Cloud WAF: Why a Checkbox Isn’t Enough


I remember when I first learned about Web application firewall technology. It seemed like magic to me: A device that could compensate for bad coding or unexpected/unintended web application functionality. It could do this by learning expected application behavior and then enforcing said behavior, even if the application itself was capable of allowing the unwanted behavior. The business case for such a technology is easily recognizable even more so today than it was in the mid- to early 2000’s when it first came out: the ability to have a device compensate for human error.

The potential cost savings of this type of technology either in physical costs or brand protection is easily explainable. Consider for one second the cost a particular adult dating site has incurred; not due to actual funds being stolen but due to PR expenditures and legal fees associated with the hack. At the end of the day, we are all just human and yes we can fix errors when we find them, but sometimes things aren’t even exploitable until they are. It is easy to see the value of a technology that can protect against this unknown risk.

To illustrate this unintended functionality risk let’s describe a simple SQL injection in the context of a story:

The year is 2003 and I have decided I want to break into your bank account. I don’t know anything about you other than your name, your wealth, that you portray yourself as tech savvy and you bank at Wealthy Man Bank. So I open an account at Wealthy Man Bank too. I get online account access (if you’re tech savvy you’ll be doing online banking) so I can see the syntax for the user name (now I know what your user name is). For argument’s sake, let’s say it was first initial, last name. Knowing a user name doesn’t get me in though, so nothing to worry about, right? Well, not quite true. I happen to be a budding SQL developer and I know that in the coding world 1=1 or a=a or 2=2 etc. means true. So in other words, I substitute this basic SQL statement for the for the password in the password field and voila! I’m in, and all your money is gone (note this type of SQL attack would likely not work today because developers are generally smarter than that now).

In the above example the hacker tricked the application into doing something it wasn’t programmed to do. This type of breach was recognized early on by the likes of the PCI-DSS council who decided to make secure code review and/or a WAF a requirement of credit card compliance in order to prevent it. Most organizations eventually chose to go the route of a WAF because although secure code review should be part of a best practice, it is usually a point-in-time static check… and almost all code today is dynamic and ever changing. It doesn’t help that we are human and we make mistakes. A true WAF, configured and managed correctly, solves that problem by enforcing only known good behavior. It has to have a positive and a negative enforcement architecture to truly achieve this.

Today we are spoiled for choices when it comes to WAF. We have multiple options for on-prem or in the cloud WAF, and we also have several other devices like next-gen firewalls and some Proxy technologies that say they protect against the OWASP top 10 risks. What makes some stand apart from others and why do you still need a real WAF?

First, let’s discuss what makes a WAF a WAF and where technology comes from. In the early days when companies like Terros first espoused this type of technology, our friends at Gartner labeled it as an IDS. The key thing that eventually differentiated it from and IDS/IPS with targeted OWASP signatures and still does is the ability to do positive application enforcement (enforce known good behaviors and block everything else). The WAF can and does have signatures, but the magic is in learning and enforcing the expected behavior. This official differentiation happened around the year 2006. The PCI-DSS council made their compliance requirement almost at the same time.

[You might also like: WAF and DDoS – Perfect Bedfellows: Every Business Owner Must Read.]

The problem with a WAF then as it is now and has always been is that it is a very interactive product. Most other security devices are to some extent set and forget, but a WAF is always high touch. Every time the application changes I have to touch the WAF to avoid false positive “blocks.” To illustrate what I mean, if I add a new feature to an application, the WAF will block it if it hasn’t seen it before and it should. A new feature would be unexpected behavior, a divergence from the baseline, so to speak. The only way to solve this is constant care and feeding. The problem is further exacerbated by the fact that the work or security team that runs the WAF don’t actually write the application code. They have to see the error or false positive, then get hold of the development team, etc. Due to this complexity of management, we found the adoption of WAF outside of the PCI compliance realm rather stunted and the success rate of people using the WAF for more than a checkmark mixed.

