Skip to content
Article

What Is a WAF? How a Web Application Firewall Works

A WAF inspects requests to a web application and stops attacks before they arrive. We explain how it differs from a firewall, rule tuning and PCI DSS.

Oğuzhan Gerçek··8 min read
What Is a WAF? How a Web Application Firewall Works

Short answer: A WAF (web application firewall) sits in front of a web application, inspects the HTTP requests coming to it and stops the ones carrying an attack before they reach the application. A network firewall looks at where a connection comes from and which port it goes to; a WAF reads inside the request: the URL, the parameters, the headers and the form data. It catches attacks such as SQL injection and XSS, and limits bot traffic and request rates. It does not fix the flaw in the code, but it makes exploiting it harder until a permanent fix arrives.

What is a WAF?

In Cloudflare's definition, a WAF protects a web application by filtering and monitoring HTTP traffic between the application and the internet, and it operates at layer 7 of the OSI model, the application layer. The firewall guidance SP 800-41 from the US National Institute of Standards and Technology (NIST) describes WAFs as specialized application firewalls that detect exploits against web servers.

A WAF works as a reverse proxy: the client connects to the WAF rather than to the application, and the WAF inspects each request and forwards only the clean ones to the server behind it. We explain reverse proxies in our proxy article, and there is a short definition of the term in our glossary.

WAF vs network firewall

A traditional network firewall looks at the packet header. According to the same NIST guide, the most basic type, the packet filter, decides based on the source and destination IP address, the protocol, the port number and the interface the packet crosses. Traffic to a website, however, arrives over a legitimate connection on 443, the default port for HTTPS (RFC 9110), and the firewall has to let it through.

The attack travels inside that permitted connection: an SQL statement typed into a form field, a script appended to a URL parameter. A WAF sees it because it parses the HTTP request. With HTTPS, the URL, headers and request body are encrypted, so a WAF can only read them if TLS is terminated at the WAF or at a layer in front of it.

One does not replace the other: a firewall decides who can talk to whom, and a WAF looks at what permitted web traffic carries.

How does a WAF work?

A WAF combines several methods:

  • Signatures and rules (negative model): It looks for known attack patterns; Cloudflare calls this a blocklist, or negative security model.
  • Allowlist (positive model): It lets through only requests that match a predefined format. This is stricter, but every expected request has to be described.
  • Anomaly scoring: In rule sets such as the OWASP Core Rule Set (CRS), a single match does not block a request immediately; each matching rule raises its score. In CRS a critical rule adds 5 to the score, and the recommended threshold for inbound requests is also 5.
  • Bot management and rate limiting: It slows down or stops sources that send many requests in a short time, and separates out automated traffic such as credential stuffing and scraping.

Volumetric DDoS attacks that saturate the network link, on the other hand, should be stopped at the network edge before they reach the WAF; we handle that layer in our network protection service.

WAF and the OWASP Top 10

The OWASP Top 10 ranks the most critical security risks to web applications and is, in OWASP's own words, a standard awareness document; the current release is the OWASP Top 10:2025. A01:2025 Broken Access Control sits at the top. Injection, which covers SQL injection and XSS, fell from third place in 2021 to fifth (A05:2025).

But not every risk shows up as a pattern in an HTTP request. A user opening another customer's record (A01), a design flaw (A06:2025 Insecure Design) or a vulnerability in a third-party component (A03:2025 Software Supply Chain Failures) can look like an ordinary request to a WAF. OWASP's main recommendation for injection is in the code, too: keep data separate from commands and queries.

What a WAF does in this gap is virtual patching. OWASP defines virtual patching as a policy enforcement layer that detects and blocks exploitation attempts against a known vulnerability without changing the vulnerable code: it does not remove the vulnerability, it buys time while a permanent fix is prepared. Finding the vulnerability itself takes code review and penetration testing.

WAF deployment models

Cloudflare divides WAFs into three groups by where they are deployed:

  • Cloud or CDN-based: Traffic is usually redirected to the provider's network with a DNS change, and the upfront cost is low. In exchange, part of the responsibility passes to a third party, and TLS is terminated at the provider.
  • Network-based (appliance): A device, generally hardware, placed in front of the application. It keeps latency low; according to Cloudflare it is the most expensive option.
  • Host-based module: ModSecurity, which OWASP calls the standard open-source WAF engine, runs on Apache HTTP Server, Microsoft IIS and Nginx. It is inexpensive, but it consumes the server's resources.

On cloud platforms, the WAF is attached to a component the traffic already passes through: AWS WAF can protect CloudFront distributions, API Gateway REST APIs and Application Load Balancers. We explain the load balancer's place in this chain in our load balancer article.

False positives and rule tuning

The hard part of running a WAF is avoiding blocks on legitimate requests, known as false positives. An editor saving HTML content from an admin panel, or a user pasting an SQL query into a support form, can look like an attacker to the rules.

CRS strikes this balance with the paranoia level. There are four levels; the higher the level, the harder it is for an attacker to go undetected, and the more false alarms there are. False positives are cleared with rule exclusions that disable a rule only for the relevant parameter or URL.

Order matters as well: rules first run in a monitoring mode that only logs. AWS recommends testing rules in a staging system first, then in count mode with production traffic, and only then enabling them. When a new field or API is added to the application, the rules need reviewing too; a broad exclusion written in a hurry punches a hole in the protection.

PCI DSS 6.4.2: when is a WAF mandatory?

Requirement 6.4.2, introduced in PCI DSS v4.0, calls for an automated technical solution that continually detects and prevents web-based attacks on public-facing web applications. According to the PCI SSC text, the solution must be installed in front of the application, be actively running and up to date, generate audit logs, and either block web-based attacks or generate an alert that is immediately investigated.

The requirement was a best practice until March 31, 2025, and became mandatory after that date. The earlier requirement 6.4.1 left a choice between reviewing the application with security assessment tools or methods and deploying an automated solution; according to the PCI SSC, it is marked not applicable (N/A) in reports after that date. The current version is v4.0.1, published in June 2024; this revision added or deleted no requirements.

The text names no product; the solution it describes matches what a WAF does. Which applications are in scope depends on the boundaries of the systems where cardholder data is processed (the CDE). We cover how WAF logs are monitored in our SIEM and SOC article, and the compliance side in our PCI-DSS compliance service.

Frequently asked questions

What does WAF mean? Web application firewall: a security layer that inspects the HTTP requests reaching a web application and blocks the ones carrying an attack.

What is a WAF used for? It stops application-layer attacks such as SQL injection and XSS before they reach the application, and limits bot traffic and excessive request rates.

What is the difference between a WAF and a firewall? A network firewall allows or blocks connections based on IP address, port and protocol. A WAF looks inside permitted web traffic and catches attacks in the content of the request.

Does a WAF fix vulnerabilities in the code? No. It blocks known attack patterns, but the vulnerability stays in the code; the permanent fix is correcting the code.

Does PCI DSS require a WAF? PCI DSS requirement 6.4.2 calls for an automated solution in front of public-facing web applications that detects and prevents web-based attacks, and it has been mandatory since March 31, 2025.

Sources