Definition · Known Vulnerabilities (CVEs)

What is Web Application Firewall?

A web application firewall (WAF) operates at the HTTP layer rather than on ports and addresses. It parses requests — paths, parameters, headers, cookies, bodies — and decides whether to pass, block, challenge or log each one. It may run as a cloud service in front of a CDN, as a reverse proxy appliance, or as a module inside the web server.

Detection models

  • Negative security (blocklist) — rules describing known attack patterns, such as SQL injection or cross-site scripting payloads. The OWASP Core Rule Set, commonly run with ModSecurity-compatible engines, is the reference implementation.
  • Positive security (allowlist) — an explicit model of legitimate requests, rejecting anything outside it. Much stronger where it can be maintained, and much harder to maintain for a changing application.
  • Rate limiting and bot management — volumetric and behavioural controls, aimed at credential stuffing, scraping and enumeration rather than single malicious requests.

Most deployments combine them, with managed rulesets updated by the vendor and a smaller set of custom rules for the specific application.

Virtual patching

The most defensible use of a WAF is buying time. When a CVE lands in a component you cannot patch immediately, a targeted rule blocking the specific request shape can hold the line while the change goes through testing and release. That is worth having, and it is a compensating control rather than a fix: the vulnerability remains, and the rule only covers the payload variants it was written for. Treating a WAF rule as closing the issue is how organisations end up with long-lived exposure they believe is remediated.

Limitations to be honest about

Signature-based rules are bypassable, and bypass techniques — encoding, parameter pollution, chunked or oversized bodies, HTTP request smuggling, protocol-level quirks — are a well-developed field. A WAF sees requests, so it cannot detect flaws in logic: broken access control, insecure direct object references and authorisation bugs all look like ordinary traffic. Rules tuned aggressively produce false positives that break legitimate use, which is why many deployments end up in permissive modes that block very little.

A WAF is also detectable and sometimes side-steppable from outside. Response behaviour, block pages and headers typically identify the product, and if the origin’s own address is reachable directly — a common finding on an external attack surface, where a stale DNS record still points at the origin — an attacker can bypass the WAF entirely by connecting to it. Verifying that origins accept traffic only from the WAF or CDN is as important as the ruleset.

See defence in depth, patch management, vulnerability management, network segmentation, DAST and penetration testing.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.