Over the past few years several changes have taken place in the WAF space. The biggest change has been the move to WAF as a service, both as a full SAAS offering and as a fully managed service. This change has been a boon for adoption as the complex setup and management has been greatly reduced. However, all is not as it seems. Remember the functionality that differentiated a WAF from an IPS or for that matter a next generation firewall, the ability to learn the application and enforce known good behavior? Well that doesn’t exist in most Cloud WAFs. I would contend that in fact there are only two WAF-as-a-service companies that actually offer a true cloud “WAF.” Remember folks, just because you call something by a particular name doesn’t make it so. What you get from the cloud hosting providers is often not a WAF, and what you get from anyone not offering positive enforcement capabilities is not a WAF.

Compounding this obvious problem is the fact that most large enterprises are stuck in a hybrid architectural scenario, with some of the assets protected behind hard-to-manage on-prem devices and some in the cloud behind a service. Most players in this space offer either an appliance or a service, not both. Worse, when they do offer both it’s not the same technology. Most on-prem solution are to a greater or lesser extent a WAF. Most cloud WAFs are in fact IPSs with a signature set tuned to protect against the OWASP top 10 threats. The limitation of signatures is not the only problem. It’s the fact that you will have to manage two different systems, pull reports form two different systems, etc. and not have a single point of contact from a support and management perspective.

The next-gen solutions that have come out over the past year have answered this challenge by offering a true WAF in the cloud that uses the same universal management and reporting console. On top of this, at least one Israeli-based organization offers a full managed services solution stack that covers both their physical appliances and their cloud SAAS offering. This allows organizations either transitioning to the cloud or who have a hybrid architecture to have a seamless experience. It also empowers organizations to now harness the full capabilities of a WAF, which were previously unattainable because of the high-touch, high-skill requirements.

In today’s world where web attacks are becoming ever more common and the cost of these attacks when successful ever higher, it is not worth selecting a solution for its substance rather than its name. Especially when the solution is roughly the same price and globally available, and unmistakably alone in answering the customer’s true needs.


Read “Keep It Simple; Make It Scalable: 6 Characteristics of the Futureproof Load Balancer” to learn more.

Download Now


  1. “(To date) we have saved about 300,000 k – Wh,” said, Dr.
    Don’t’ forget to click on the Slide Show and Video to your left.
    Many new & old tradesmen, with creative
    one-of-a-kind gifts & treasures, spent 3 days at the Prime Osborn Center supplying individuals with gift-to
    give away and some gifts to keep for themselves.

  2. He had the same chance as everyone else on the
    flight. He chose to fight in the most childish way possible when he could have just driven home with
    his wife. He delayed the flight the amount of
    time it would have taken to drive.. Natsumi suspects that Keroro will use
    his invisibility device to go out and cause trouble, so she convinces her
    family to install hidden cameras throughout
    the house to spy on him. Later, Natsumi accuses Keroro of spying on the family when she discovers a pair
    of binoculars outside, but the Hinatas survey the security footage to find
    that Keroro has done nothing out of the ordinary.
    The true culprit is later revealed to be
    Giroro, another member of Keroro’s platoon..

    Bathing Suits The midfoot is also wide, though, which leads to me tightening the
    laces a lot and that creates a tight spot on the top of my foot.
    Otherwise, it’s a nice shoe that has a flexible
    sole. Very comfortable for walking around. Finally moved down to Kyle.
    LOVE LOVE LOVE it out here. We get more square footage for our money.Bathing Suits

    swimwear sale But then she also openly shares and shows the fact she works out for hours every day.
    I seen one clip where she said she was off for workout
    number 3 of the day. Then I saw one where she did a 2 hour
    work out session.. And the rules seem to change
    country by country as well. Esther, 7, told me
    just the other day that she noticed people are more comfortable being naked here in France than they are in America.
    She noticed this after just a few visits to a public pool,
    and lots of visits to her friend backyard pool.swimwear sale

    dresses sale 2) Click on the title of the template (it will then appear on its own for a closer inspection), then click “Download” after which you simply agree to their user license agreement to receive the file.
    (You might have to install an Active X plug in for Internet Explorer
    if you don’t already have it.)3) Open your now downloaded template in Word and follow the simple instructions
    to enter your specifics in the right category. It’s just a
    matter of typing over their text with your own personal information and history..dresses sale

