---
title: "WAF Curator"
sidebar_label: "WAF Curator"
sidebar_position: 2
description: "How it works, pricing, how to enable the service, configure it, and disable the service"
---

import Formbricks from '@theme/MDXComponents/Formbricks';

# WAF Curator

Protection of web applications against targeted attacks in partnership with [Curator](https://curator.pro/).

The main task of WAF Curator is to block attacks and eliminate vulnerabilities included in the [OWASP Top Ten project's list of common web application vulnerabilities](https://owasp.org/www-project-top-ten/). .

The service is provided only as an add-on to the [Curator Protection](/anti-ddos/curator.mdx) service.

## How it works \{#principle-of-operation}

After enabling the service, application traffic that is already passing through [the basic Curator protection](/anti-ddos/curator.mdx) is additionally redirected to the WAF Curator protection system.

For the first two weeks after activating the service, the system operates in monitoring and learning mode to learn how to protect your specific application. To do this, the system studies user behavior and checks traffic for compliance with known types of attacks.

During the learning phase, Curator specialists independently monitor anomalies and suppress false positives—requests from real users that the system mistakenly identified as an attack.

Based on the collected data, filtering rules are generated and the accuracy of attack blocking is improved.

Once system learning is complete, Curator specialists will notify you via a ticket in the [Curator control panel](#work-in-account), and you will be able to [enable protection](#manage-defense).

## Pricing \{#price}

A one-time payment equal to the cost of the selected plan is charged on the day of activation. Subsequently, the payment is charged automatically on the first day of each month. The monthly payment includes:

* monthly fee — a fixed payment for the next month;
* connecting an additional domain.

The plan includes a bandwidth of 3 Mbps. If this value is exceeded, each additional Mbps is billed separately. An invoice for the additional [bandwidth](#bandwidth) is generated in the [control panel](https://my.selectel.ru/balance/add) within five business days after the end of the calendar month.

Pricing for the WAF Curator subscription fee, additional Mbps, and connecting an additional domain can be found on [selectel.ru](https://selectel.ru/services/is/waf/?section=prices).

### Bandwidth calculation \{#bandwidth}

Only legitimate traffic—traffic cleared of malicious requests—is billed. Attack traffic is not counted.

To calculate bandwidth, the volume of outgoing traffic and incoming traffic cleared by the filtering system is measured every minute. The maximum value from these measurements is selected for each minute. At the end of the calendar month, all values are sorted in descending order. 90 maximum values are excluded from the calculation. The remaining value is rounded down to the nearest whole Mbps—this number is the bandwidth value. If it exceeds 3 Mbps, each additional Mbps is billed separately.

## Enable service⁠​ \{#enable-service}

1. In the [control panel](https://my.selectel.ru/network/antiddos), on the top menu, click **Products** and select **DDoS Protection**.
2. Go to the **DDoS Protection** section.
3. Click **Order services**.
4. In the row for the required plan (Curator — Elementary WAF, Curator — Advisory WAF), click **Pay**.
5. Verify the details and click **Pay for service**.
6. We will create a [ticket](https://my.selectel.ru/tickets/) to enable the service, in which we will clarify a convenient day for you to connect.

## Working in the Curator control panel \{#work-in-account}

Login credentials for the Curator control panel will be sent to the email address you specified when ordering the [Curator Protection](/anti-ddos/curator.mdx) service.

In the Curator control panel, you can:

* [enable protection](#manage-defense);
* [suppress a false positive](#mark-false-positive);
* [view statistics](#view-statistics);
* contact Curator technical support.

### Enable protection \{#manage-defense}

When the system training is complete, Curator specialists will notify you in your account. After this, you can enable the attack blocking mode by checking the [WAF](https://client.curator.pro/curator/waf/) section box **Active Protection**.

If your application is under attack but system learning is not yet complete, contact Curator technical support to discuss enabling attack blocking mode on an individual basis.

### Suppress a false positive \{#mark-false-positive}

During the system learning phase, Curator specialists suppress false positives so that their number is minimal when protection is operational.

After system learning is complete, you can independently monitor false positives using the [statistics](#view-statistics) tools.

If you notice a false positive, contact Curator technical support in your account and specify the transaction number for the false positive. The transaction number can be viewed in the transaction list in the [WAF](https://client.curator.pro/curator/waf/) section. Curator specialists will analyze the anomaly and adjust the model. Filtering rules will be automatically reconfigured, and the system will allow similar requests. You can also suppress false positives yourself.

### View statistics⁠​ \{#view-statistics}

Statistics are available in the [WAF](https://client.curator.pro/curator/waf/) section. Here you can view:

* a dashboard with key traffic metrics;
* security events grouped by type and threat level;
* a list of transactions — requests, responses, and errors.

## Disable service⁠​ \{#disable-service}

To disable WAF Curator, [create a ticket](https://my.selectel.ru/tickets/create/).

The service is disabled on the last day of the calendar month. If you need to disable the service earlier, the payment for the current month is not refunded.

If, in the last month of service, bandwidth usage exceeded 3 Mbps, an invoice for the additional [bandwidth](#bandwidth) will be generated in the [control panel](https://my.selectel.ru/balance/add) within five business days after the end of the calendar month.

Disabling WAF Curator does not affect the main [Curator protection](/anti-ddos/curator.mdx) — it will continue to work.

<Formbricks />
