Web application firewall (WAF)
What is a web application firewall (WAF)?
A web application firewall (WAF) sits in front of a website and checks every request before it reaches the application, stopping the ones that look like an attack. The usual examples are injection through a search box, thousands of login attempts with stolen passwords, and bots crawling for admin addresses. It does not fix the flaw in the code; it buys time until the fix ships.
Example
Overnight, a shop’s admin login takes 40,000 attempts from around 900 addresses: passwords stolen in somebody else’s breach, tried one by one. The server stays up, but every attempt runs a database query and the whole site crawls. A filter in front of the site does three things:
- It limits attempts, say five per ten minutes from one address, and refuses the rest before they reach the application.
- It blocks requests carrying known attack patterns, such as SQL injection through the search box or a script pasted into a comment field.
- It closes the admin addresses to everyone except a few known networks.
There is a cost to this. A rule written for an attack sometimes stops real work: an editor pasting HTML into an article gets refused. New rules therefore run in log-only mode for a week or two, and start blocking after that.
Why it matters for a business
What a WAF buys is time. When a vulnerability in a plugin becomes public and no fix exists yet, a rule in front of the site can block that specific request shape, which is called virtual patching and is often the difference between a quiet weekend and a restore from backup. The same rules throttle the bots scraping your prices every morning and the logins tried with stolen passwords. Where the traffic flows matters too: if the server still answers requests at its own address, an attacker simply goes around the filter.
What to ask
- Where does the filter run, in the network in front of the site or as a module on the server, and who updates the rules?
- Does the server still accept direct requests, or only traffic that came through the filter?
- Is there rate limiting on login, search, basket and the API?
- Who reviews blocked requests, and how is a wrongly blocked customer let back in?
- How long do new rules run in log-only mode before they block?
A WAF is a bandage, not a cure: it shows that something is knocking, not which door is unlocked. That is what website security testing answers, by running the attacks themselves and ranking what it finds by severity.