Web Application Firewall
Description
Even in highly secure hosting environments, a residual risk remains for application operations. This risk often originates within the applications themselves. The pressure to rapidly release new software features—whether to keep pace with competitors or maintain a market lead—often results in code that has not been adequately tested. The use of third-party libraries or software can also introduce security vulnerabilities.
The most common attacks exploit HTTP/HTTPS requests to
- inject database queries to manipulate or exfiltrate data
- inject code for execution within the browser (XSS)
- serve locally stored files containing sensitive information (LFI)
Protect your web application against attacks delivered via web requests (OSI Layer 7).
Our WAF solution detects application-level attacks such as
- DoS/DDoS,
- brute force,
- SQL injection,
- cookie poisoning,
- session hijacking,
- and others.
What's more, it enables greater accuracy in tracking and blocking malicious activities by using unique device IDs for each visitor across various IP addresses and sessions. It also supports the identification of malicious bots that bypass standard detection methods; this increased accuracy minimizes threats to your setup. Our Web Application Firewall is an extension of our Local Traffic Management product (#22.60). For defense against volumetric attacks occurring below OSI Layer 7, we offers DDoS Guard. You can find more details in our product description for our DDoS Guard (#22.50.xx).
Our goals for this service
- Protection of your web application against the OWASP Top 10 threats
- Protection against application vulnerabilities
- Protection against zero-day attacks
- Protection of your sensitive data (for example, credit card details)
- Increased web application availability by blocking unwanted traffic
What you can expect from our service
- Extensive set of standard rules
- Customization for your web application via a WAF learning phase managed by us
- Advanced detection and risk mitigation techniques
- Sensitive data masking
- High availability
- High performance headroom
- Our WAF solutions cater to a wide range of requirements and budgets. We don't like surprises, either. If you feel the same way, you'll be pleased to know that you will know the final invoice price at the start of each month. No ifs, ands, or buts. There are no additional usage- or processing-based costs for operating the WAF.
Optional Service Features
- Ongoing adjustment and optimization of the rule set following the initial learning phase
- Logging to a central log server within your setup (#SAE.SLS.xx)
- Near-live analysis via a standard Kibana dashboard on the central log server
FAQ
Do you support WAF IPv6?
Yes.
Can I define my own rules as a customer?
Our experts assist you in defining and maintaining your rules. Direct self-management of the rules is not possible with this product.
How do I find out about currently blocked requests?
When a request is blocked by the WAF, the sender receives an error message containing a support ID. Using this support ID, our experts can identify the rule that was applied and retrieve details of the blocked request. Alternatively, we can log data to a log server, allowing you to perform your own analysis.
How do I eliminate "false positives"?
During the learning phase, the standard rule set is tailored to your application to achieve maximum security and minimal false positives. However, new false positives may occur during ongoing operation, particularly if the application or your data changes. You can open a ticket to modify the rule set by providing the support ID of the blocked request.
Where can I get an overview of attacks on my application?
With the optional central log server (#SAE.ZLS), we offer you the ability to store data generated by the WAF and analyze it using a standardized Kibana dashboard. You receive charts and "top 10" lists about attacks, points of origin, and other details, giving you a quick overview of attacks on your application.
Important Information
We offers the Web Application Firewall as a managed service. You can find further information and details about our managed services on our website.