Essentially, WAF provides all your web applications a secure solution which ensures the data and web applications are safe. A web application firewall applies a set of rules to HTTP conversation to identify and restrict the attacks of cross site scripting, SQL injections etc. You can also get web application framework and web based commercial tools, for providing security to web applications. Web Application Firewalls allows you to customize the rules by identifying and blocking malicious content. ESAPI WAF is developed by Aspect Security and it is designed to provide protection at the application layer instead of network layer. Binarysec is web application software firewall, and it protects applications against illegitimate HTTP and blocks suspicious requests as well. HTTPS traffic to protect the web application from external attacks.

Art of defense is a San Francisco based web application security provider which started a project on open source OpenWAF in February 2011. Qualys created cloud based open source web application firewall – Ironbee which examines the HTTP instead of the traditional IP packets to evaluate a data. It can even track attacks on cross site scripting code. Smoothwall provides strong web security tools to manage emails. It has flexible user rules and a fully integrated component for web filtering and security. Internet based protection is also provided by companies which provide security at the network layer with features such as packet filter.

Besides, there are some other types of firewalls which are designed to ensure security of the database. Therefore, the criteria for selecting an open source WAF should be the types of vulnerabilities the WAF can prevent and the exact requirements that your company is having. Hope you found this list useful! What is your experience with WAF? Please don’t forget to share with me in comments. It shows, how to open text document in notepad, how to open image in a default viewer or how to open url address in a default web browser.