    Sexy Bikini Swimsuit My advice Buy one or two inexpensive pairs
    of shoes that arecomfortable and fit your feet the way they
    are now. I pretty much lived in my flip flops (my OB/GYN joked she could always
    spot a pregnant woman in Colorado because we
    were the ones wearing flip flops during a blizzard). After you given yourself some
    time, you can start trying on shoes and seeing what feels good and if you must
    buy larger sizes.Sexy Bikini Swimsuit

    Tankini Swimwear She has also been trained in basic self
    defense. She has a large appetite and constantly struggles
    with getting enough money to eat, despite coming from a wealthy household.
    She has an older sister who ran away from home due to their parents being
    very strict as well has having a strong dislike towards phantoms.Tankini

    beach dresses Chi l’ha detto che i costumi da bagno interi
    siano noiosi Accendi il divertimento estivo con un fresco e
    provocante trikini. Un trikini veste come un costume intero combinandolo alla copertura di un bikini.
    Immagina un bikini con simpatici lacci e ampi ritagli sul lato.beach dresses

    cheap swimwear If you look at I think lots of those would
    work well. I really appreciate it. I got fitted
    at Victoria Secret and that the size they gave me twice.
    This was my first God of War game. I tried watching a recap of
    the previous games and only came out with a general sense of
    his past, which made a big difference in the
    story for me. I also a huge Norse mythology nerd, and so this game hit all the right notes for swimwear

    Sexy Bikini Swimsuit I have never worn a properly
    fitted bra before. I wore 36As that big cups and bands.

    I wore 36Bs that were too narrow and dug into my sides.
    She isn saying that the food isn similar to the
    subcontinent, it just that the regional style makes a
    difference in how you cook it as well. I moved across the country and the
    way Indian food is made has a different style and take between the
    east and west coast. All of it is easily identifiable as certain desi dishes, and they largely taste the same, but it is a little different..Sexy Bikini

    Cheap Swimsuits Hi! Certain shape factors can lead the
    calculator to overestimate. Your estimated band size of 40 looks to be a good place to start as bras in the 40+ band
    range tend to have extra stretch in them. Being pendulous myself with a lot
    of soft breast tissue, you may get a good fit with a 40H (UK) /
    40K (US).Cheap Swimsuits

    Tankini Swimwear Managed VPN solution service providers can also help organizations save money
    by routing the data of several organization over the
    same data lines, or help enterprises to leverage the expertise of the provider’s staff to alleviate additional
    overhead expenses. The widespread availability of WWAN,
    DSL and other broadband options gives enterprises multiple ways to securely interconnect network users over a VPN.
    Another benefit of VPN is that it gives an organization the advantage to use virtually Bathing Suits any data service option, as cost and availability dictate Tankini Swimwear.


  3. male sex toys
    In Alaska, Senator Lisa Murkowski, whose family began the Waterfall Foundation to finance breast
    cancer screening in rural Alaska, appeared at an exclusive fishing resort on Prince of Wales
    Island, reachable only by boat or seaplane. The guest list
    of nearly 100 was a who’s who of the global oil and coal industries, with lobbyists and executives from Exxon Mobile, ConocoPhillips, BP,
    Duke Energy and Royal Dutch Shell. (David Lawrence, Shell’s executive
    vice president for oil exploration, pulled in one of the biggest fish, a 105 pound halibut.).

    anal sex toys Take your light show up a notch by turning up the frequency to your desired intensity.
    The Twilight Wand is handsomely accompanied with four glowing glass pieces each with
    their own ambient light show, sensation, and intensity.
    This compact and lightweight piece is travel friendly.
    While details are sketchy, the program might start with next year’s
    high school freshmen, who would commit to the pilot at the start of high school.
    Schools Chancellor Kaya Henderson is pushing
    to open the program to every high school. Sessoms said he’d prefer to
    start with a pilot and work out the kinks
    before going city wide.. anal sex toys

    cheap sex toys So if you want, add a few, but i dont think you need to double your stash.

