WAF · web application protection

A WAF that protects web applications
without a foreign cloud

Aegis WAF covers the OWASP Top 10, runs in „monitor“ or „protect“ mode and blocks attacks at the edge of your network — without routing traffic through a third-party cloud and without hiding the visitor's real IP address from your own logs.

OWASP Top 10 Monitor or protect mode Traffic never leaves your infrastructure
What Aegis WAF does

Stops attacks on the application before they reach the code

A web application is the most exposed part of most systems. A WAF (Web Application Firewall) filters requests to the application and stops known attack patterns before they reach your code and database.

OWASP Top 10

Protection against injection, XSS, LFI, broken access control and other common web application risks.

Monitor → Protect

First observe what the WAF would block, then turn on active protection without the risk of suddenly blocking legitimate traffic.

Auto-block at the edge

The WAF blocks persistent attackers at the firewall, before a request even reaches the application.

Geo-blocking

Stop traffic from regions where you have no users and reduce your attack surface.

Virtual patching

Cover a known attack vector with a WAF rule until the real code patch arrives.

Integration with the SIEM

WAF events enter correlation with the rest of your infrastructure for a broader picture of the attack.

COMPARISON

Aegis WAF vs. cloud WAF (e.g. proxy providers)

A cloud WAF routes your traffic through an external network before it reaches you. That has advantages, but also a cost: traffic and TLS pass through a third party, and a visitor's real IP can get lost. Aegis WAF works at your edge.

CRITERIONAegis WAF (at your edge)Cloud WAF (third-party proxy)
Where traffic is processedIn your infrastructureThrough an external provider's network
The visitor's real IP✓ Directly in your logsBehind the proxy (depends on headers)
TLS termination at a third partyNot requiredOften required
Data residency✓ HR/EU, traffic never leavesDepends on the provider and region
OWASP Top 10 protection
Dependency on a third partyLowHigher (vendor / network)
Volumetric DDoS scrubbingLimited to the application layerThe advantage of large CDN networks
To be fair: for volumetric (network) DDoS, a large CDN/scrubbing network has the advantage and is a good complementary layer. Aegis WAF focuses on application attacks and control at your edge; we don't promise an abstract percentage of blocked attacks, because such a figure depends on the application, the rules and the traffic.
HOW IT WORKS

From "monitor" to "protect" — without the risk of sudden blocking

1
Monitor modeThe WAF first only observes and logs what it would block. You see whether legitimate traffic would be affected, without a single real block.
2
Rule tuningExceptions and adjustments resolve false positives specific to your application before blocking is turned on.
3
Protect modeWhen you are confident, the WAF switches to active blocking — SQLi, XSS, LFI and other OWASP patterns are stopped at the edge.
4
Auto-block and correlationPersistent attackers are blocked at the firewall, and WAF events feed into SIEM correlation for the bigger picture.
Basics

What a WAF is and where its limits are

WAF (Web Application Firewall) analyzes HTTP(S) requests to a web application and blocks those matching attack patterns. Unlike a network firewall that looks at IPs and ports, a WAF understands the content of a request — parameters, headers and body.

OWASP Top 10

The OWASP Top 10 is a reference list of the most common web application risks (e.g. injection, broken access control, XSS). Aegis WAF specifically covers these categories with known rules and virtual patches.

Virtual patching

When there is a known vulnerability in an application and the patch has not yet been applied, a WAF rule can virtually patch the attack vector and buy you time until the real fix.

A WAF is not a substitute for secure code

A WAF reduces risk but doesn't fix the vulnerability in the code. That's why it pairs with vulnerability assessment i penetration testing, which find and prove the real weaknesses of the application.

Frequently asked questions

WAF — frequently asked questions

Does my traffic have to pass through your network? +
No. Aegis WAF runs at the edge of your infrastructure, so traffic does not have to pass through a third party. The visitor's real IP address stays visible in your logs.
Will the WAF block legitimate users? +
That's why there's a „monitor“ mode: the WAF first only records what it would block, so you tune exceptions before switching to active „protect“ mode. This way false positives are resolved without service interruption.
Does the WAF cover DDoS? +
Aegis WAF helps with application-layer attacks and can rate-limit and geo-block traffic at the edge. For large volumetric DDoS attacks, an additional CDN/scrubbing layer is recommended as a complement.
Does a WAF replace a pentest? +
No. A WAF mitigates attacks but does not fix the vulnerability in the code. Penetration testing finds and proves the real weaknesses that you then fix.
RELATED

Keep exploring the platform

Protect web applications without a foreign proxy

Let us show Aegis WAF on your application: first in "monitor" mode so you see its accuracy, then active protection at your edge.

Odgovaramo isti radni dan · info@aegis.hr