UUSEC WAF is a high-performance web application firewall and API security gateway. It uses machine learning and semantic analysis to protect web applications and APIs against attacks, including zero-day threats.
The software provides defence at the traffic, system, and application runtime layers. Its semantic engines analyse SQL injection, XSS, remote code execution, and local file inclusion attacks, while its extensible rule engine supports Lua scripts and custom plugins.
This is free and open source software.
Key Features
- Machine learning based anomaly detection helps identify malicious HTTP traffic and defend against zero-day vulnerabilities.
- Three-layer protection covering the traffic, system, and application runtime layers.
- Semantic analysis engines for SQL injection, XSS, remote code execution, and local file inclusion attacks.
- Deep decoding of HTTP content including Base64, JSON, and form data.
- HIPS functionality provides host-level protection against process, network, file, privilege escalation, and system attacks.
- RASP protection integrates with runtime environments including Java JVM and PHP Zend.
- Flexible rule engine supports traditional rules and Lua script based security rules.
- Plugin architecture allows administrators to extend WAF functionality.
- Rules take effect immediately without restarting the service.
- CDN acceleration with regular expression based cache cleaning.
- Reverse proxy deployment model.
- Web-based management interface.
- Supports Let’s Encrypt certificates and automatic certificate renewal.
- Docker based deployment.
Website: github.com/Safe3/uusec-waf
Support:
Developer: UUSEC Technology
License: BSD 2-Clause License
UUSEC WAF is written in C. Learn C with our recommended free books and free tutorials.
Related Software
| Web Application Firewalls | |
|---|---|
| ModSecurity | Web Application Firewall Engine for Apache, IIS and Nginx |
| SafeLine | Self-hosted web application firewall and reverse proxy |
| BunkerWeb | Next-generation Web Application Firewall |
| NAXSI | Nginx Anti XSS & SQL Injection |
| Coraza | Enterprise grade, Golang port of ModSecurity |
| open-appsec | Automatic web application and API security using machine learning |
| UUSEC WAF | High-performance web application firewall |
| lua-resty-waf | High performance WAF built on the OpenResty stack |
Read our verdict in the software roundup.
Explore our carefully curated directory of recommended free and open source software, covering every major software category.The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more. Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form. |


Please read our Comment Policy before commenting.