Build Intelligent Real-Time WAF Platform -- 2
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted1 hour ago
The goal is to create an intelligent Web Application Firewall that sits in front of my custom web applications, inspects traffic in real time, and automatically reacts to threats. The platform must excel at three core functions I have prioritised: Real-Time Threat Detection, Defensive Blocking, and Attack Analytics.
Key attack surfaces to guard against are SQL Injection, Cross-Site Scripting (XSS), and Distributed Denial of Service (DDoS). Every request should be scored, logged, and, when required, blocked or rate-limited instantly. I want to see exactly what is happening through a live security dashboard and to manage rules through a clean API that my apps can call programmatically.
Integration needs to be seamless: the WAF will be deployed in front of several custom web services, so architecture choices (reverse-proxy, inline, side-car, etc.) must not force changes inside those apps. Container-friendly deployment, secure configuration storage, and clear documentation are expected so I can roll this out across staging and production without friction.
Deliverables
• Fully functional WAF service with REST/GraphQL API for rule management and log retrieval
• Real-time dashboard that visualises threat metrics, blocked requests, and historical analytics
• Detection rules covering SQLi, XSS, and DDoS, with an extensible rule engine for future patterns
• Automated test suite demonstrating accurate detection and zero false-positive impact on legitimate traffic
• Deployment scripts (Docker / Kubernetes Helm chart or equivalent) plus step-by-step setup guide
• Handover documentation: architecture diagram, code comments, and operational run-book
Acceptance criteria
1. The WAF blocks >95 % of simulated SQLi, XSS, and volumetric DDoS attacks in an isolated test.
2. Legitimate requests incur
Key attack surfaces to guard against are SQL Injection, Cross-Site Scripting (XSS), and Distributed Denial of Service (DDoS). Every request should be scored, logged, and, when required, blocked or rate-limited instantly. I want to see exactly what is happening through a live security dashboard and to manage rules through a clean API that my apps can call programmatically.
Integration needs to be seamless: the WAF will be deployed in front of several custom web services, so architecture choices (reverse-proxy, inline, side-car, etc.) must not force changes inside those apps. Container-friendly deployment, secure configuration storage, and clear documentation are expected so I can roll this out across staging and production without friction.
Deliverables
• Fully functional WAF service with REST/GraphQL API for rule management and log retrieval
• Real-time dashboard that visualises threat metrics, blocked requests, and historical analytics
• Detection rules covering SQLi, XSS, and DDoS, with an extensible rule engine for future patterns
• Automated test suite demonstrating accurate detection and zero false-positive impact on legitimate traffic
• Deployment scripts (Docker / Kubernetes Helm chart or equivalent) plus step-by-step setup guide
• Handover documentation: architecture diagram, code comments, and operational run-book
Acceptance criteria
1. The WAF blocks >95 % of simulated SQLi, XSS, and volumetric DDoS attacks in an isolated test.
2. Legitimate requests incur
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.