Intelligent Web Application Firewall (WAF)

An AI-driven threat detection system that blocks application-layer attacks in real time, stopping SQL injection, cross-site scripting and web shells before they reach your origin.

Translucent globe marked with the locations of RockCloud scrubbing nodes worldwideClose-up of neatly routed network patch cables inside a data centre rackRows of server racks with status indicators lit inside a data centre hall

How the RockCloud intelligent WAF works

The RockCloud WAF is a web application firewall you enable with a single click in your control panel. Once it is on, even an application with known weaknesses is shielded from the vast majority of intrusion attempts.

Diagram of the intelligent WAF request flow: every request is inspected by the rule engine and the AI model, malicious requests are blocked at the edge, and only legitimate traffic is forwarded to the origin server

RockCloud runs the OWASP Core Rule Set (CRS), which is designed to mitigate the most common web application vulnerabilities, including the OWASP Top 10, such as:

  • SQL injection (SQLi)
  • Cross-site scripting (XSS)
  • Local file inclusion (LFI)
  • Remote file inclusion (RFI)
  • PHP code injection
  • Java code injection
  • HTTPoxy proxy header injection
  • Shellshock
  • Unix and Windows shell command injection
  • Session fixation
  • Malicious script, scanner and bot detection
  • Metadata and error message leakage

Paired with the RockCloud AI engine, machine learning surfaces malicious requests that no signature covers yet, so novel attacks are blocked the first time they appear.

If you need custom rules, targeted exceptions or a heuristics-based policy for your workload, you are welcome to talk to our security engineering team

Turn on the intelligent WAF for your site