Yandex Smart Web Security

A service for protecting web applications.

Anti-DDoS protection at the application level

Protection from DDoS attacks at the OSI model L7 application level. Allows you to protect yourself from attacks aimed at exhausting system resources and disrupting application operations.

Anti-bot protection

Analysis, detection, and blocking of illegitimate automated queries. For example, protection against bots that create a parasitic load on web resources, spam, or content parsing.

Simple connection

Connect to Yandex Application Load Balancer in just a few clicks. Create a preset profile with full protection, or a custom profile to meet your specific needs.

Built-in monitoring and logging

Use the service not just to block illegitimate requests, but also to log and analyze incoming traffic. You can use built-in Yandex Cloud tools to monitor traffic and log events. Visual traffic data and send it to third-party analytics systems like SIEM.

Flexible traffic filtration

Choose how to react to various traffic categories. Filter traffic by IP address or geographic features, set conditions for any HTTP request parameter. Send traffic for full analysis or allow certain automated requests for resources running through the API.

Web Application FirewallPreview

This firewall protects web apps against exploiting vulnerabilities, including those in OWASP TOP‑10. This firewall is also protected against DDoS attacks.

Get started

Create a security profile and connect is to an L7-balancer.

Proprietary Smart Protection technology

The system uses ML models trained on years of DDoS protection data from Yandex web resources.

The service analyzes traffic with ML algorithms and behavioral analysis to:

  • Block attacks, abnormal and illegitimate requests.
  • Send suspicious requests to Yandex SmartCaptcha.

Use Smart Web Security in your projects

Protect web applications from DDoS attacks

Protext web applications by analyzing incoming traffic, detecting and blocking abnormal requests. With integration with Yandex SmartCaptcha, the service can, when necessary, verify that your visitors are humans and not robots.

Protect your API from DDoS attacks

Use Smart Web Security to protect your web resources and API. The service analyzes incoming traffic, blocking illegitimate requests and accepting automated requests that you expect.

Filtration of incoming traffic

Use filtration rules to control which queries to your web resource to block, and which to accept. Permit, for example, requests from specific regions, subnets, or groups of devices.

FAQ

Smart Web Security is designed to protect web applications from DDoS attacks and bots at the L7 level, including content parsing.

For protection from DDoS attacks at the L3 and L4 levels, use the Yandex DDoS Protection service.