Web application firewall (WAF)
Keep your site and your online services out of an attacker's reach
A web application firewall reads the traffic arriving at your site the way your application does, and refuses the requests that were written to break it: SQL injection, cross-site scripting, brute force sign-in attempts and a long tail of everything else. Mashhad Cloud fits the rules to what your business actually serves and runs the thing for you, so the service stays fast, stays up, and stays yours.


Where a web firewall earns its place
Retail
Online stores
Checkout pages, customer accounts and the records behind them, kept away from the attacks that go looking for them.
Platform teams
APIs and web services
Calls to a public endpoint are checked, the rate they can arrive at is capped, and a leaked key stops being useful.
Enterprise
Corporate websites
Intrusion and the abuse of known weaknesses both stop at the edge, and the site stays reachable while they do.
SaaS
SaaS platforms
One tenant's traffic never reaches another tenant's data, and a shared sign-in stops being a way in.
Education
Learning systems and services
Student records stay private and a class does not go down because somebody pointed a script at it.
Finance
Financial systems
A hard layer in front of the services that hold balances, statements and everything a transaction touches.
What a web firewall does
APIs protected
Incoming calls are checked, endpoint abuse is refused, and traffic that does not look like traffic is capped.


SQL injection and XSS stopped
Requests written to reach data they should not, or to run code that is not yours, are recognised and refused.
Internal systems hardened
A layer of defence in front of business software, portals and anything else you serve over the web.


Brute force turned away
Repeated sign-in attempts are recognised for what they are, and the password guessing stops there.
What Mashhad Cloud's web firewall gives you
- SQL injection blocked
- XSS blocked
- Brute force defence
- HTTP and HTTPS request filtering
- Rate limiting
- Rules you write yourself
- API protection
- Logs and reporting
- Live attack monitoring
- Managed and supported
What it is worth
A safer website
Intrusion and the abuse of known weaknesses both stop before they land.
The service stays reachable
Fewer of the outages a flood of malicious traffic would otherwise cause.
Less exposure to attack
Threats are recognised and stopped before they reach the server.
Your users' data protected
Sensitive records are harder to reach and harder to leak.
Frequently asked questions
Does a WAF slow a website down?
A correctly configured WAF has a very small effect on speed, small enough that in practice it is not noticed.
Does a WAF stop DDoS attacks?
A WAF identifies and blocks layer 7 attacks, the ones aimed at the application. Volumetric DDoS at the lower layers usually needs a dedicated anti-DDoS service, though some WAFs offer limited protection of their own.
Can we define our own rules?
Yes. Custom rules can be written around what your application or your organisation needs, blocking or allowing suspect traffic on your terms.
Can a WAF protect an API?
Yes. A WAF protects APIs against the same layer 7 attacks it protects a site from: injection, request tampering and abuse of application logic.
What is a WAF?
A web application firewall inspects HTTP and HTTPS traffic and blocks malicious requests, SQL injection, cross-site scripting (XSS) and other application-layer attacks among them, before they reach the server.
How does a WAF differ from a network firewall?
A network firewall works at layers 3 and 4, filtering traffic by address and port. A WAF works at layer 7: it reads the content of HTTP requests and responses, and identifies the attacks aimed at the web.
Reading on web firewalls
خدمات WAF
WAF چیست ؟
WAF چیست و چگونه از وبسایت شما محافظت میکند؟ امنیت وبسایت یکی از مهمترین بخشهای هر کسبوکار آنلاین است. امروزه بسیاری از وبسایتها و سرویسهای اینترنتی هدف حملات مختلف قرار میگیرند و حتی پروژههای کوچک نیز از…
