Web Application Firewall (WAF)
A web application firewall (WAF) inspects HTTP requests to web applications and APIs and blocks those that match attack patterns, such as SQL injection, cross-site scripting or known exploits.
A WAF sits between users and the application, usually inside a CDN or cloud load balancer. It evaluates each request against rule sets: vendor-managed rules for common attacks, plus custom rules the security team writes.
WAFs have existed for about 30 years, and the core model has changed little. The hard part is not deploying one but keeping its rules accurate as applications change, which is why many WAFs end up in log-only mode or full of exceptions.
Where Huskeys fits
Huskeys doesn't replace a WAF; it measures how well each WAF is working and tunes its rules per application.
