ABSTRACT

Furthermore, WASC classifies WAF as “a new breed of information security technology designed to protect Websites from attack. WAF solutions are capable of preventing attacks that network firewalls and intrusion detection systems can’t, and they do not require modification of application source code.”†

In this chapter, we will push the concept of WAF to “protect the information processed by Web applications from Web-based attacks,” present some typi-

Contents 6.1 Introduction ...............................................................................................73 6.2 The Security Layers ....................................................................................74 6.3 WAF Operating Modes ..............................................................................76