    I would recommend at least 3 more covers. Newborn poop has a tendency to escape, even with the best jellyroll (though we weren very good at it in the beginning).
    I was asked to go back in the following weekend for another scan. A baby?
    It just wasn something I had planned for. Things were complicated with Jay, too, so what would having
    a child together mean for us? Would we get back together?. cheap
    sex toys

    cheap sex toys The singer lawyers reportedly claimed Belafonte had taken 12 to 15 boxes of personal belongings and memorabilia from the garage of the family home in California after Mel filed for divorce last month.Mel wore a tight white dress and kept her eyes hidden under a pair of dark sunglassesTMZ
    reports Belafonteput the boxes in a storage locker
    under the name of the former family nanny, Lorraine Gilles, who heis accused of having a fling with and getting pregnant.During the court date, Mel the judge to forceBelafonte to give them access tothe
    storage facilityso they can retrieve the items, but the judge has yet to
    rule on the request.Mel points to a bruise on her face in a Twitter post
    from 2012New papers filed as part of the case allegeBelafonte threatened to released intimate videos of Mel.Mel filed for divorce from Stephen last month after 10 years of marriageand the divorcebattle took a
    dark turn this week as the pop star filed for a restraining order to keep
    him away from her.The court papers contained explosive allegations about domestic abuse, threesomes and claims Stephen got nanny Lorraine pregnant and paid for her to have an abortion.Lorraine
    was pictured out and about in LA just days after the shocking
    claims came to lightas herfriends told The Sun that
    the nanny has denied having a fling with Stephen.Astatement
    released by Belafonte rep dismissed Mel claims: “In due course, Mr. Belafonte will be filing his response to the outrageous and unfounded allegations made by Ms. Brown, which allegations he vehemently denies.”When the Court determines the truth, it will become clear that this entire charade was nothing more than a smear
    campaign intended to cover up Ms. cheap sex toys

    sex toys Truly I tell you, they have received their reward in full.
    But when you give to the needy, do not let
    your left hand know what your right hand is doing, so that
    your giving may be in secret. Anything.. “You shouldn”t listen to all you hear, Sandyman,” said the Gaffer, who did not much like the miller. “There isn”t no call to
    go talking of pushing and pulling. Boats
    are quite tricky enough for those that sit still without looking further
    for the cause of trouble. sex toys

    sex Toys for couples I really enjoy the fantasy of it with my
    wife. We haven done it, but it is my biggest fantasy
    to watch my wife having sex with someone else. I think
    of him doing things that maybe I can do. I don’t use these anal options every time, but I like to make use of them fairly
    often, as the extra stimulation is great. Men, if you’re
    afraid of pleasuring your ass or your woman doing it because
    it will “turn you gay,” get over yourself. If it were that easy to become gay,
    we’d have a hell of a lot more gay men sex Toys for couples.

  4. dazeymayhem comments on is new attitude wigs legit

    hair extensions Back in the day we downed heroic festergut for
    the first time because I res an ally as a ghoul and she managed to get
    the last like.001% before the wipe. I also saved our raid from wipes using armies before
    the glyph when a tank went down. I used to be able to pop blood presence and taunt bosses when bad shit happened and
    now I feel like I can really do anything but deathstrike and pray.

    This is a choppy and chic short wig with lots of styling options.

