications are attacked. Both are needed: one does not replace the other.

What it protects against

WAFs are designed around common web attacks, many of them listed in the OWASP Top 10: injection, cross site scripting, access to forbidden paths, credential stuffing and malicious bots. Many WAF services also absorb application layer DDoS attacks.

Virtual patching

When a vulnerability is found in an application and the fix will take time, a WAF rule can block attempts to exploit it in the meantime. This buys time, but it does not replace fixing the code.

Limits

A WAF needs tuning: too strict and it blocks real customers, too permissive and it lets attacks through. It does not fix insecure code or logic flaws, which is why it works best alongside secure development, SAST and DAST testing and regular pentesting.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub