Home / Services / Web Security / WAAP

Web Security / AWS WAF operations automation

AWS WAF operations
that don't over-block and that you can delegate.

WAAP (Web Application & API Protection) is a service that automates AWS WAF operations. It shows whether legitimate customers are being blocked by mistake, and supports you through exclusion suggestions, pre-change impact estimates and a gradual switch from Count to Block. Automation doesn't go all-in at once: for each feature, you choose Off, Suggest or Auto.

Challenges

Sound familiar?

Stuck in Count mode for fear of false blocks

To avoid the risk of stopping legitimate users, the WAF ends up effectively blocking nothing.

Tuning depends on one person

Without someone who can tell which rules are false positives and which are real attacks, operations stall.

Settings change without you knowing

When multiple people and tools touch the configuration, unintended changes (drift) can happen unnoticed.

Features

WAAP key features

01Exclusion suggestions for false blocks

Blocked requests are aggregated daily by rule × path × IP × country, and exclusions are suggested for likely false positives. Review them and apply in one click.

02Impact estimates before changes

Before adding or changing a rule, it is applied to recent logs to estimate how much traffic it would affect (shadow evaluation).

03Automatic promotion from Count to Block

New rules start in Count mode. They are promoted to Block after a set observation period, with enough matches and no unresolved false-positive candidates.

04Automatic quarantine of attacking IPs

IPs that attack repeatedly are blocked with an expiry, and released automatically when it passes. Can also work with threat intelligence IP lists.

05Bot defense without paid rule groups

Verifies legitimate bots and detects impersonation using the published IP ranges of major crawlers, detects scrapers with JA3/JA4 fingerprints, rate-limits login and sign-up pages, and more, all with standard WAF rules.

06ML-based malicious request detection

A machine learning model that scores how malicious URIs and headers are runs inside your AWS account.

07Drift detection and rollback

Configuration snapshots are saved and unintended changes are detected daily. If something is wrong, revert to a previous state in one click.

08Log search and AI daily briefing

Search WAF logs across sources from the console. AI summarizes each day's situation for you. Alerts can be sent by email, Slack or webhook.

Rule library

An extensive rule library
to protect every kind of web system
and API

The WAAP rule library covers a wide range, from OWASP's major attack categories to known vulnerabilities (CVEs) that have actually been exploited and attacks specific to frameworks and databases, and is continuously updated to keep up with new attack patterns. Pick what you need in the console or apply a use-case template, and the rules are deployed to your AWS WAF.

INJECTION

Injection

SQL (MySQL / MSSQL / PostgreSQL / Oracle; 15 types in total)Template (Jinja2 / Freemarker / Velocity; 8 types in total)NoSQL (MongoDB / CouchDB / Redis)OS commandLDAPXPathGraphQLCSVMass Assignment
CVE

Known vulnerabilities (CVE)

Log4ShellSpring4ShellApache Struts2ConfluenceMOVEit TransferReact Server ComponentsCitrix ADCF5 BIG-IPFortinetPalo AltoIvanti
BOT

Bots and scanners

Attack toolsHeadless browsersAI crawlers
XSS

XSS

Script tagsEvent handlersEncoding evasion
TRAVERSAL / LFI

Path traversal

../ referencesSensitive filesPHP wrappers
SSRF

SSRF

Cloud metadataPrivate IPsProtocol abuse
WEB SHELL

Web shell / RCE

Shell uploadsDeserialization.env / .git
HEADER

HTTP headers

CRLF / HostSmugglingJWT tampering
XXE

XXE

External entitiesBlind XXEXInclude
CMS / REDIRECT

CMS and redirects

WordPressOpen redirects

Custom rules tailored to your systems

RULE BUILDER

Build rules by combining conditions

Create rules in the console by combining IP address, country, ASN, data center, User-Agent, regular expressions, TLS fingerprints and rate limits. You can also write AWS WAF rule definitions (JSON) directly.

SHADOW EVALUATION

Check the impact before deploying

Apply a new rule to the last 24 hours or 7 days of WAF logs to see, before deploying, which requests it matches and how many requests and IPs it would affect.

COUNT → BLOCK

Switch safely from Count

Run new rules in Count mode to watch their behavior, and switch to Block after confirming sufficient observation and no false-positive candidates. For each rule, choose Block, Count, CAPTCHA, Challenge or a custom response.

Supported tech stacks

CMS
WordPressDrupalJoomla
Languages and runtimes
PHPPythonNode.jsJavaRuby on Rails
Frameworks
SpringApache Struts2Next.js / ReactDjango / Jinja2FreemarkerVelocitySmartyHandlebarsPug
Databases
MySQLSQL ServerPostgreSQLOracleMongoDBCouchDBRedisLDAP
API
REST / JSONGraphQLXMLJWT
Servers and products
ApacheTomcatWebLogicExchangeConfluenceJenkinsCitrix ADCF5 BIG-IPIvantiFortinetPalo AltoCisco IOS XE
Cloud
AWSGoogle CloudAzureOracle CloudDigitalOceanOpenStack

Use-case templates

  • Website (standard protection)
  • Website (strict)
  • API server
  • CMS - WordPress
  • CMS - Drupal
  • CMS - Joomla
  • High-risk applications
  • Bot defense only

Please note: Rules are deployed as rule groups in your AWS WAF, and for each rule you can choose Block, Count, CAPTCHA or Challenge. We recommend first checking impact in Count mode and promoting to Block after a period of observation. Library updates take effect when you redeploy. Rules can be combined within the AWS WAF rule group capacity (WCU).

Bot defense

One technique is not enough for bot defense

Scrapers, credential stuffing, crawler impersonation, attacks that keep going while rotating IPs. Effective countermeasures differ by type of bot. WAAP lets you combine multiple approaches as standard WAF rules, without subscribing to AWS's paid bot-defense rule groups. Everything is off by default, and for each feature you choose Suggest or Auto.

VERIFIED BOTS

Identifying legitimate bots

Major crawlers such as Google, Bing, OpenAI, Anthropic, Perplexity, Apple and DuckDuckGo are checked against the IP ranges each company publishes. Genuine ones are labeled and allowed through, and impersonators that only copy the name are detected.

JA3 / JA4

TLS fingerprints

Scrapers and attack tools that spread requests across changing IPs are identified by their TLS fingerprints, so you can quarantine by “tool” rather than by IP. JA4 features are used as inputs to the score and do not trigger blocks on their own.

IP / UA / ASN

Bot score

Multiple signals, such as skewed sessions or UAs and a small variety of TLS types, are scored per IP, User-Agent and ASN. To avoid mistakenly stopping companies behind NAT or legitimate users who only use an app, scoring measures how far signals exceed a baseline.

CREDENTIAL ATTACK

Protecting login and sign-up pages

Rate limits and checks for missing required fields are placed on login and sign-up paths as WAF rules, and signs of credential stuffing are scored separately from logs. With CloudFront / ALB access logs, concentrated login failures are also detected.

COORDINATED

Coordinated attack detection

Distributed attacks in which many IPs hit the same URI at once are detected every 10 minutes, and the IPs involved are quarantined together with an expiry.

THREAT INTEL

Threat intelligence integration

Public lists of botnet C2 servers and malicious TLS fingerprints are imported and applied to WAF rules at a confidence threshold you set. Check the impact in Count mode first, then switch to Block.

Please note: Some capabilities provided by AWS's paid rule groups (Bot Control / Account Takeover Prevention / Account Creation Fraud Prevention), such as per-username aggregation and token-based legitimate-client verification, cannot be replicated equivalently due to how WAF rules work. Where needed, we can also advise on using them alongside the paid rule groups.

Better together

Combine with other Web Security services
to cover the full cycle of web protection

A WAF alone can't cover knowing which entry points to protect, the latest information on attackers, or finding attacks that slipped through. With WAAP at the center, combining threat intelligence, ASM and defacement detection connects “find, know, stop, notice” in a single console.

THREAT INTELLIGENCE HUB

Attacker information, into your WAF rules

Malicious IP lists gathered by threat intelligence are automatically applied to your WAAP policy at a confidence threshold you set. Malicious TLS fingerprints are also used in WAAP detection. Check the impact in Count mode first, then switch to Block.

ASM

Unseen entry points, brought under protection

Of the live subdomains and servers ASM finds, you can add the ones that need protection to WAAP's protected targets. When a new vulnerability is disclosed, use ASM to identify the affected assets, and strengthen protection with the WAAP rule library until they are fixed.

DEFACEMENT DETECTION

Notice attacks that slipped through, right away

Defacement detection catches attacks the WAF could not stop, and unauthorized updates made from an admin panel, from changes to pages and scripts. The techniques it uncovers can feed your next line of defense through WAAP custom rules and log investigation.

Please note: Each service is contracted individually. Applying threat intelligence to WAAP requires contracts for both services.

Log forensics

Investigate WAF, CloudFront and ALB logs
right where they are

When you're attacked, the first thing you want to know is “who did what, and where.” With WAAP log investigation, you can search across the logs in your S3 from the console, covering not only WAF events but also CloudFront and ALB access logs and even CloudTrail. There is no need to forward or copy logs. Just enable the log sources you want to use, and they become available for investigation.

AWS WAF

WAF events

Filter blocked and counted requests by source IP, URI, rule and country. Aggregation templates instantly show top IPs, top URIs, top rules, breakdown by country and block count trends.

