What is a Web Application Firewall
Web Application Firewall (WAF) is a one-stop AI-based risk prevention solution for web business operations. It can identify malicious traffic with the aid of AI and rule engines to protect websites and further improve the website security and reliability. By leveraging bot behavior analysis, it can defend against malicious access requests and safeguard core website businesses and data.
Tencent Cloud provides two types of on-cloud WAF, namely, SaaS WAF and CLB WAF. They have basically the same security protection capabilities but different connection methods.
SaaS-based WAF resolves the domain to the CNAME address provided by the WAF cluster via DNS resolution. By configuring the origin server IP through WAF, malicious traffic targeting the domain is cleansed and filtered, and normal traffic is pulled to the origin server to protect the security of the website.
CLB WAF works with the Tencent Cloud CLB cluster to mirror the HTTP/HTTPS traffic of CLB instances to the WAF cluster. Then, WAF performs bypass threat detection and cleansing and syncs the trusted status of user requests to the CLB cluster, which will block or allow the requests accordingly to protect the website security.
WAF can effectively prevent SQL injection, cross-site scripting (XSS), trojan upload, unauthorized access, and other OWASP attacks. In addition, it can also provide all-around protection for website systems and businesses by effectively filtering CC attacks, providing zero-day vulnerability patches, and preventing webpage tampering.
Main Feature
Features | Introduction |
AI + Web Application Firewall | AI + Rules Web is characterized by its ability to accurately identify attacks, prevent bypass attempts, minimize missed reports and false positives, and provide effective defense against a wide range of common Web attacks, such as SQL injection, unauthorized access, XSS cross-site scripting, CSRF cross-site request forgery, Webshell Trojan upload and other top ten Web security threat attacks defined by OWASP |
0day Vulnerability Virtual Patching | Tencent Security Team provides 24/7 monitoring, proactively discovers and responds, issues high-risk Web vulnerabilities within 24 hours, 0day vulnerability protection with virtual patches, no action required from protected users to obtain emergency security patches, 0day attack prevention capabilities, significantly reducing the vulnerability response cycle |
Webpage anti-tampering | Users can set up cloud caching of core web page content and publish cached web page content to achieve web page replacement effect, preventing web page tampering from bringing negative impact to the organization |
Data Leakage Prevention | Prevent backend database from being stolen by hackers through server application hiding beforehand, intrusion protection during the process, and sensitive data replacement hiding policy afterward |
CC Attack Prevention | Intelligent CC Protection, based on comprehensive analysis of origin server abnormal responses (timeouts, response delays) and big data analysis of website behavior, generates defense strategies through intelligent decision-making. It employs multi-dimensional Customized Precise Access Control, combining CAPTCHA and Frequency Control to effectively filter junk access and mitigate CC attack issues |
Crawler and BOT behavior management | With AI-based rule engine and rule library, this feature manages web crawlers and BOTs to help prevent user data leakage, content infringement, competition-based pricing, inventory query, black hat SEO, business strategy disclosure, and other business risks caused by malicious BOT behavior |
API Security | Refers to measures to protect Application Programming Interfaces (APIs) from malicious attacks or abuse, automatically discovering APIs in business access through proactive learning. It helps users quickly identify and classify known and unknown API assets, creating an API profile list. Additionally, based on threat detection and data identification engines, it provides attack protection, impersonation protection, abuse protection, and data protection capabilities |
30 BGP lines for access protection | WAF supports protection with 30 dedicated BGP IP link access nodes. Intelligent scheduling of nodes effectively solves access latency issues, ensuring the site access speed for users in different cities. It enables a seamless security protection deployment with Cloud WAF, making the impact on website access speed unnoticeable |
Why do you need a Web Application Firewall
In the following scenarios, WAF can effectively defend and prevent, ensuring the system and business security of the enterprise website.
Data leakage (leakage of core information assets)
Web sites are the entrance to corporate information assets. Hackers can steal corporate information assets through Web intrusions, causing immeasurable losses to the companies.
Malicious access and data scraping (Unable to serve normally, data exploited by business competitors)
Hackers control botnets to launch CC attacks on Web sites, exhausting resources and hindering normal service. Malicious users use web crawlers to scrape the core content of websites (literature blogs, recruitment websites, forum websites, comments within e-commerce) E-commerce websites are deliberately crawled by competitors to study product details. Bargain hunters attempt to search for low-priced product information or gain intelligence before major marketing promotions to find arbitrage opportunities.
Websites defaced and tampered with (Affecting website operation and image)
After obtaining Web site or server permissions, attackers insert malicious code to cause users to execute malicious programs, earn traffic, steal accounts, show off skills, etc.; implant "pornography, gambling, illegal" links; tamper with webpage images and text; greatly affect the operation of the website, damaging the website operator's image.
Framework vulnerability (attacks during patching)
Many web systems are based on common open-source frameworks such as Structs2, Spring, and WordPress, which often have security vulnerabilities. The patching period is a difficult and dangerous time as many attacks will emerge just one day after the vulnerabilities are disclosed.
CC attack (business interruption and consuming server resources)
In an attempt to disrupt business operations or make key portal websites inaccessible, CC attacks have become a low-cost and low-barrier method. Attackers often flood business servers with large amounts of data packets, causing resource occupation to soar and a sudden increase in request quantity, thereby blocking normal website access or even causing downtime. This greatly affects business continuity and brand reputation, leaving operators in a passive position when under attack.