OWASP core ruleset
Block known web attacks, including the OWASP Top 10, with the core ruleset.
Defend against OWASP Top 10 attacks and malicious traffic.
Overview
Known web attacks are blocked by the core ruleset, while traffic is analyzed in real time to filter out only malicious requests. Custom rules tailored to your service keep your web application safe.
Block known web attacks, including the OWASP Top 10, with the core ruleset.
Traffic is analyzed in real time to detect and block malicious requests instantly.
Apply custom rules and rate limits tailored to your service.
Identify and block malicious bots, scrapers, and automated attack traffic.
Limit excessive requests to defend against DDoS and brute-force attacks.
Coverage
The types below are detected and blocked by the default ruleset.
01
Block database query manipulation attempts
02
Defend against malicious script injection
03
Protect users from forged requests
04
Block massive traffic attacks
05
Detect attacks exploiting unknown vulnerabilities
06
Block dangerous file upload attempts
Features
Ruleset updates, real-time detection, custom rules, bot blocking, and rate limiting are all managed in one place.
Machine-learning-based analysis automatically detects even new, previously unseen attack patterns.
Define and apply your own security policies tailored to how your service works.
Use cases
When payment info and customer data protection is essential
When public APIs need protection from abuse
When PCI-DSS, GDPR compliance is required
When handling personal or financial data
FAQ
What people check most before putting a firewall in front of a service.
It blocks the known attacks, OWASP Top 10 included. Whatever is specific to your service is better handled by adding custom rules on top.
Add an exception for that path or condition as a custom rule. Rules are yours to define and apply.
Machine-learning analysis picks up new attack patterns automatically. A brand-new pattern can take time to surface, though, so we suggest rate limiting on critical paths as well.
No. Ruleset updates, real-time detection, custom rules, bot blocking and rate limiting are managed in one place.
The firewall inspects individual HTTP requests and filters the malicious ones. The clean zone absorbs the volume that fills your link, upstream. They do different jobs and are often used together.
Protect your web applications with enterprise-grade WAF.