Web Application Firewall (WAF) is a one-stop, AI-based risk prevention solution for web business operations. It identifies malicious traffic using AI and rule engines to protect websites, enhancing overall security and reliability. By leveraging bot behavior analysis, it defends against malicious access requests and safeguards critical website services and data.
Converge Cloud provides an on-cloud WAF called CLB WAF, which offers robust protection through seamless integration with the Converge Cloud CLB cluster.
- CLB WAF works by mirroring HTTP/HTTPS traffic from CLB instances to the WAF cluster. The WAF performs real-time threat detection and cleansing, then synchronizes trusted request statuses back to the CLB cluster. This ensures that malicious traffic is blocked while legitimate requests are allowed, providing continuous and reliable website protection.
Converge Cloud WAF effectively prevents SQL injection, cross-site scripting (XSS), trojan uploads, unauthorized access, and other OWASP security risks. It also offers comprehensive protection against CC attacks, provides zero-day vulnerability patching, and helps prevent webpage tampering.
| Feature | Description |
|---|---|
| AI + WAF | Web attack recognition is based on AI + rules, offering anti-bypass capability with low false negative and false positive rates. It effectively defends against common web attacks, including the OWASP Top 10 threats such as SQL injection, unauthorized access, cross-site scripting (XSS), cross-site request forgery (CSRF), and web shell trojan uploads. |
| Virtual zero-day vulnerability patching | The 24×7 Converge Cloud Security Team proactively identifies and responds to vulnerabilities. Within 24 hours, it issues virtual patches for zero-day and high-risk web vulnerabilities. Protected users receive instant and automatic protection, significantly reducing vulnerability response time. |
| Web tampering protection | Core web content can be cached to the cloud and published as substitute pages, preventing negative consequences from web page tampering. |
| Data leakage protection | Backend data is safeguarded through a three-phase defense strategy — pre-event server and application concealment, mid-event attack prevention, and post-event sensitive data replacement and concealment. |
| CC attack protection | Smart CC protection automatically generates defense policies based on real server anomalies (e.g., timeouts, delays) and behavioral big data analysis. It supports multi-dimensional access control, intelligent filtering of malicious requests, and defense measures such as CAPTCHA and frequency control. |
| Crawler and bot traffic management | The AI + rules-based bot management system prevents risks from malicious bots such as data scraping, content infringement, price comparison, inventory crawling, malicious SEO, and strategy leakage. |
| 30 BGP lines for access protection | With 30 dedicated BGP lines across protective nodes, WAF enables smart node scheduling to reduce access latency and ensure fast, stable connections — delivering strong cloud-based security without sacrificing performance. |
Why WAF
Web Application Firewall (WAF) can effectively protect enterprise websites and business systems in the following use cases:
Data leakage (leakage of core information assets)
A website is the entry to enterprise information assets and may be hacked for asset theft, causing incalculable losses to enterprises.Malicious access and data crawling (unavailability and data utilized by competitors)
Hackers control botnets to launch CC attacks on a website, which will consume all its resources and makes it unavailable. Malicious users scrape core content of websites (blog, recruitment, forum, and e-commerce websites) by using web crawlers.
For example, e-commerce offering details are crawled by competitors for analysis, and low-price offering information is crawled or promotion intelligence is obtained before sales campaigns by bargain hunters for their benefits.Network trojans and tampering (affecting credibility and image)
After obtaining website or server permissions, attackers can inject malicious code to make users execute malicious programs, drive traffic, steal accounts, and show off. They may also implant links to pornographic, gambling, and illegal information or tamper with the images and texts on the website, adversely affecting website operations, undermining the credibility, and damaging the image.Framework vulnerability (attacks during patching)
Many web systems are based on common open-source frameworks such as Structs 2, Spring, and WordPress, which are prone to security vulnerabilities. A lot of attacks will emerge just one day after the vulnerabilities are discovered, making patching extremely hard.Business interruption due to high-traffic DDoS attacks
DDoS attacks have become a cost-effective and easy way to interrupt the business of competitors or make their key portals inaccessible. These attacks have severe impact on business continuity and brand image. More often than not, companies are very passive when attacked.