{"id":26944,"date":"2023-05-17T16:51:58","date_gmt":"2023-05-17T08:51:58","guid":{"rendered":"https:\/\/www.exabytes.sg\/blog\/?p=26944"},"modified":"2023-05-17T16:51:58","modified_gmt":"2023-05-17T08:51:58","slug":"web-application-firewall-waf-security-control","status":"publish","type":"post","link":"https:\/\/www.exabytes.sg\/blog\/web-application-firewall-waf-security-control\/","title":{"rendered":"Web Application Firewall: Your Impenetrable Fortress of Security Control"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-26945 size-large\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=696%2C364&#038;ssl=1\" alt=\"web application firewall WAF security control\" width=\"696\" height=\"364\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=1024%2C536&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=300%2C157&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=768%2C402&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=696%2C364&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=1068%2C559&amp;ssl=1 1068w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=218%2C114&amp;ssl=1 218w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?resize=803%2C420&amp;ssl=1 803w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?w=1200&amp;ssl=1 1200w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">A <a href=\"https:\/\/www.exabytes.sg\/web-security\/cloudflare-web-performance-booster\">Web Application Firewall<\/a> (WAF) is a form of security control that protects websites and web applications from cyberattacks. Essentially, a WAF is similar to a doorman at an exclusive club who decides who goes in and who does not. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">It functions by analyzing the traffic between the internet and the web application and blocking any suspicious activity. In contrast to traditional firewalls, which are designed to protect networks, WAFs are primarily concerned with web-based attacks. <\/span><\/p>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/en.wikipedia.org\/wiki\/Runtime_application_self-protection\" rel=\"noopener\">Runtime Application Self-Protection<\/a> (RASP) is a more recent technology that detects and blocks assaults in real-time, as they occur within the application itself.<\/span><\/p>\n<h2><b>Web Application Firewall (WAF) &#8211; What is it?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A web application firewall or WAF aids in the protection of web applications by filtering and monitoring HTTP traffic between a web application and the Internet. It typically protects web applications from a variety of attacks, including cross-site forgery, cross-site scripting (XSS), file inclusion, and <a href=\"https:\/\/www.exabytes.sg\/web-security\/sucuri-website-security\">SQL injection<\/a>. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">A WAF is a defense at protocol layer 7 (in the OSI model) and is not designed to defend against all forms of attack. Typically, this technique of attack mitigation is part of a suite of tools that, when combined, provide comprehensive defense against a variety of attack vectors.<\/span><\/p>\n<h2><b>What is the function of a web application firewall (WAF)?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A WAF safeguards your web applications by filtering, monitoring, and barring any malicious HTTP\/S traffic traveling to the web application and preventing any unauthorized data from leaving the application. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">It accomplishes this by adhering to a set of policies that assist in determining which traffic is malicious and which is secure. In the same way that a proxy server functions as an intermediary to protect the identity of a client, a WAF acts as an intermediary to protect the web application server from a potentially malicious client. This is known as a reverse proxy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">WAFs can be implemented as software, a hardware appliance, or as a service. Policies can be modified to accommodate the specific requirements of your web application or collection of web applications. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Although many WAFs require regular policy updates to address new vulnerabilities, machine learning advancements enable some WAFs to update themselves. This automation is becoming more crucial as the complexity and ambiguity of the threat landscape continue to increase.<\/span><\/p>\n<h2><b>What is the Difference Between a WAF and a Firewall?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">A web application firewall (WAF) is designed to safeguard the application layer by analyzing each HTTP\/S request at the application layer. It is typically aware of the user, session, and application, as well as the web applications and services they support. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Because of this, you can consider a WAF to be the intermediary between the user and the app, analyzing all communications before they reach either the app or the user. Traditional WAFs ensure that only permitted actions (based on security policy) are allowed. