Услуга · Information security

WAF web application protection

A site is open to the whole internet round the clock, and automated scanners find it within hours of publication. A request filter cuts off common attacks on the approach, keeping them away from the application code.

Round the clock
request filtering
Automation
bots cut off
Patches
by a rule until it is fixed
Reports
what and from where

What the work includes

A filter does not replace careful development but buys time: we close a hole with a rule today and fix it in the code in the next release.

Discuss the scope

Filtering

Cutting off common attacks: injection into database queries, substituting scripts on a page, attempts to escape the directory.

Password guessing

Limiting login attempts, protecting the sign-in and account recovery forms.

Bots

We separate search engine crawlers from scrapers and malicious automation.

Quick patches

The vulnerability is closed by a rule before the developers release a fix.

Forms

Filtering out automated submissions without losing genuine enquiries.

Reports

What was blocked, where it came from and under which rule.

How it goes

Connecting takes a few days, but tuning the rules to a specific site stretches out longer than the installation itself.

01

Site review

What the application is, which forms it has, whether there is sign-in, user accounts and integrations.

02

Monitoring

The filter runs without blocking and builds a picture of the real traffic.

03

Rules

We clear out the false positives, of which a live site always has plenty.

04

Blocking mode

We enable blocking and set up alerts and a regular review.

A new site starts being scanned within hours of appearing in the index. There is no need to wait for a targeted attack: bots run through admin panel addresses and known platform vulnerabilities round the clock and indiscriminately. That is why the filter goes up at launch, not after the first incident.

Questions and answers

The cloud option is simpler and usually cheaper, and it speeds delivery through a distributed network. Your own is needed when requirements forbid passing traffic through an external service, or the site is not reachable from the internet at all.

Work through them during the first month and adjust the rules. Getting rid of them entirely is impossible, but bringing them down to isolated cases is quite realistic. That is exactly why the monitoring phase is never skipped.

No. A filter buys time, not immunity: it closes known attack patterns but does not see logic errors in your business rules. Updates will still have to be installed.

We will protect your site

Describe the application and state the platform. We will pick a suitable filter and tune the rules to your traffic.