Deploying a Web Application Firewall

Web Application Firewalls (WAFs) are essential security mechanisms used on almost all commercial websites today. Using a WAF is a very effective way of preventing known attacks. The WAF combats commonly known attacks against web servers using a number of security checks to filter inbound HTTP/HTTPS requests. In addition to managing requests, you can apply WAF security checks to modify the responses sent back to users. Despite the excellent protection they offer against many types of attacks, WAF is inadequate for protecting against today's sophisticated SQL Injection (SQLi) attacks. You can consider WAF a rule-based second layer of defense for protecting web servers against known threats XSS, SQLi, and ...

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.