Security & networking

Web Firewall

Defend against OWASP Top 10 attacks and malicious traffic.

Overview

Block attacks, let legitimate traffic through

Known web attacks are blocked by the core ruleset, while traffic is analyzed in real time to filter out only malicious requests. Custom rules tailored to your service keep your web application safe.

OWASP core ruleset

Block known web attacks, including the OWASP Top 10, with the core ruleset.

Real-time detection

Traffic is analyzed in real time to detect and block malicious requests instantly.

Custom rules

Apply custom rules and rate limits tailored to your service.

Bot Blocking

Identify and block malicious bots, scrapers, and automated attack traffic.

Rate Limiting

Limit excessive requests to defend against DDoS and brute-force attacks.

Coverage

Protected Attack Types

The types below are detected and blocked by the default ruleset.

  • 01

    SQL Injection

    Block database query manipulation attempts

  • 02

    XSS (Cross-Site Scripting)

    Defend against malicious script injection

  • 03

    CSRF

    Protect users from forged requests

  • 04

    DDoS Attacks

    Block massive traffic attacks

  • 05

    Zero-Day Attacks

    Detect attacks exploiting unknown vulnerabilities

  • 06

    Malicious File Upload

    Block dangerous file upload attempts

Features

From detection to response, operations made simple

Ruleset updates, real-time detection, custom rules, bot blocking, and rate limiting are all managed in one place.

Real-time Threat Detection

Machine-learning-based analysis automatically detects even new, previously unseen attack patterns.

Custom Rules

Define and apply your own security policies tailored to how your service works.

Included Features

  • OWASP Rule Set
  • Custom Rule Engine
  • Bot Defense
  • Rate Limiting
  • Geographic Blocking
  • IP Whitelist
  • Real-time Log Analysis
  • Detailed Attack Logs

Use cases

Recommended For

  • E-commerce

    When payment info and customer data protection is essential

  • API Services

    When public APIs need protection from abuse

  • Compliance

    When PCI-DSS, GDPR compliance is required

  • Sensitive Data

    When handling personal or financial data

FAQ

Frequently asked questions

What people check most before putting a firewall in front of a service.

  • It blocks the known attacks, OWASP Top 10 included. Whatever is specific to your service is better handled by adding custom rules on top.

  • Add an exception for that path or condition as a custom rule. Rules are yours to define and apply.

  • Machine-learning analysis picks up new attack patterns automatically. A brand-new pattern can take time to surface, though, so we suggest rate limiting on critical paths as well.

  • No. Ruleset updates, real-time detection, custom rules, bot blocking and rate limiting are managed in one place.

  • The firewall inspects individual HTTP requests and filters the malicious ones. The clean zone absorbs the volume that fills your link, upstream. They do different jobs and are often used together.

Worried About Web Security?

Protect your web applications with enterprise-grade WAF.