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">WAFs are the first line of defense for applications in many organizations, particularly for protection against the <a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" rel=\"noopener\">OWASP Top 10<\/a> \u2014 the foundational list of the most common application vulnerabilities.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Currently included in this list&#8217;s Top 10 are:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Injection offensives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Invalid Access restriction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sensitive data disclosure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Insecure configurations<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cross-Site Scripting (XSS)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Invalid Authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XML External Entities (XXE)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Insecure Deserialization<\/span><\/li>\n<\/ul>\n<h2><b>Web Attacks Compared to Unauthorised Access<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">WAF solutions safeguard organizations from web-based attacks that target applications. Without an application firewall, web application vulnerabilities would allow criminals to breach the network. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">WAF security solutions safeguard enterprises against common web attacks, including:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.exabytes.sg\/web-security\/sucuri-website-security\">DDoS<\/a>: Direct denial-of-service is an attempt to disrupt a network, service, or server by flooding it with an excessive amount of internet traffic. It seeks to deplete the resources of its target and can be difficult to defend against because the traffic is not always obviously malicious.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection: SQL injection is a form of injection attack that allows hackers to execute malicious SQL statements that control the database server underlying a web application. This allows attackers to circumvent webpage authentication and authorization, retrieve the SQL database&#8217;s contents, and modify or delete its records. Using a SQL injection, cybercriminals can gain access to consumer information, personal data, and intellectual property. In 2017, the OWASP Top 10 ranked it as the number one threat to web application security.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.exabytes.sg\/blog\/wordpress-security-vulnerabilities\/\">Cross-site scripting<\/a>: A web security flaw that allows attackers to compromise user interactions with web applications. It allows the perpetrator to circumvent the same-origin policy, which separates websites by origin. As a result, the perpetrator can impersonate a legitimate user and access the data and resources to which they have access.<\/span><\/li>\n<\/ul>\n<h2><b>Network Traffic <\/b><b>Compared to <\/b><b>Application Traffic<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Traditional network firewalls limit or prevent unauthorized network access. The firewall policies define the network traffic that is permitted, and all other access attempts are blocked. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">This helps prevent network traffic from unauthorized users and assaults from users or devices in less secure zones.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A WAF targets application traffic specifically. It safeguards <a href=\"https:\/\/www.exabytes.sg\/blog\/https-vs-http\/\">HTTP and HTTPS<\/a> traffic and applications in internet-accessible network zones. This protects businesses from threats such as <a href=\"https:\/\/www.exabytes.sg\/web-security\/sucuri-website-security\">cross-site scripting (XSS)<\/a>, distributed denial of service (DDoS), and SQL injection attacks.<\/span><\/p>\n<h2><b>Protection at Layer 7 as opposed to Layers 3 and 4<\/b><\/h2>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" class=\"alignnone wp-image-26834 size-full\" src=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=696%2C522&#038;ssl=1\" alt=\"Open Systems Interconnection (OSI) model\" width=\"696\" height=\"522\" srcset=\"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?w=1024&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=300%2C225&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=768%2C576&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=696%2C522&amp;ssl=1 696w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=152%2C114&amp;ssl=1 152w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=560%2C420&amp;ssl=1 560w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=80%2C60&amp;ssl=1 80w, https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/Open-Systems-Interconnection-OSI-model.jpg?resize=265%2C198&amp;ssl=1 265w\" sizes=\"(max-width: 696px) 100vw, 696px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The principal technical distinction between application-level and network-level firewalls is the security layer they operate on. Open Systems Interconnection (OSI) is a model that identifies and standardizes communication functions within telecommunication and computing systems.