Yandex Cloud
Search
Contact UsGet started
  • Blog
  • Pricing
  • Documentation
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • ML & AI
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Customer Stories
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Education and Science
    • Yandex Cloud Partner program
  • Blog
  • Pricing
  • Documentation
© 2025 Direct Cursus Technology L.L.C.
Yandex Smart Web Security
  • Getting started
    • Overview
    • Security profiles
    • WAF
    • ARL (request limit)
    • Rules
    • Conditions
    • Lists
    • Quotas and limits
  • Access management
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Release notes
  1. Concepts
  2. Overview

Yandex Smart Web Security overview

Written by
Yandex Cloud
Updated at April 9, 2025

Yandex Smart Web Security is a service for protection against DDoS attacks and bots at application level L7 of the OSI model.

You can connect the service to Yandex Application Load Balancer virtual hosts.

Smart Web Security checks the HTTP requests sent to the protected resource via the virtual host of the L7 load balancer against the rules configured in the security profile. Depending on the results of the check, the requests are routed to the virtual host, blocked, or sent to Yandex SmartCaptcha for additional verification.

To protect your web apps from external threats, Smart Web Security also implements a Web Application Firewall (WAF).

Monitor and limit web app loads with the help of Advanced Rate Limiter (ARL).

Smart Web Security logs are sent to Yandex Cloud Logging.

Smart Web Security metrics are sent to Yandex Monitoring.

Smart Web Security audit logs are sent to Yandex Audit Trails.

Note

To enhance your security, we use HTTP request data to improve our machine learning (ML) models. You can disable the use of this information in the management console when creating a security profile or later in its settings.

Application Load Balancer coniguration recommendationsApplication Load Balancer coniguration recommendations

To enhance DDoS protection of your applications, consider these additional tips:

  • Configure autoscaling. This will allow you to dynamically adapt to the increased load and optimize traffic redistribution.
  • Place resource units in multiple availability zones.
  • Use the secure HTTPS protocol: configure a listener to automatically redirect requests from HTTP to HTTPS.
  • Ensure protection at the lower OSI model level: enable basic DDOS protection at L3 and L4 to prevent some attacks at an earlier stage.

These measures, in addition to setting up Smart Web Security, will increase the resilience of your services to potential threats and ensure security of your applications.

Was the article helpful?

Previous
Terraform
Next
Security profiles
© 2025 Direct Cursus Technology L.L.C.