Knowledge Base Hub

Browse through our helpful how-to guides to get the fastest solutions to your technical issues.

Home  >  Firewall  >  How to Prevent Cross-Site Scripting (XSS) with WAF?

How to Prevent Cross-Site Scripting (XSS) with WAF?

 4 min

Cross-site scripting attacks involve the embedding of malevolent web scripts in legitimate websites or web applications. These scripts attack web users when they load the website or the application in their browsers.

Ways in which these scripts can be used to attack users include the theft of users’ HTTP cookies or session tokens. In turn, the attacker can impersonate a legitimate user and, in full breach of trust, deface the attacked website. However, such attacks can all be avoided if a web application firewall (WAF) is deployed.

Use a Web Application Firewall

A web application firewall (WAF) can defend against attacks like XSS. WAF sits in front of web applications (operates as a reverse proxy server) and defends them by filtering and monitoring all HTTP communications.

WAF can have set rules to filter URL requests for embedded malicious scripts. Excellent WAF solutions use machine learning to defend against attempts at attack rule circumvention and other attack variations.

How Does a WAF Defend Against an XSS Attack?

Step 1: Filtering of HTTP Requests

WAF must filter all HTTP requests, including:

  • URL requests;
  • Form requests;
  • Cookies.
  • HTTP request headers;
  • JSON requests;

WAF would then search for XSS attack signatures, which would be embedded in the requests.

Example payload:

<script>alert('XSS')</script>

Step 2: Signature Detection

Most modern WAFs have a signature database of known attacks.

When a request matches a known XSS signature, a WAF will:

  • Automatically block the request,
  • Log the event,
  • Send an alert to the admins (if set up).

This serves as an initial safeguard against the most prevalent XSS techniques.

Step 3: Behavioural Analytics 

Some advanced WAFs are capable of identifying suspicious requests even if they do not match a known signature.

For example, requests that contain a high level of encoded characters, scripts that are not easily readable, or requests that have a payload with an odd structure may be security rule violations.

This method is able to identify new XSS techniques that may be incorporated in the future.

Step 4: Input Validation & Sanitization

Some WAFs implement input validation by:

  • Blocking invalid characters,
  • Removing declared harmful script elements,
  • Blocking suspicious html tags,
  • Preventing malicious event handlers.

Some of the most commonly blocked elements are:

< script >

< iframe >

< object >

onload=

onclick=

Step 5: Virtual Patch

One of the many benefits of a WAF is virtual patching.

If a XSS vulnerability is found and the application is not patched right away, the WAF will block attempts to exploit the vulnerability until the developers patch it.

That improves application security without downtime costs.

How to Configure a WAF to Protect Against XSS?

Step 1: Turn on Managed Security Rules for XSS detection, most WAFs have pre-made rules.

Here are some of the most common examples: 

  • OWASP Core Rule Set (CRS) 
  • ModSecurity Rules
  • Cloud Managed Rulesets 

These rules should be your first line of defense against XSS attacks.

Step 2: Enter Filtering Rules

Configure custom rules for high-risk user inputs, such as

  • Contact form
  • Search fields
  • Login forms
  • User-generated content areas
  • Comments sections 

These input fields are vulnerable to XSS attacks.

Step 3: Examine the Security Logs

Check WAF security logs regularly to identify:

Attacks that were attempted and were successful

  • Suspicious IPs
  • Most targeted attacked 
  • False-positive detection

Active monitoring of security logs can improve security policy.

Step 4: Get real-time alerts 

Configure alerts for: 

  • XSS blocked attempts 
  • Rules triggered
  • Unusual activity such as traffic spikes.

Trends of the same requester that are attempted repeatedly

Faster incident discovery and resolution.

Step 5: Regularly Test WAF Rules 

Regular security checks should be upgraded to WAF security.

The testing should include: 

  • Checking security vulnerabilities 
  • Penetration Testing
  • Checking rules validity
  • Perform security reviews.

Testing security and WAF regularly should be done to identify vulnerabilities before attackers do.

Best Practices Beyond WAF Protection

WAF protection is an ongoing security measure, not a one-time solution.

– Always Validate Inputs

Both client and server sides should validate inputs. Suspicious inputs should be rejected. Only formats of the expected data should be accepted.

– Use Output Encoding

User-supplied and suggested content should be removed or coded as non- executable.

– Deploy a Content Security Policy (CSP)

A Content Security Policy allows setting rules to determine which page scripts will be allowed to run, thereby limiting the potential XSS impact.

– Keep All Applications Updated

Ensure the following are always up-to-date:

  • CMSs
  • Plugins
  • Themes
  • Frameworks
  • Third-party libraries

Updating security regularly fixes many XSS vulnerability issues.

– Carry Out Security Audits Frequently

Security assessments should be regularly scheduled to find vulnerabilities before they can be exploited.

The Closing Line

XSS attacks continue to present a risk for all types and sizes of businesses. XSS will be abused for stealing user data, taking over user sessions, and ruining user trust for the business. Secure coding, validation of user inputs, and content security policies are important, but the use of Web Application Firewalls (WAFs) also helps provide an additional important protection layer. WAF can help support the other security practices by identifying and stopping bad requests to your applications.

The use of managed rule sets, careful perusal of security logs, crafting personalized filtered rule sets, using WAF, and employing secure development practices will reduce the risk associated with XSS and help protect user data while maintaining user trust in the business.

For our Knowledge Base visitors only
Get 10% OFF on Hosting
Special Offer!
30
MINS
59
SECS
Claim the discount before it’s too late. Use the coupon code:
STORYSAVER
Note: Copy the coupon code and apply it on checkout.