WAF
/wæf/ · Abbreviation · Security & Infosec
Definitions
Web Application Firewall — a security layer that filters, monitors, and blocks HTTP traffic to and from a web application, protecting against attacks like SQL injection and XSS.
In plain English: A security guard specifically for websites that inspects every visitor's request and blocks anything that looks like an attack.
Etymology
- 1990s
- Early web application firewalls emerge as HTTP-aware proxies that inspect request content beyond traditional packet filtering
- 2002
- ModSecurity is released as an open-source WAF module for Apache, democratizing web application protection
- 2010s
- Cloud WAFs (Cloudflare, AWS WAF) make protection accessible without hardware, becoming standard infrastructure
Related Terms
- Firewall
- DDoS
- Botnet
- Air Gap
- VPN
- Rate Limiting
- Zero Trust
- HTTPS
- Security Headers
- Air-Gapped Network
- CAPTCHA
- Code Obfuscation
- Defense in Depth
- Hardened Image
- HTTP Strict Transport Security
- Human Firewall
- Implicit Grant
- Infrastructure Security
- Isolation
- Mobile Security
- Padding Oracle Attack
- Port Knocking
- RASP
- Syslog
- WAF Rule
- Active Defense
- Application Hardening
- ARP Cache Poisoning
- Blind Command Injection
- Blind XSS
- C2 Server
- Computer Network Defense
- Confusion
- Control Plane Security
- Cookie Hijacking
- Cross-Domain Attack
- Cyber Operations
- Double Encoding
- HPKP
- HTTP Method Tampering
- Local File Inclusion
- Management Plane Security
- Memory Scraping
- NTP Security
- Out-of-Band Management
- Output Encoding
- Parameter Tampering
- Path Traversal
- Responsible AI Security
- Reverse Proxy Security