Edition 14: To WAF or not to WAF - by Sandesh Mysore Anand
First, a confession: For the longest time, I have been biased against WAFs. Most WAF tool sales pitches are too good to be true and often feels like NetSec folks trying to solve AppSec issues, without understanding AppSec well enough. Unsurprisingly, there’s more nuance than that. A few days ago, On a Twitter space with Chris Folini and others, his answer to a question of mine (34m mark) got me thinking. It’s clear that WAFs work well against some kind of attacks and can only respond in a limited set of ways (block or slow down traffic), but it’s unclear what those attacks are and what types of responses they work well against. It maybe useful to develop a hypothesis which helps us determine when WAFs can be useful. WAFs can be used as a part of the defense strategy only when two conditions are met: (1) The cost of fixing the defect in the target software is prohibitively more expensive than blocking attack traffic and (2) the organization can tolerate a percentage of legitimate traffi
The Boring AppSec Newsletter Edition 14: To WAF or not to WAF Effectiveness of WAFs are a hotly debated subject in AppSec circles. This editions tries to bring a structure to that discussion. Sandesh Mysore Anand Jan 02, 2022 8 Share Shakespeare answering an important question: To WAF or not to WAF. Image credit: iofoto Subscribe First, a confession: For the longest time, I have been biased against WAFs. Most WAF tool sales pitches are too good to be true and often feels like NetSec folks trying to solve AppSec issues, without understanding AppSec well enough. Unsurprisingly, there’s more nuan
Explore this link on the map →related reading
- How Wiz Became the Fastest Software Company to Hit $500M & Its Path to $1Bsoftwareanalyst.substack.com
- Security incident disclosure — July 2026huggingface.co
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Web Application Firewall Market to Grow at CAGR of 16.7%globenewswire.com
- Firewalls | Computer Securitytextbook.cs161.org
- NGINX | F5nginx.com
- AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Bloglantian.pub
- Denial-of-Service (DoS) | Computer Securitytextbook.cs161.org
- Illumio et Wiz : Voir, détecter et contenir automatiquement les attaques de l'informatique en nuage - Blog d'Illumio sur la cybersécurité | Illumioillumio.com
- How Wiz Became the Fastest Software Company to Hit $500M & Its Path to $1Bsoftwareanalyst.substack.com
- Denial of Service (DoS) guidance | National Cyber Security Centrencsc.gov.uk
- All learning materials - detailed | Web Security Academyportswigger.net