Skip to main content

General information about Web Application Firewall (WAF) protection

WAF (Web Application Firewall) is a class of solutions that ensure web application security at the L7 level, protecting a site or application from targeted attacks.

A targeted attack is an attack on your website or application aimed at stealing confidential data, gaining access to internal systems, causing reputational damage, or disrupting the operation of the application. Targeted attacks are often disguised as normal user traffic.

The WAF Curator service is available in Selectel.

Operation principle

Traffic that has been scrubbed at DDoS protection filtering nodes is redirected to WAF. WAF analyzes HTTP and HTTPS traffic and applies filtering rules to clean the traffic from malicious requests.

WAF operates based on machine learning algorithms. There is a mandatory learning and monitoring period that lasts about two to three weeks. The duration of the learning period depends on the volume of incoming traffic. During the learning process, WAF analyzes traffic directed to your application and learns how to protect your specific application. The following are used for learning:

  • behavioral analysis — WAF studies user behavior and learns to recognize abnormal behavior;
  • signature analysis — WAF matches traffic against known types of attacks.

This is how a list of filtering rules is formed and the accuracy of blocking attacks is increased. After completing the learning process, WAF can proceed to active attack blocking.

Limitations

WAF analyzes traffic that has already been scrubbed of attacks, so the service can only be enabled in addition to DDoS protection at the application layer (L7). For more information on how DDoS protection works, see the General information about DDoS protection.