Home / Services / Web Security / WAAP
Web Security / AWS WAF operations automationAWS WAF operations
that don't over-block and that you can delegate.
WAAP (Web Application & API Protection) is a service that automates AWS WAF operations. It shows whether legitimate customers are being blocked by mistake, and supports you through exclusion suggestions, pre-change impact estimates and a gradual switch from Count to Block. Automation doesn't go all-in at once: for each feature, you choose Off, Suggest or Auto.
Challenges
Sound familiar?
Stuck in Count mode for fear of false blocks
To avoid the risk of stopping legitimate users, the WAF ends up effectively blocking nothing.
Tuning depends on one person
Without someone who can tell which rules are false positives and which are real attacks, operations stall.
Settings change without you knowing
When multiple people and tools touch the configuration, unintended changes (drift) can happen unnoticed.
Features
WAAP key features
01Exclusion suggestions for false blocks
Blocked requests are aggregated daily by rule × path × IP × country, and exclusions are suggested for likely false positives. Review them and apply in one click.
02Impact estimates before changes
Before adding or changing a rule, it is applied to recent logs to estimate how much traffic it would affect (shadow evaluation).
03Automatic promotion from Count to Block
New rules start in Count mode. They are promoted to Block after a set observation period, with enough matches and no unresolved false-positive candidates.
04Automatic quarantine of attacking IPs
IPs that attack repeatedly are blocked with an expiry, and released automatically when it passes. Can also work with threat intelligence IP lists.
05Bot defense without paid rule groups
Verifies legitimate bots and detects impersonation using the published IP ranges of major crawlers, detects scrapers with JA3/JA4 fingerprints, rate-limits login and sign-up pages, and more, all with standard WAF rules.
06ML-based malicious request detection
A machine learning model that scores how malicious URIs and headers are runs inside your AWS account.
07Drift detection and rollback
Configuration snapshots are saved and unintended changes are detected daily. If something is wrong, revert to a previous state in one click.
08Log search and AI daily briefing
Search WAF logs across sources from the console. AI summarizes each day's situation for you. Alerts can be sent by email, Slack or webhook.
Rule library
An extensive rule library
to protect every kind of web system
and API
The WAAP rule library covers a wide range, from OWASP's major attack categories to known vulnerabilities (CVEs) that have actually been exploited and attacks specific to frameworks and databases, and is continuously updated to keep up with new attack patterns. Pick what you need in the console or apply a use-case template, and the rules are deployed to your AWS WAF.
Injection
Known vulnerabilities (CVE)
Bots and scanners
XSS
Path traversal
SSRF
Web shell / RCE
HTTP headers
XXE
CMS and redirects
Custom rules tailored to your systems
Build rules by combining conditions
Create rules in the console by combining IP address, country, ASN, data center, User-Agent, regular expressions, TLS fingerprints and rate limits. You can also write AWS WAF rule definitions (JSON) directly.
Check the impact before deploying
Apply a new rule to the last 24 hours or 7 days of WAF logs to see, before deploying, which requests it matches and how many requests and IPs it would affect.
Switch safely from Count
Run new rules in Count mode to watch their behavior, and switch to Block after confirming sufficient observation and no false-positive candidates. For each rule, choose Block, Count, CAPTCHA, Challenge or a custom response.
Supported tech stacks
Use-case templates
- Website (standard protection)
- Website (strict)
- API server
- CMS - WordPress
- CMS - Drupal
- CMS - Joomla
- High-risk applications
- Bot defense only
Please note: Rules are deployed as rule groups in your AWS WAF, and for each rule you can choose Block, Count, CAPTCHA or Challenge. We recommend first checking impact in Count mode and promoting to Block after a period of observation. Library updates take effect when you redeploy. Rules can be combined within the AWS WAF rule group capacity (WCU).