    The fringe has been expertly textured to create a
    wispy and realistic frame to your eyes. This then blends into the flattering side layers.
    hair extensions

    360 lace wigs I so proud! And jealous, let be honest.
    But I made some, too so it okay. Edit: is
    not okay; I put mine in the wrong order. To promote his autobiography, A
    Book, on February 21, 1976, Arnaz served as a
    guest host on Saturday Night Live, with his son,
    Desi, Jr., also appearing. The program contained spoofs of I Love Lucy
    and The Untouchables. The spoofs of I Love Lucy were supposed to be earlier concepts of the show that never made it on the air, such as “I Love Louie”, where
    Desi lived with Louis Armstrong. 360 lace wigs

    human hair wigs Pranin interviewed Noriaki
    (Yoichiro) Inoue, nephew of Morihei Ueshiba and
    an early Aiki Budo pioneer in Tokyo, several times in 1987 88.
    Inoue’s father, Zenzo Inoue, married Ueshiba’s eldest sister Tame.

    Zenzo and Ueshiba’s father, Yoroku, influenced and financed Morihei Ueshiba
    during his early years. Those are actual reasons for some of
    the garments, though hollywood does exaggerate a bit to add flair to the characters.
    Though in the second half of the 19th century photography became fast and practical enough
    to take “quick” snapshots, cameras were still too cumbersome for real candid photography
    of close subjects like that, and a photographer was
    a rare sight in isolated places on the frontier being photographed was an occasion,
    something people would stop what they doing for. As you can tell,
    all of those photographs are more or less posed don take the pictures
    as an indication that this is how people dressed and looked all
    the time in their daily lives.. human hair wigs

    hair extensions The short, wavy layers on top add just the right amount of airy volume, and the pretty,
    feathery bangs elegantly frame the face. The neatly tapered sides,
    back, and neck complete the chic, short silhouette.
    100% human hair fibers are heat stylable, just like your own hair!
    Length: 2 3 Front; 2 2.5 Top; 2.25 Crown; 2 2.5 Sides;
    2 2.5 Upper Back; 2.25 Nape. Eat a Healthy Diet and ExerciseEating right and
    exercise do not necessarily increase the rate that your hair will grow but they can reduce
    hair loss. Hair loss due to stress and a poor diet may hinder your natural hair results.
    Studies have shown that regular exercise including
    at least 30 mins of cardio 3 5 days a week can significantly reduce stress
    and increase endorphins. hair extensions

    clip in extensions I agree, it is a shame but thankfully there been a movement since the
    1990s to take the scholarship into new directions
    with a focus on the Vietnamese side. My own research is a strong follower of that movement.
    Now, you got several great books in your list (Wiest, Brigham, Miller, Nguyen, and
    the book I just recommended) that will be very valuable to
    balance the otherwise normal narrative. Hard shifts from
    1>2>3 are commonplace for these cars, as are slight bumps between P, D, and R.

    These are generally worse when the car is cold. Shifting at the wrong points might be an ECU problem, as the car adjusts
    its shift points based on what it thinks your driving style is.
    clip in extensions

    360 lace wigs STDs are severely over hyped.
    I think it stems from the poor quality of sexual education as well
    as other influences. In reality STDs are so common that they don even check for most
    of them when you get a STD test. Wie was given a sponsor’s exemption to the 2004 Sony Open in Hawaii, becoming the fourth, and
    youngest, female to play a PGA Tour event. Her second
    round score of 68 was the lowest ever by a woman in a PGA Tour event, though she went on to miss the cut in the tournament.
    While missing the cut by 1 stroke she bettered the 36 hole
    score of 47 men including 4 major winners and matched the scores
    of 15 more men including 3 more major winners 360 lace wigs.

