Glossary

    Web Application Firewall (WAF)

    Network Security

    AWS WAF is a web application firewall that monitors and filters HTTP/HTTPS requests to your web applications hosted behind CloudFront, ALB, API Gateway, AppSync, Amazon Cognito user pools, AWS App Runner, AWS Verified Access, or AWS Amplify. It protects against common web exploits at Layer 7 (application layer).

    What WAF Protects Against

    • SQL injection
    • Cross-site scripting (XSS)
    • Bot traffic and scrapers
    • Rate limiting (DDoS mitigation at L7)
    • Geo-blocking (restrict by country)
    • IP reputation lists

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.