How to Protect Your REST API with a Free WAF

작성자

카테고리:

← 피드로
DEV Community · Lia · 2026-08-07 개발(SW)

Lia

Why APIs Need Different Protection

Web form attacks (SQLi, XSS) target HTML endpoints. API attacks are different — they exploit JSON bodies, GraphQL queries, auth tokens, and rate limits. Your API needs protection that understands these attack vectors.

API-Specific Threats

Threat What It Looks Like Without WAF GraphQL deep queries {users{posts{comments{author{email}}}}} Server CPU exhaustion BOLA (Broken Object Level Auth) GET /api/users/12345 when you own user 67890 Data leak Mass assignment {"role":"admin"} in a user update payload Privilege escalation JWT replay / none algorithm Manipulated tokens without server-side validation Auth bypass API rate abuse 10,000 req/min to /api/search Server crash

Setting Up SafeLine for API Protection

# 1. Deploy SafeLine behind your API gateway
bash -c "$(curl -fsSLk https://waf.chaitin.com/release/latest/manager.sh)" -- --en

# 2. Add your API domain as a site
# Domain: api.yourdomain.com
# Backend: localhost:3000 (your API server)

# 3. Create custom rules for API protection
# Rule 1: Block requests without proper Content-Type for POST/PUT
# Rule 2: Limit request body size (prevent large payload attacks)
# Rule 3: Rate limit per API key (not just per IP)

Enter fullscreen mode Exit fullscreen mode

Rate Limiting for API Endpoints

The most effective API protection you can set up in 5 minutes:

Endpoint: /api/*
Limit: 100 requests/minute per IP
Action: Block with 429 status

Endpoint: /api/auth/*
Limit: 10 requests/minute per IP
Action: Block with 429 + captcha challenge

Endpoint: /api/search
Limit: 30 requests/minute per IP
Action: Throttle

Enter fullscreen mode Exit fullscreen mode

SafeLine’s semantic engine also catches injection attempts in JSON bodies, GraphQL queries, and URL parameters — the same 71.65% detection rate applies to API traffic.

What SafeLine Detects in API Traffic

  • SQL injection in JSON body fields
  • NoSQL injection targeting MongoDB endpoints
  • Command injection in query parameters
  • SSRF via URL parameters that resolve to internal IPs
  • Path traversal in file upload endpoints
  • XML External Entity (XXE) attacks

FAQ

Does the WAF add latency to API calls?

About 1ms per request (measured on a 2GB VPS). For an API that already takes 50-200ms to process a request, this is negligible. The security gain far outweighs the 1ms cost.

Can I whitelist certain API endpoints?

Yes. Create a whitelist rule for health check endpoints (/health, /ping) or webhook receivers that need to accept large payloads. Everything else gets full inspection.

What about authenticated vs unauthenticated API routes?

Create separate rate limit rules for authenticated (higher limits) vs unauthenticated (lower limits) endpoints. SafeLine can distinguish them by the presence of Authorization headers.

Try SafeLine Community Edition — free, self-hosted, and takes 5 minutes to deploy:

bash -c "$(curl -fsSLk https://waf.chaitin.com/release/latest/manager.sh)" -- --en

Enter fullscreen mode Exit fullscreen mode

Dashboard: https://<your-server-ip>:9443 | Docs

What API endpoints are you exposing right now without WAF protection?

원문에서 계속 ↗

코멘트

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다