  5. sex toys
    I found this site when i small penguin was in my bed stealing my sanity
    well i was sleeping and he told me if you go there they will talk about weird thing, this happened
    for 4 nights in a row, on the fifth night when the penguin started to talk to me i woke up and asked him for
    small bowl of cottege cheese, a bag of funions, and what he ment by his little saying.
    Over the next three and half hours the penguin and i had a lenthy discussion on the
    internet and poodles and the use to the
    defense dept. Well we ate and drank tea and bagels.

    cheap vibrators ‘She deserves death,’ he allegedly wrote Cop hid assault rifle
    under bed, threatened to kill ex and poison her dog, police say.
    Woman charged with abandoning skin and bones dog found eating another
    dog’s carcass to survive The dogs were abandoned in a vacant New Jersey house.
    One dog died and the other fed off the carcass for survival.
    cheap vibrators

    vibrators The president was “clearly excited” to see “Top Gun,” though the sex scenes seemed to go on far too long
    for his and Nancy’s taste. The “over the top violence” of “Red Dawn”
    may have similarly dampened their appreciation of its Commie repelling Colorado kids.
    Bureaucrat. I normally wouldn’t consider the packaging on a pair of panties such as these,
    but it didn’t exactly scream quality. They were in a small white box about the
    size of a large postcard. That was good. vibrators

    cock rings I have 5 Vixskin toys and the only one that has for some reason been extra
    troublesome with smells is my Goodfella. Not sure why.

    But all silicone has the tendency hold on to smells, unfortunately, but never permanently.
    The hybrid news commentary format is on regular display in cable’s evening hours.

    In a “breaking news”discussion about the latest twist in special counsel Robert S.
    Mueller III’s Russia investigation last week, for example,
    CNN’s Anderson Cooper opened the floor to multiple talking heads:
    New York Times reporter Maggie Haberman, investigative reporter and political
    analyst Carl Bernstein, legal analyst Jeffrey
    Toobin and a former federal prosecutor, Anne Milgram.
    cock rings

    cheap vibrators But one day I pulled it out and the material hadBut one day I pulled it
    out and the material had melted, leaving a half circle whole in the baseI keep other silicone toys in the same area
    and have never had any issues. I also do
    not live in a hot climate or have the drawer near a furnace ventBut one day I pulled it out and the material hadBut one day I
    pulled it out and the material had melted, leaving a half
    circle whole in the baseI keep other silicone toys in the same
    area and have never had any issues. I also do not live in a
    hot climate or have the drawer near a furnace ventAny ideas what may have happened?Its a very good idea to
    store your toys in seperate baggies. cheap vibrators

    sex Toys for couples Olan heard creatures chirping and howling, the wind blowing through the trees, and something else rumbling below it all.
    What was that? It sounded like water falling.
    Wait. But I guess I’m scared, in a way, and this makes me
    feel like a terrible person. I’m scared that if we do find a really great LGBTQ
    community, he’ll abandon me, or that I won’t fit in, or that I just won’t get it,
    no matter how good of a friend or ally I am. I’m just scared I’ll get left
    behind and then I feel guilty for thinking that.. sex Toys
    for couples

    cock rings What you really get in those types of situations, I guess it would be an effective
    ban. Because by the time you do that many setbacks, there isn any other area within that municipality to place the industry activities.
    Removed >Until now, the only major proposal limiting municipalities’ drilling regulations came from Senate President Pro Tem Joe Scarnati.

    cock rings

    sex toys You also have the right not to take a pregnancy test if you do not want to or feel that is not something you want to do.
    That, however, does not change our limits, particularly since we are NOT a pregnancy test, so cannot tell you if you are or are not pregnant.

    This is yet another power we lack, and cannot magically gain by someone harassing us..
    sex toys

    butt plugs The source said there were to four Americans, some pretending to be Canadian and Australian telling the story that it was a punch,
    and he was choking the girl witness claimed on social media that Mr Robb was attacked by up to five men and his head repeatedly stomped on. Was a coward punch.
    There is an investigation going on right now butt plugs.


Please enter your comment!
Please enter your name here