← WORK 목록으로
GLOBALFreelancer서버/인프라REMOTE

Build Intelligent Real-Time WAF Platform -- 2

커스텀 웹 애플리케이션 앞단에 배치되어 실시간으로 트래픽을 검사하고 위협에 자동 대응하는 지능형 WAF(웹 방화벽) 플랫폼을 구축하는 프로젝트입니다. SQLi·XSS·DDoS 탐지 및 차단, 요청 스코어링·로깅, 실시간 보안 대시보드, 규칙 관리 REST/GraphQL API, 확장 가능한 룰 엔진을 핵심 기능으로 요구합니다. 리버스 프록시/인라인/사이드카 등 무침습적 아키텍처와 Docker/K8s 기반 컨테이너 배포까지 포함되어, 웹 보안과 인프라에 능숙한 시니어 개발자에게 적합합니다.

2026.09.04VIEW 83Freelancer에서 수집
Budget$12,500~$37,500 INR
Difficulty전문가
Duration3~5개월
Work style원격 가능
Required stack

필요 기술

PHPJavaScriptDockerKubernetesGraphQLREST APIWeb SecurityReverse Proxy
Project brief

프로젝트 내용

The goal is to create an intelligent Web Application Firewall that sits in front of my custom web applications, inspects traffic in real time, and automatically reacts to threats. The platform must excel at three core functions I have prioritised: Real-Time Threat Detection, Defensive Blocking, and Attack Analytics.

Key attack surfaces to guard against are SQL Injection, Cross-Site Scripting (XSS), and Distributed Denial of Service (DDoS). Every request should be scored, logged, and, when required, blocked or rate-limited instantly. I want to see exactly what is happening through a live security dashboard and to manage rules through a clean API that my apps can call programmatically.

Integration needs to be seamless: the WAF will be deployed in front of several custom web services, so architecture choices (reverse-proxy, inline, side-car, etc.) must not force changes inside those apps. Container-friendly deployment, secure configuration storage, and clear documentation are expected so I can roll this out across staging and production without friction.

Deliverables
• Fully functional WAF service with REST/GraphQL API for rule management and log retrieval
• Real-time dashboard that visualises threat metrics, blocked requests, and historical analytics
• Detection rules covering SQLi, XSS, and DDoS, with an extensible rule engine for future patterns
• Automated test suite demonstrating accurate detection and zero false-positive impact on legitimate traffic
• Deployment scripts (Docker / Kubernetes Helm chart or equivalent) plus step-by-step setup guide
• Handover documentation: architecture diagram, code comments, and operational run-book

Acceptance criteria
1. The WAF blocks >95 % of simulated SQLi, XSS, and volumetric DDoS attacks in an isolated test.
2. Legitimate requests incur
지원 기회 분석

지원 전에 볼 것

핵심 요구사항

  • SQLi·XSS·DDoS 실시간 탐지 및 즉시 차단/레이트리밋
  • 요청별 스코어링·로깅 및 확장 가능한 룰 엔진 설계
  • 규칙 관리·로그 조회용 REST/GraphQL API 제공
  • 실시간 위협 메트릭·차단 요청·이력 분석 대시보드
  • 무침습적 아키텍처(리버스 프록시/인라인/사이드카)로 기존 앱 수정 불필요
  • Docker/Helm 기반 컨테이너 배포 및 스테이징·프로덕션 문서화

예상 산출물

  • REST/GraphQL API를 갖춘 완전 동작 WAF 서비스
  • 실시간 위협 시각화 보안 대시보드
  • SQLi/XSS/DDoS 탐지 룰 및 확장형 룰 엔진
  • 탐지 정확도·오탐 검증 자동 테스트 스위트
  • Docker/K8s 배포 스크립트 및 아키텍처 문서·운영 런북

매력 포인트

  • 명확하고 구조화된 스펙·산출물 정의
  • 보안 전문성을 어필할 수 있는 고난도 프로젝트

확인할 점

  • 예산 단위가 모호함($와 INR 혼재, 실제 금액이 매우 낮을 가능성)
  • expert급 보안 플랫폼 요구에 비해 예산이 현저히 부족함
  • '>95% 차단·제로 오탐' 등 달성 난이도 높은 수용 기준
Client signal

클라이언트 정보

플랫폼에서 상세 정보를 확인하세요.
START THE LOOP · CHOOSE

시장과 사람의 답을 봤다면,
다음 결과물의 구조를 고릅니다.

한 번의 결과에 기대지 않고 다시 만들 수 있도록, 문제 발견부터 제작·배포·수익화까지 이어지는 전체 흐름을 익혀보세요.

TTJ CLASS에서 다음 구조 고르기 →
처리 중...