General information about Web Application Firewall (WAF) protection
WAF (Web Application Firewall) is a class of solutions that ensure web application security at the L7 level, protecting a site or application from targeted attacks.
A targeted attack is an attack on your website or application intended to steal confidential data, gain access to internal systems, cause reputational damage, or disrupt application operations. Targeted attacks are often disguised as regular user traffic.
The WAF Curator service is available in Selectel.
Operation principle
Traffic that has been cleaned at the DDoS protection filtering nodes is redirected to WAF. WAF analyzes HTTP and HTTPS traffic and applies filtering rules to clean the traffic of malicious requests.
WAF works based on machine learning algorithms. There is a mandatory learning and monitoring period that lasts about two to three weeks. The duration of the learning period depends on the volume of incoming traffic. During the learning period, WAF analyzes the traffic directed to your application and learns how to protect your specific application. The following are used for learning:
- behavioral analysis — WAF studies user behavior and learns to recognize abnormal behavior;
- signature analysis — WAF matches traffic against known types of attacks.
This way, a list of filtering rules is formed and the accuracy of attack blocking is improved. After the learning process is completed, WAF can proceed to active attack blocking.
Limitations
WAF analyzes traffic that has already been scrubbed of attacks, so the service can only be enabled in addition to DDoS protection at the application level (L7). Learn more about how DDoS protection works in the General information about DDoS protection guide.