Service · Cybersecurity

Web application firewall (WAF)

An online shop faces the entire internet around the clock, and automated scanners find it within days of going live. A web application firewall turns away the routine attacks before they reach your code, whether the site runs on WooCommerce, PrestaShop, Magento or a platform written for you. The hard part is not blocking: it is blocking without also turning away your customers, the callbacks from your payment provider and the feed that goes to your order-handling tool.

Learning
always before enforcement
OWASP
the ten major risks as a baseline
Virtual patch
a rule while the fix is written
Report
what was stopped, and under which rule

Where this service reaches

This kind of filter is no substitute for careful code, it buys time: the flaw announced this morning is closed by a rule today and corrected in the code at the next release.

Put your scope to an engineer

Attack filtering

Known techniques are blocked: injection into queries, scripts executed in the visitor's browser, walking up the file tree, and attempts to reach administration directories.

Login protection

Attempt limits on the site administration and on customer accounts, plus protection for the password reset form against being fired in bulk.

Bots

The search engines and comparison sites you work with come through. Price scrapers, bots testing stolen card numbers and scripts that hold stock in a basket stay outside.

Virtual patching

A vulnerability announced in a module is closed by a rule before the fix even ships, which happens more often than anyone would like with the most widely used extensions.

Exceptions for your flows

Callbacks from Stripe, PayPlug, Lyra or Mollie, notifications from Colissimo, Chronopost or Mondial Relay and the link to your back-office tool get precise exceptions, so orders do not sit frozen awaiting payment.

Reporting

What was stopped, where it came from and under which rule, in a periodic summary the shop owner can also read.

The way an engagement runs

Most of the trouble this kind of filter causes appears in the first few days, which is why we never begin in blocking mode.

01

Analysis

Platform, forms, customer accounts, payment methods and integrations. We write down everything that legitimately connects to the site.

02

Learning

The filter watches without blocking and builds a picture of real traffic, covering a full weekend and a promotion if the calendar allows.

03

Tuning

We remove the false positives. A live shop always has some, most often in the internal product search and in the admin area.

04

Enforcement

Protection switched on, alerting configured and a regular event review, with a particular look before the sales season and before the year-end peak.

The worst moment to switch on a web application firewall is the week before a big promotion. Traffic is abnormal exactly then, and every false positive is an abandoned basket. Put in place several weeks ahead, the same filter has had time to learn the shop and spends the peak stopping bots rather than customers.

Questions and answers

Rarely. Most hosted services run alongside a delivery network that serves images and scripts from a point near the visitor, so pages can even load faster. The inspection itself is measured in milliseconds and stays invisible to the buyer.

On that kind of offer the provider runs the infrastructure and the reach of their protection is set out in their terms of service, so a filter of your own generally has no place. We look after what stays with you: administrator accounts, strong authentication, the rights of connected apps and the modules you install.

After the learning phase and rule tuning, whose length follows traffic volume: a busy shop gives a reliable picture in a fortnight, a quiet site takes longer. Obvious rules, against a known flaw in a module for instance, are switched on straight away.

They see a page carrying an event reference. With that number we find the rule in the logs and correct it, usually within the hour. After the initial tuning such cases become rare, and the periodic report shows whether they are creeping back up.

Put a filter in front of your shop

Tell us which platform runs your site or portal and what it is connected to. We will propose a type of filter and a plan for switching it on.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.