Specialized firewall for web applications, acting as a primary shield between a web application and the internet. Located at the outer edge of the network, at the application layer (layer 7 of the OSI model). Protects web servers by filtering, monitoring, and blocking malicious HTTP and HTTPS traffic. When properly configured, it helps preventing attacks like SQL injection, cross-site scripting (XSS), and HTTP protocol violations. As a bonus, WAFs often come with out-of-the-box OWASP Top 10 mitigation capabilities. WAF extended info About the OSI model