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">WAFs protect against intrusions at Layer 7 of the OSI model, which is the application level. This includes cookie manipulation, SQL injection, and URL attacks, as well as attacks against applications such as Ajax, ActiveX, and JavaScript. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition, they target the web application protocols HTTP and HTTPS, which connect web browsers and web servers.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A Layer 7 DDoS attack, for instance, sends a deluge of traffic to the server layer, where web pages are generated and delivered in response to HTTP requests. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">A WAF mitigates this by functioning as a reverse proxy to protect the targeted server from malicious traffic and filtering requests to identify DDoS tools.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Layers 3 and 4 of the OSI model are utilized by network firewalls to safeguard data transfer and network traffic. This includes Domain Name System (DNS) and File Transfer Protocol (FTP) attacks, along with Simple Mail Transfer Protocol (SMTP), Secure Shell (SSH), and Telnet attacks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Amazon Web Services (AWS) and Cloudflare both offer Web Application Firewall (WAF) services.<\/span><\/p>\n<h2><b>AWS vs. Cloudflare | <\/b><b>Comparing WAF pricing and features\u00a0<\/b><\/h2>\n<table>\n<thead>\n<tr>\n<th>Features<\/th>\n<th>AWS WAF<\/th>\n<th>Cloudflare<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Cost<\/td>\n<td>No initial cost, $20\/month<\/td>\n<td>Free plan available, affordable pricing tiers<\/td>\n<\/tr>\n<tr>\n<td>Deployment<\/td>\n<td>Easy configuration, managed rules<\/td>\n<td>Quick installation, customization options<\/td>\n<\/tr>\n<tr>\n<td>Services<\/td>\n<td>Web application firewall<\/td>\n<td>CDN, WAF, load balancing (depending on plan)<\/td>\n<\/tr>\n<tr>\n<td>Installation Speed<\/td>\n<td>Minutes<\/td>\n<td>Minutes to days<\/td>\n<\/tr>\n<tr>\n<td>Customizability<\/td>\n<td>Highly customizable<\/td>\n<td>Customization options available, but less than AWS WAF<\/td>\n<\/tr>\n<tr>\n<td>Security Attacks<\/td>\n<td>Application layer attacks only<\/td>\n<td>DDoS attack protection, additional WAF functions<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><b>AWS Web Application Firewall<\/b><\/h3>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/d2908q01vomqb2.cloudfront.net\/17ba0791499db908433b80f37c5fbc89b870084b\/2021\/07\/01\/FioriWAF_Picture_1.png?w=696&#038;ssl=1\" alt=\"Securing SAP Fiori with AWS WAF (Web Application Firewall) | AWS for SAP\" \/><\/p>\n<p><span style=\"font-weight: 400;\">AWS WAF is a web application firewall provided by AWS, the market leader in cloud services worldwide. It is primarily used to secure websites from web application attacks. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The seventh layer (application layer) of the OSI reference model must be protected. AWS WAF possesses the following attributes:<\/span><\/p>\n<h4><strong>1. Cost efficiency<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">While other WAF products may have an initial cost of thousands of dollars, AWS WAF has no initial cost and an ongoing cost of approximately $20 per month, making it very affordable.<\/span><\/p>\n<h4><strong>2. Easy deployment<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">If you have a basic understanding of security, you can configure it with a few clicks. And if you lack security expertise, you can begin with &#8220;Managed Rules&#8221; for AWS WAF, the defensive rules supplied by security-specific vendors in the AWS marketplace. These &#8220;managed rules&#8221; are also extremely inexpensive.<\/span><\/p>\n<h3><b>Cloudflare<\/b><\/h3>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.cloudflare.com\/img\/learning\/ddos\/glossary\/waf\/waf.png?w=696&#038;ssl=1\" alt=\"DDOS How A WAF Works\" \/><\/p>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.exabytes.sg\/web-security\/cloudflare-web-performance-booster\">Cloudflare<\/a> is a CDN (Content Delivery Network) service offered by Cloudflare, Inc. A Content Delivery Network (CDN) is a service that caches (temporarily stores) images and text displayed by Web applications all over the globe.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Let&#8217;s examine the benefits of using Cloudflare.<\/span><\/p>\n<h4><strong>1. Affordability<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">Cloudflare offers four distinct plans: Free, Pro, Business, and Enterprise. Although the free plan&#8217;s features are quite limited, you can begin using it for free. The Pro Plan costs approximately $20 per month, and the Business Plan costs $200 per month, which is quite affordable.<\/span><\/p>\n<p>View the pricing table <a href=\"https:\/\/www.cloudflare.com\/plans\/\" rel=\"noopener\">here<\/a>.