Stable & Intelligent

Enables remote disaster recovery with intelligent scheduling and optimal access; supports resolution on the cloud; deploys within seconds.


Allows you to define your own application-specific protection rules to accurately intercept attacks and reduce misreports, perfect for various industries.

360 Degree

Professional security teams provide 24/7 monitoring. With comprehensive protection configuration, WAF can defend against latest 0-day vulnerabilities.


Supports automatic upgrade on the cloud; detects potential threats and sets up multi-dimensional defense systems in collaboration with other security services.

Application Scenarios

  • Data Leakage

  • 0-Day Vulnerabilities

  • CC Attacks

  • Web Page Tampering

Data Leakage

Data Leakage

Malicious visitors use such methods as SQL injection and webshells to intrude website databases and steal service data or other sensitive information.


  • Precise Identification

    Uses semantic analysis & regex to examine traffic from different dimensions, precisely detecting attacking traffic.

  • Distortion Attack Detection

    Supports seven ways to restore codes so that more types of distortion attacks can be detected, preventing WAF from being bypassed.

Related Services



0-Day Vulnerabilities

0-Day Vulnerabilities

In cases of 0-day vulnerabilities in third-party frameworks or plug-ins, WAF provides 360-degree protection using virtual patches against attacks that may exploit these vulnerabilities.


  • Swift Response

    Responses, including delivering virtual patches and updating the rule library, to vulnerabilities even before vendors can take action

  • Lower Cost

    Lower deployment and O&M costs resulting from service upgrades, avoiding service interruption

Related Services



CC Attacks

CC Attacks

If a large number of malicious CC attacks are initiated, core resources are occupied for an extended period of time, causing low website response or service interruption.


  • Flexible Configuration

    Allows you to flexibly set rate limiting policies by IP address or cookie, precisely detects CC attacks, and facilitates stable service running.

  • Interface Customization

    Allows you to configure response actions and content of returned pages to meet your particular needs.

Related Services




Web Page Tampering

Web Page Tampering

Attackers leave backdoors on website servers or tamper with web page content, causing asset loss or negative impact.


  • Website Malicious Code Detection

    Detects malicious codes injected to the website server, protecting security of website visitors.

  • Protection Against Web Page Tampering

    Prevents attackers from tampering with or changing web page content or publishing indecent information that can damage the website's brand.

Related Services




Web Attack Defense

Thoroughly detects and blocks OWASP common threats, including malicious scanners, IP addresses, and webshells.

  • Complete protection

    Detects and intercepts attacks, including SQL injection, XSS, file inclusion, directory traversal, sensitive file access, command/code injection, webshell uploads, and third-party vulnerability exploits.

  • Precise identification

    Uses semantics analysis & regex dual engines and supports common code restoration methods, reducing misreporting and enhancing capabilities of detecting distortion attacks.

CC Attack Defense

Limits rate over interfaces and uses man-machine identification, mitigating impact of CC attacks (such as HTTP flood).

  • Fine-grained flexibility

    Allows you to flexibly set rate limiting policies by IP address and cookie.

  • Returned page customization

    Enables you to address diversified needs with customizable content and types of returned pages.

Visualized Security

Provides a user-friendly GUI to allow you to view attack information and event logs in real-time.

  • Centralized policy configuration

    Central on-console configuration, rapid delivery, and immediate implementation of policies

  • Traffic & event statistics

    Real-time information provided, such as access times, numbers and types of security events, and logs

Access Control

Offers precise and powerful access control policies based on combinations of parameter and logics conditions.

  • Rich variety of parameter conditions

    Based on condition combinations of common HTTP parameters such as IP, URL, Referer, User-Agent, and Params

  • Various logics conditions

    Blocking or releasing based on logics conditions such as "Include", "Exclude", "Equal to", "Not equal to", "Prefix is", and "Prefix is not"

Create an Account and Experience HUAWEI CLOUD for Free

Register Now