A WAF creates a shield between a web app and the Internet; this shield can help mitigate many common attacks.
After reading this article you will be able to:
Related Content
DDoS mitigation
What is IP spoofing?
What is a DDoS botnet?
Low and slow attack
Ping of death (historic)
Subscribe to theNET, Cloudflare's monthly recap of the Internet's most popular insights!
Copy article link
A WAF or web application firewall helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet. It typically protects web applications from attacks such as cross-site forgery, cross-site-scripting (XSS), file inclusion, and SQL injection, among others.
By deploying a WAF in front of a web application, a shield is placed between the web application and the Internet. While a proxy server protects a client machine’s identity by using an intermediary, a WAF is a type of reverse-proxy, protecting the server from exposure by having clients pass through the WAF before reaching the server.
A WAF operates through a set of rules often called policies. These policies aim to protect against vulnerabilities in the application by filtering out malicious traffic. The value of a WAF comes in part from the speed and ease with which policy modification can be implemented, allowing for faster response to varying attack vectors; during a DDoS attack, rate limiting can be quickly implemented by modifying WAF policies.
A WAF that operates based on a blocklist (negative security model) protects against known attacks. Think of a blocklist WAF as a club bouncer instructed to deny admittance to guests who don’t meet the dress code. Conversely, a WAF based on an allowlist (positive security model) only admits traffic that has been pre-approved. This is like the bouncer at an exclusive party, he or she only admits people who are on the list. Both blocklists and allowlists have their advantages and drawbacks, which is why many WAFs offer a hybrid security model, which implements both.
A WAF can be implemented one of three different ways, each with its own benefits and shortcomings:
Learn how a connectivity cloud lets companies protect their websites with a cloud-based WAF solution.
护士资格证什么时候考 | 莲藕什么时候种植最佳 | 脱盐乳清粉是什么 | 2015属什么生肖 | 抑郁到什么程度要吃氟西汀 |
阴湿是什么病 | 肠胃不好拉肚子吃什么药 | left是什么意思 | 排卵期什么意思 | 为什么一紧张就拉肚子 |
嘴唇发红是什么原因 | 殆什么意思 | 马桶堵了用什么疏通 | 什么生意好做又赚钱 | 总流鼻血是什么原因 |
carol什么意思 | 母亲节送妈妈什么 | 来姨妈吃什么水果好 | 先算什么再算什么 | 寒碜是什么意思 |
王莲是什么植物0735v.com | 胃气上逆是什么原因造成的hcv9jop5ns6r.cn | 手口足吃什么药hcv8jop8ns0r.cn | 梦见死蛇是什么预兆hcv7jop5ns0r.cn | 铅是什么颜色hcv7jop5ns0r.cn |
西洋参不适合什么人吃hcv8jop6ns6r.cn | 面红耳赤是什么生肖hcv7jop7ns2r.cn | 恭候是什么意思hcv7jop6ns6r.cn | mb什么意思hcv8jop8ns7r.cn | 下巴长痘痘什么原因hcv9jop4ns8r.cn |
右手心痒是什么预兆hcv9jop7ns4r.cn | 虎的偏旁是什么hcv9jop2ns5r.cn | 张学友属什么生肖hcv9jop3ns1r.cn | 血压高吃什么好jingluanji.com | 眼睛干涩发痒用什么药hcv8jop9ns3r.cn |
苦瓜对肝脏有什么好处hcv9jop7ns4r.cn | 拔凉拔凉是什么意思hcv8jop5ns7r.cn | 糜烂性脚气用什么药hcv7jop5ns4r.cn | 无济于事的济是什么意思hcv8jop7ns7r.cn | 尿酸高不能吃什么水果hcv8jop8ns8r.cn |