<\/p>\n<h4><strong>2. Customization options<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">Cloudflare offers WAF and load balancing services, depending on your plan. The WAF that can be used in this scenario is less configurable than the AWS WAF, but it can withstand a certain number of security attacks.<\/span><\/p>\n<h4><strong>3. Variety of services<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">AWS WAF is a firewall for web applications. Given that <a href=\"https:\/\/docs.aws.amazon.com\/AmazonCloudFront\/latest\/DeveloperGuide\/Introduction.html\" rel=\"noopener\">AWS CloudFront<\/a> functions as a CDN, it must be utilized in conjunction with AWS CloudFront. On the other hand, Cloudflare refers to a Content Delivery Network. Depending on the chosen plan, WAF features are available.<\/span><\/p>\n<h4><strong>4. Installation speed<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">AWS WAF can be introduced in a matter of minutes. For Cloudflare, all you need to do is prepare a domain name, and you will be up and running within minutes to days.<\/span><\/p>\n<h4><strong>5. Customizability<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">AWS WAF can be customized independently in numerous ways. AWS services such as AWS CloudFront and AWS Shield can also be combined to add functionality. With higher-tier programs, additional options and features can be added to Cloudflare. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, it does not offer as many customization options as the AWS WAF.<\/span><\/p>\n<h4><strong>6. Preventable Security Attacks<\/strong><\/h4>\n<p><span style=\"font-weight: 400;\">AWS WAF can only prevent application layer attacks. You can also obtain additional protection against DDoS and other attacks by combining AWS Shield and other services. Cloudflare, on the other hand, provides defense against DDoS attacks. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">You can also use additional WAF functions to protect against application-layer attacks.<\/span><\/p>\n<p><b>In Closing<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A <a href=\"https:\/\/www.exabytes.sg\/web-security\/cloudflare-web-performance-booster\">Web Application Firewall<\/a> (WAF) is a necessary security measure for any organization with an online presence. It protects sensitive data and prevents malicious attacks by acting as a barrier between web applications and cyber threats. With the rise of web-based attacks, it is more necessary than ever to implement a WAF. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Additionally, more recent technologies such as Runtime Application Self-Protection (RASP) offer even more advanced protection by detecting and preventing intrusions within the application itself. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">By implementing a WAF and other security measures, businesses can ensure that their web applications continue to be secure and reliable for users.\u00a0<\/span><\/p>\n<p><span class=\"td_btn td_btn_md td_default_btn\">Get Managed Cloudflare to Improve Website Security<\/span><\/p>\n<p>Related articles:<\/p>\n<p><a href=\"https:\/\/www.exabytes.sg\/blog\/cloudflare-cdn-for-wordpress\/\">What You Can Expect From This Cloudflare CDN for WordPress<\/a><\/p>\n<p><a href=\"https:\/\/www.exabytes.sg\/blog\/cloudflare-vs-sucuri-ideal-security-services\/\">Cloudflare vs. Sucuri: Which Security Service is Most Ideal?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Web Application Firewall (WAF) is a form of security control that protects websites and web applications from cyberattacks. Essentially, a WAF is similar to a doorman at an exclusive club who decides who goes in and who does not. It functions by analyzing the traffic between the internet and the web application and blocking [&hellip;]<\/p>\n","protected":false},"author":75,"featured_media":26945,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[293],"tags":[551,540,488,196,472,255],"class_list":{"0":"post-26944","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-backup","8":"tag-cyber-security","9":"tag-cybersecurity","10":"tag-digital-security","11":"tag-security","12":"tag-website-security","13":"tag-wordpress-security"},"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.exabytes.sg\/blog\/wp-content\/uploads\/2023\/05\/web-application-firewall-waf-security-control.jpg?fit=1200%2C628&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/pbHhPQ-70A","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts\/26944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/users\/75"}],"replies":[{"embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/comments?post=26944"}],"version-history":[{"count":1,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts\/26944\/revisions"}],"predecessor-version":[{"id":26946,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/posts\/26944\/revisions\/26946"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/media\/26945"}],"wp:attachment":[{"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/media?parent=26944"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/categories?post=26944"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.exabytes.sg\/blog\/wp-json\/wp\/v2\/tags?post=26944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}