WAF - Web Application Firewall Protection
About 2 min read
A WAF (Web Application Firewall) is a dedicated firewall that inspects HTTP/HTTPS traffic to a web application and detects and blocks attacks such as SQL injection and XSS. Whereas a conventional firewall controls communication at the network layer (IP addresses, port numbers), a WAF analyzes the application layer (the contents of HTTP requests). As of 2025, enhancements to WAF features specialized for API security are advancing.
What a Count-Based Judgment Actually Separates
A mechanism that blocks based on the number of arrivals from the same sender within a fixed span of time is not separating attacks from legitimate use; it is separating how the arrivals are grouped. Once the count that serves as the criterion and the width of the span are fixed, splitting the sender into several or spacing the arrivals further apart is enough to stay under the criterion, and nothing is left on the blocking side to act upon. Tighten the criterion instead, and a person repeatedly correcting a mistyped entry, or a case where an unstable connection resends the same submission, all look the same. As long as the division is made by count alone, no value satisfies both at once. Moreover, the unit of a single sender does not coincide with the unit of the person actually operating. In a configuration where many people arrive through one shared exit, unrelated people appear grouped together as one sender, while conversely the activity of one person splits across several senders as location or line changes. Because the units do not match, counting on the basis of the sender produces both over-grouping and over-splitting within the same mechanism. Furthermore, how a block is reported back conveys where the criterion sits. If the content of the response, or the time it takes to return, differs between what is let through and what is stopped, the point at which blocking begins can be confirmed from outside. Once the boundary is known, keeping just under it is enough to keep getting through, so deciding a blocking criterion also means deciding how much of the fact of the block is shown to the other side.
WAF Detection Methods
The signature-based method detects attacks by defining known attack patterns (for example, request parameters containing SQL statements) as rules. The scoring method assigns scores to multiple suspicious characteristics and blocks requests that exceed a threshold. The machine-learning-based method learns normal traffic and automatically detects anomalous requests. Cloud WAFs such as AWS WAF, Cloudflare WAF, and Akamai have the strength of being able to reflect global threat intelligence into their rules in real time.
How Far Into the Same Request Each Layer Looks
Even if a request matches no single pattern, the scoring method blocks it once the combined score of its suspicious characteristics exceeds the threshold. With the machine-learning-based method, deviation from the normal traffic it has learned is itself the basis for judgment. Note that in the monitoring mode used right after deployment, a request judged to be an attack is still forwarded to the web server instead of being blocked.
Deployment Scenarios and Operation
On an e-commerce site, the WAF defends against credential stuffing attacks on the login page, SQL injection on the search form, and XSS on review submissions. Right after deployment, it is safer to operate in monitoring mode (detection only, no blocking), grasp the patterns of false detections, and then switch to blocking mode. Handling false positives, in which legitimate requests are mistakenly blocked, is the greatest challenge of WAF operation. By combining DNS security with a WAF, you can achieve multi-layered web defense.
Limitations of a WAF
A WAF is merely one layer of defense and is no substitute for fixing the vulnerabilities of the application itself. Since there are also advanced attack techniques that bypass WAFs, both secure coding and a WAF are necessary. Protect the WAF management console with a strong random password and record the change history of rules in an audit log.
Was this article helpful?