From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 24,300 courses taught by industry experts.

Web application firewalls (WAF)

Web application firewalls (WAF)

- In this web safari, we're going to look at one of the most dominant web application firewalls, and that is the AWS WAF, which you can run on your application load balancer, for example, you can run it on your CDN distribution, your CloudFront CDN distribution at edge locations, you can run it on the API gateway, you can even run it on Amazon AppSync. Some of the benefits of the WAF, also referred to as a web security gateway, it is a logical way to create security rules that can help us with our web bot traffic, common attack patterns, like SQL injection, and cross-site scripting. Some of the other features of the WAF would be web traffic filtering, okay, so let us filter a wide variety of things. And when you use the WAF, generally you're going to use what's called WAF and shield. So it kind of goes hand-in-hand with AWS's anti-DDoS feature. So it's kind of a bundle. Usually the WAF is going to be a managed service where you'll let different vendors, like F5 or others, manage the…

Contents