WAF: web application and API protection
Radware AppWall or Cloud WAF detects and blocks common classes of web attacks, login abuse and attacks on APIs. Virtual patches reduce exposure while the application team fixes the underlying code.
What a web application risks
Data theft through forms
One SQL injection in an old form, and the entire client database belongs to the attacker.
Vulnerabilities nobody has time to fix
Development is busy with features; the WAF closes the hole with a virtual patch while the code waits for a fix.
Bots and password brute force
Automated attacks against login forms run around the clock.
What's included
- Radware AppWall on-prem or Cloud WAF as a managed service
- Policies for common OWASP Top 10 classes, tuned to reduce false positives
- Protection of APIs, login brute-force defence and apps behind CDNs
- Automatic real-time policy generation and upkeep
- Logging and reporting for incident analysis
Offensive security experience
Engineers holding OSWE, the certification for web application exploitation. We configure defence knowing how things get broken.
One platform for WAF and DDoS protection
AppWall and DefensePro are components of a single Radware Attack Mitigation solution: WAF and DDoS protection operate together rather than as separate systems.
How we implement
Consultation & audit
We review your infrastructure and threats. Free, under NDA.
Pilot deployment in your infrastructure
We deploy the solution in a limited segment of your infrastructure. You can evaluate the result before signing a contract.
Implementation
Deployment, AD and SIEM integration, policy tuning, team training.
Ongoing operations
24/7 SOC monitoring, reporting, security that grows with you.
What the price depends on
Pricing is calculated after the scope is defined
traffic and applicationsPricing depends on traffic volume and the number of protected web applications and APIs.
A precise quote for your infrastructure takes one call: request a quote.
Frequently asked questions
Will the WAF slow the site down?
We measure added latency before and after enabling the WAF during the pilot. Acceptable values are set for the specific application and traffic profile.
Will users get falsely blocked?
We start in observation mode and tune policies on real traffic. Blocking is enabled after critical application journeys have been tested.
Can WAF and DDoS protection be combined?
Yes. AppWall or Cloud WAF protects the web application and APIs, while DefensePro and cloud scrubbing address network and volumetric attacks. The integration design depends on the service architecture.
Tell us what to protect: we reply within one business day
The call is free of obligations: we analyse the task, propose an architecture and price it for your scale.
Or directly: +7 775 677 0259 · [email protected]
Other services: SOC · MDR · DDoS Protection · DLP · EDR · NGFW · Penetration Testing · Awareness Training · Cyber Range