What is a web application firewall?
A WAF inspects the content of web requests and blocks those it judges malicious — operating at the application layer, which is what distinguishes it from an ordinary network firewall.
The distinction that matters. A network firewall decides based on addresses and ports: allow traffic to port 443, block everything else. It has no idea what the request says. A WAF reads the actual HTTP request — the URL, parameters, headers, cookies and body — and decides based on content.
This is necessary because most web attacks arrive over perfectly legitimate connections to ports you must leave open. The connection is fine; the request is not.
What it looks for:
SQL injection — input crafted to alter a database query.
Cross-site scripting (XSS) — input designed to execute in other users' browsers.
Path traversal attempts to read files outside the web root.
Command injection and file inclusion attempts.
Known exploit signatures for specific software and vulnerabilities.
Abnormal request patterns, bot activity and credential stuffing.
How it decides. Mostly rule sets — the OWASP Core Rule Set is the widely used open standard — supplemented by reputation data, rate limiting and, increasingly, behavioural models.
The genuine limitations, which matter:
It is a filter, not a fix. A WAF blocks known attack shapes; it does not remove the vulnerability. Secure coding, parameterised queries and input validation remain the actual defence, and a WAF should be treated as defence in depth.
False positives are a constant problem. Legitimate content containing SQL-like text, code samples, or unusual characters gets blocked. Anyone running a WAF spends real time tuning exceptions, and over-aggressive rules break genuine users silently.
Evasion is possible through encoding and obfuscation.
Encrypted traffic must be decrypted to inspect, so the WAF must terminate TLS — which is why WAFs typically sit at a CDN or load balancer.
Where it is genuinely valuable: as a virtual patch, blocking exploitation of a newly disclosed vulnerability within hours while the underlying software is updated properly. That speed advantage is the strongest argument for having one.
Detection mode first is standard practice — log what would be blocked before blocking it.