Alibaba Cloud WAF Benefits
Professional, Stable, and End-to-end Solution to the Major Security Pain Points of Web Applications
Professional: provides Alibaba Cloud-developed rules, AI-based deep learning, and proactive protection rules, and allows you to create custom rules.
Stable: enables multi-line and multi-node disaster recovery and intelligent routing, protects services that have millions of QPS, and enables millisecond-level responses.
Timely: automatically detects and defends against the latest web vulnerabilities, including zero-day vulnerabilities first exposed by Alibaba Cloud, within hours.
Comprehensive: delivers end-to-end protection against vulnerabilities, web attacks, and bot traffic, ensures data and account security, and meets the requirements of security O&M.
Compliant: complies with the requirements of classified protection and PCI DSS, and boosts security compliance construction for enterprises.
Exclusive threat intelligence: provides exclusive network-wide threat intelligence, which is accumulated and updated from the real service scenarios of Alibaba Cloud.
The Only Chinese Vendor That Receives Full Recognition for Web Application Firewalls
Recognized by international authorities:WAF is recognized by Gartner, Forrester, IDC, and Frost & Sullivan.
Recognized by the market: A report of Frost & Sullivan shows that Alibaba Cloud WAF ranks first in the cloud WAF market in Greater China.
Extensive experience: WAF protects core services of Alibaba Cloud and accumulates a large amount of attack and defense experience from Tmall and Taobao Double 11 events over the years.
Multi-scenario Deployment and Flexible Access
Multi-scenario deployment: You can deploy WAF in the cloud or deploy protection clusters in your data centers to meet the requirements of different scenarios, such as public clouds, hybrid clouds, and data centers. Both Alibaba Cloud and third-party clouds are supported. WAF delivers the same protection capabilities for services in the cloud and in data centers.
Flexible access: You can connect Alibaba Cloud SLB, CDN, and ECS to WAF with a few clicks, and quickly configure the DNS records for your services that are deployed in data centers.
WAF Editions
WAF is available in all regions in mainland China. WAF is also available in the following regions: China (Hong Kong), Singapore (Singapore), Malaysia (Kuala Lumpur), US (Silicon Valley), Australia (Sydney), Germany (Frankfurt), Indonesia (Jakarta), UAE (Dubai), and Japan (Tokyo).
* PayPal is not supported for Alibaba Cloud Pay-as-you-go Free Trial. Learn more>
Pay-as-you-go
This edition is suitable for web applications that are deployed on Alibaba Cloud or whose service traffic will be forwarded to Alibaba Cloud.
- Your bills are generated on a daily basis
- You can use resource plans to offset fees
Subscription
This edition is suitable for web applications that are deployed on Alibaba Cloud or whose service traffic will be forwarded to Alibaba Cloud
- Prepay for subscription on monthly or yearly
- Suitable for fixed budget
Hybrid Cloud WAF
The Hybrid Cloud Exclusive edition is suitable for web applications that cannot forward traffic to Alibaba Cloud and require protection clusters to be deployed in data centers
- Delivers the same protection capabilities for services in the cloud and in data centers
- Allows online scaling and provides flexible and stable services
Alibaba Cloud WAF Scenarios
Security Capabilities Required for Migrating Web Applications to the Cloud
Automatically fixes zero-day vulnerabilities on your web applications. You do not need to manually patch and fix the vulnerabilities. WAF prevents your web applications such as websites, HTML5 pages, apps, and mini programs from being attacked and against virus intrusion in an efficient manner. WAF mitigates attacks such as trojans, web tampering, malicious bots, data leaks, and HTTP flood attacks.
Scenarios
-
Prevents common web attacks, such as SQL injections, XSS attacks, webshell uploads, directory traversals, and backdoors.
Prevents attackers from using zombie servers to launch HTTP flood attacks.
Automatically fixes zero-day vulnerabilities at the earliest opportunity by using virtual patching. This avoids code rewrite, which is difficult and time-consuming.
Proactively discovers APIs of the earlier versions, and APIs that lack the authentication mechanism and throttling policies. This helps reduce data leak risks.
Automatically blocks unauthorized scanning and detection activities.
Related Services
Prevention of Fraud and Promotion Abuse
Business operations may generate volumetric traffic, which affects system availability. In addition, promotion abuses always occur. These all affect and even have negative impacts on the business operations. Alibaba Cloud provides you with a complete solution to handle risks on business operations. The solution is based on years of experience on business operations.
Scenarios
-
Ensures system stability during business operations and prevents issues such as website freezing and system failures caused by bot traffic.
Prevents promotion abuse and fraud to ensure that real customers benefit from promotions.
Mitigates data crawling and avoids excessive bandwidth fees caused by data crawling.
Related Services
Hybrid Cloud WAF Solution
Deploys protection clusters in data centers to protect web services that are deployed across public clouds and data centers. Both Alibaba Cloud and third-party clouds are supported. You can use the Alibaba Cloud WAF console to control and perform O&M on the services.
Scenarios
-
Services that are latency-sensitive, require high availability, and demand zone-disaster recovery, geo-disaster recovery, and centralized protection across multiple network environments.
Web services that cannot be deployed on Alibaba Cloud or protected by WAF.
Web services that are deployed in the private network of the cloud or data centers.
Related Services
Related Resource
Blog
Alibaba Cloud Provides Proven Data Security Solution to Empower UAE E-Commerce Platform
Leading UAE-based Asian supermarket chain WEMART taps Alibaba Cloud’s trusted security solution against cyber threats.
Web Application Firewall Demo
Solution
Cloud Security Solution
Safeguard business security, application security, data security, infrastructure security, and account security with Alibaba Cloud's powerfull security toolset.
End-to-end Enterprise Security in the Cloud
Meets the requirements of data security, platform security, and the security of your new applications or migrated applications. WAF allows you to view and understand the security posture of your services in a convenient manner.
Learn More