CLOUDFRONT

CloudFront access logs

Aggregate every request that reached the edge by status code, referrer and client. Check for error spikes and see the actual responses to requests that passed the WAF.

ALB

ALB access logs

In addition to aggregation by target, client and status code, extract slow-responding requests and check error trends. Also used to detect concentrated login failures.

CLOUDTRAIL / VPC / DB

CloudTrail and beyond

Investigate denied CloudTrail operations, console logins, role assumptions, IAM changes and destructive operations. VPC flow logs and MySQL and PostgreSQL logs are also supported.

From enabling to investigating

  1. Register log sources

    Specify an existing log bucket, and the storage format and partitions are detected automatically to create tables for search.

  2. Access logs enabled for you

    If CloudFront / ALB access logs aren't set up, they can be enabled for you from the console. A list also shows which features use which logs.

  3. Investigate with templates

    Just choose an aggregation template and filter conditions to investigate without writing SQL. Partitions are narrowed by time range, so short investigations don't scan every record.

Please note: Searches run on Amazon Athena in your AWS account, and logs do not leave your S3. Athena scan charges and log storage charges are incurred as part of your AWS usage fees. Each search displays up to 500 rows of results.

Patented detection

Two patented learning models
that find both “missed detections” and “false positives”

What makes a WAF hard is that “missed detections,” which let attacks through, and “false positives,” which stop legitimate users, happen at the same time. Based on Japanese Patent No. 6998099, “Method for detecting fraudulent access requests,” obtained by Classmethod Security (formerly CyberMatrix Co., Ltd.), WAAP combines two learning models to detect both.

MODEL 01

Attack-pattern analysis

A machine learning model that determines whether URI, query and header strings are attacks. It also responds to variants and obfuscation that regular expressions struggle to catch. It runs inside your AWS account and does not send request contents outside.

MODEL 02

Normal-pattern learning

A site-specific model that learns the normal requests actually allowed on that site and determines “whether a request is normal for this site.” The same request can be judged differently on a different site.

ATTACK × UNUSUAL

Detecting missed detections (FN)

Among requests the WAF let through, those that attack-pattern analysis considers attacks and that normal-pattern learning judges different from the site's usual traffic are presented as “missed-detection candidates.” They serve as grounds for adding or promoting rules.

WAF BLOCK × NORMAL

Detecting false positives (FP)

Among requests the WAF blocked, those that normal-pattern learning judges to have the same form as the site's usual traffic are presented as “false-positive candidates.” They come with exclusion conditions, reasons and real request examples, and can be applied in one click.

After onboarding

  1. Attack-pattern analysis is active right away

    Analysis starts with a general-purpose attack-pattern model immediately after connection. The default is Suggest, which only records results and does not affect production.

  2. Learn normal patterns

    Site-specific normal patterns are learned from several days of normal traffic. Training data stays in your S3.

  3. Review and apply candidates

    Missed-detection and false-positive candidates are listed with reasons. Review and apply them, and once you're comfortable, switch each feature to Auto.

Please note: Attack-pattern analysis does not replace regular-expression detection; it adds to it. So that false positives don't lead directly to blocking real users, attack-pattern analysis results are Suggest-only by default and are not used for automatic quarantine.

Specifications

Scope and delivery

Target
  • AWS WAF (WAFv2)
  • Web ACLs associated with CloudFront / Application Load Balancer
Deployment
  • Create an operations IAM role with CloudFormation
  • Place a lightweight agent (Lambda) that analyzes WAF logs in your account
Data location
  • WAF log data itself is stored in your S3
  • Only alert candidates and aggregate values are sent to CyberForces
Notifications
  • Email / Slack / Webhook
  • Weekly and monthly reports
Pricing
  • Usage-based pricing by number of protected requests

Please note: Only AWS WAF is supported (Azure WAF / Google Cloud Armor are not). Some features require additional log sources, such as CloudFront / ALB access logs.

Getting started

Getting started

  1. Create the role

    Create the operations role with CloudFormation, register it in the console and run a connection test.

  2. Connect a Web ACL

    Connect an existing Web ACL, or create a new one and associate it with CloudFront / ALB.

  3. Enable logging

    Once WAF logging is enabled, log search and analysis become available automatically.

  4. Choose automation levels

    Choose Off, Suggest or Auto for each feature. Verify with Suggest first, then move to Auto.

FAQ

FAQ

Do I need AWS's paid managed rules (such as Bot Control)?

No. Bot defense is built from combinations of standard WAF rules. However, some capabilities, such as per-username aggregation, are not equivalent to AWS's paid features.

Will my production WAF settings change without my knowing?

For each feature, you choose Off, Suggest or Auto for automation. Changes are recorded and can be reverted from snapshots.

Works well with

WAAP — details and demo requests

Our team will explain deployment options and pricing for your environment.