Bot defense
One technique is not enough for bot defense
Scrapers, credential stuffing, crawler impersonation, attacks that keep going while rotating IPs. Effective countermeasures differ by type of bot. WAAP lets you combine multiple approaches as standard WAF rules, without subscribing to AWS's paid bot-defense rule groups. Everything is off by default, and for each feature you choose Suggest or Auto.
Identifying legitimate bots
Major crawlers such as Google, Bing, OpenAI, Anthropic, Perplexity, Apple and DuckDuckGo are checked against the IP ranges each company publishes. Genuine ones are labeled and allowed through, and impersonators that only copy the name are detected.
TLS fingerprints
Scrapers and attack tools that spread requests across changing IPs are identified by their TLS fingerprints, so you can quarantine by “tool” rather than by IP. JA4 features are used as inputs to the score and do not trigger blocks on their own.
Bot score
Multiple signals, such as skewed sessions or UAs and a small variety of TLS types, are scored per IP, User-Agent and ASN. To avoid mistakenly stopping companies behind NAT or legitimate users who only use an app, scoring measures how far signals exceed a baseline.
Protecting login and sign-up pages
Rate limits and checks for missing required fields are placed on login and sign-up paths as WAF rules, and signs of credential stuffing are scored separately from logs. With CloudFront / ALB access logs, concentrated login failures are also detected.
Coordinated attack detection
Distributed attacks in which many IPs hit the same URI at once are detected every 10 minutes, and the IPs involved are quarantined together with an expiry.
Threat intelligence integration
Public lists of botnet C2 servers and malicious TLS fingerprints are imported and applied to WAF rules at a confidence threshold you set. Check the impact in Count mode first, then switch to Block.
Please note: Some capabilities provided by AWS's paid rule groups (Bot Control / Account Takeover Prevention / Account Creation Fraud Prevention), such as per-username aggregation and token-based legitimate-client verification, cannot be replicated equivalently due to how WAF rules work. Where needed, we can also advise on using them alongside the paid rule groups.
Better together
Combine with other Web Security services
to cover the full cycle of web protection
A WAF alone can't cover knowing which entry points to protect, the latest information on attackers, or finding attacks that slipped through. With WAAP at the center, combining threat intelligence, ASM and defacement detection connects “find, know, stop, notice” in a single console.
Attacker information, into your WAF rules
Malicious IP lists gathered by threat intelligence are automatically applied to your WAAP policy at a confidence threshold you set. Malicious TLS fingerprints are also used in WAAP detection. Check the impact in Count mode first, then switch to Block.
Unseen entry points, brought under protection
Of the live subdomains and servers ASM finds, you can add the ones that need protection to WAAP's protected targets. When a new vulnerability is disclosed, use ASM to identify the affected assets, and strengthen protection with the WAAP rule library until they are fixed.
Notice attacks that slipped through, right away
Defacement detection catches attacks the WAF could not stop, and unauthorized updates made from an admin panel, from changes to pages and scripts. The techniques it uncovers can feed your next line of defense through WAAP custom rules and log investigation.
Please note: Each service is contracted individually. Applying threat intelligence to WAAP requires contracts for both services.
Log forensics
Investigate WAF, CloudFront and ALB logs
right where they are
When you're attacked, the first thing you want to know is “who did what, and where.” With WAAP log investigation, you can search across the logs in your S3 from the console, covering not only WAF events but also CloudFront and ALB access logs and even CloudTrail. There is no need to forward or copy logs. Just enable the log sources you want to use, and they become available for investigation.
WAF events
Filter blocked and counted requests by source IP, URI, rule and country. Aggregation templates instantly show top IPs, top URIs, top rules, breakdown by country and block count trends.
CloudFront access logs
Aggregate every request that reached the edge by status code, referrer and client. Check for error spikes and see the actual responses to requests that passed the WAF.
ALB access logs
In addition to aggregation by target, client and status code, extract slow-responding requests and check error trends. Also used to detect concentrated login failures.
CloudTrail and beyond
Investigate denied CloudTrail operations, console logins, role assumptions, IAM changes and destructive operations. VPC flow logs and MySQL and PostgreSQL logs are also supported.
From enabling to investigating
Register log sources
Specify an existing log bucket, and the storage format and partitions are detected automatically to create tables for search.
Access logs enabled for you
If CloudFront / ALB access logs aren't set up, they can be enabled for you from the console. A list also shows which features use which logs.
Investigate with templates
Just choose an aggregation template and filter conditions to investigate without writing SQL. Partitions are narrowed by time range, so short investigations don't scan every record.
Please note: Searches run on Amazon Athena in your AWS account, and logs do not leave your S3. Athena scan charges and log storage charges are incurred as part of your AWS usage fees. Each search displays up to 500 rows of results.
Patented detection
Two patented learning models
that find both “missed detections” and “false positives”
What makes a WAF hard is that “missed detections,” which let attacks through, and “false positives,” which stop legitimate users, happen at the same time. Based on Japanese Patent No. 6998099, “Method for detecting fraudulent access requests,” obtained by Classmethod Security (formerly CyberMatrix Co., Ltd.), WAAP combines two learning models to detect both.
Attack-pattern analysis
A machine learning model that determines whether URI, query and header strings are attacks. It also responds to variants and obfuscation that regular expressions struggle to catch. It runs inside your AWS account and does not send request contents outside.
Normal-pattern learning
A site-specific model that learns the normal requests actually allowed on that site and determines “whether a request is normal for this site.” The same request can be judged differently on a different site.
Detecting missed detections (FN)
Among requests the WAF let through, those that attack-pattern analysis considers attacks and that normal-pattern learning judges different from the site's usual traffic are presented as “missed-detection candidates.” They serve as grounds for adding or promoting rules.
Detecting false positives (FP)
Among requests the WAF blocked, those that normal-pattern learning judges to have the same form as the site's usual traffic are presented as “false-positive candidates.” They come with exclusion conditions, reasons and real request examples, and can be applied in one click.
After onboarding
Attack-pattern analysis is active right away
Analysis starts with a general-purpose attack-pattern model immediately after connection. The default is Suggest, which only records results and does not affect production.
Learn normal patterns
Site-specific normal patterns are learned from several days of normal traffic. Training data stays in your S3.
Review and apply candidates
Missed-detection and false-positive candidates are listed with reasons. Review and apply them, and once you're comfortable, switch each feature to Auto.
Please note: Attack-pattern analysis does not replace regular-expression detection; it adds to it. So that false positives don't lead directly to blocking real users, attack-pattern analysis results are Suggest-only by default and are not used for automatic quarantine.
Specifications
Scope and delivery
| Target |
|
|---|---|
| Deployment |
|
| Data location |
|
| Notifications |
|
| Pricing |
|
Please note: Only AWS WAF is supported (Azure WAF / Google Cloud Armor are not). Some features require additional log sources, such as CloudFront / ALB access logs.
Getting started
Getting started
Create the role
Create the operations role with CloudFormation, register it in the console and run a connection test.
Connect a Web ACL
Connect an existing Web ACL, or create a new one and associate it with CloudFront / ALB.
Enable logging
Once WAF logging is enabled, log search and analysis become available automatically.
Choose automation levels
Choose Off, Suggest or Auto for each feature. Verify with Suggest first, then move to Auto.
FAQ
FAQ
Do I need AWS's paid managed rules (such as Bot Control)?
No. Bot defense is built from combinations of standard WAF rules. However, some capabilities, such as per-username aggregation, are not equivalent to AWS's paid features.
Will my production WAF settings change without my knowing?
For each feature, you choose Off, Suggest or Auto for automation. Changes are recorded and can be reverted from snapshots.
Works well with
WAAP — details and demo requests
Our team will explain deployment options and pricing for your environment.