The WAF must die – some interesting thoughts – FireTail Blog
嗯,用户让我总结一篇文章,控制在100字以内,而且不需要特定的开头。我得先通读一下文章内容。 文章主要讲的是WAF(Web应用防火墙)的不足之处。Dr. Chase Cunningham在LinkedIn上发帖,认为WAF已经过时了,不能有效防御现代攻击。FireTail.io也支持这个观点,他们提到WAF基于传统的防火墙结构,无法应对零信任环境的需求。 文章还引用了Ponemon的研究数据,显示很多组织虽然认为WAF重要,但实际使用中效果不佳,比如超过40%的组织只用它来生成警报,而没有阻止攻击。此外,管理WAF需要大量的人力和时间成本,年均花费高达62万美元。 作者还提出了替代方案,比如Web应用隔离(WAI),但FireTail.io对此有保留意见,认为对于公共应用可能有效,但需要更好的授权控制和API安全配置。 所以总结起来,文章的核心是批评WAF的局限性,并提出替代方案。我需要用简洁的语言涵盖这些要点。 </think> Dr. Chase Cunningham和FireTail.io认为传统Web应用防火墙(WAF)已无法有效应对现代网络安全威胁。WAF基于规则和模式匹配的防御机制与零信任架构不符,且管理复杂、成本高昂。研究显示多数组织依赖WAF仅生成警报而非阻止攻击。作者建议采用更灵活的安全策略如API安全配置和隔离技术来替代传统WAF。 2025-12-19 11:14:53 Author: securityboulevard.com(查看原文) 阅读量:4 收藏

A recent posting by Dr. Chase Cunningham from Ericom Software on LinkedIn took an interesting view on web application firewalls, most commonly known as a WAF.

WAF’s Must Die Like the Password and VPN’s

Here at FireTail.io, we are also not fans of a WAF. Why? We do not believe that a WAF will catch most modern attacks. WAFs are fundamentally based on firewall (perimeter defense) structures that are designed to keep attackers out based on where they are coming from, where they are going to, and what they are trying to access. A simple search for bypassing a WAF returns quite a lot of results:

Bypass WAF, 1.28M results

Dr. Cunningham’s post shares some interesting opinions and statistics on WAFs:

  • “WAFs are antithetical to the move to Zero Trust”
  • “According to most innovators and experts, the pattern and rule-based engine used by WAFs are not aligned with current security needs.”
  • “Ponemon conducted research at that time to probe the market for issues with WAF solutions, and more than 600 respondents made their point clear: WAFs aren’t helping.”

The Ponemon WAF research referenced also included some eye-opening statistics:

  • While 66% of respondent organizations consider the WAF an important security tool, over 40% use their WAFs only to generate alerts (not to block attacks)
  • 86% of organizations experienced application-layer attacks that bypassed their WAF in the last 12 months.
  • Managing WAF deployments are complex and time-consuming, requiring an average of 2.5 security administrators who spend 45 hours per week processing WAF alerts, plus an additional 16 hours per week writing new rules to enhance WAF security.
  • The CapEx and OpEx for WAFs together average $620K annually. This includes $420K for WAF products, plus an additional $200K annually for the skilled staffing required to manage the WAF.

SUMMARY OF WAF FAILURES FROM DR. CHASE CUNNINGHAM

If you wanted the tl;dr version of what Dr. Cunningham had to say, it’s this:

In other words, WAFs are not stopping attacks, require continuous configuration and intensive management and security human capital, and are more expensive than other better-suited technologies.

WHAT IS A BETTER APPROACH THAN USING A WAF THEN?

This is where our view may both overlap with and also differ from from Dr. Cunningham’s. Dr. Cunningham speaks of the model of Web Application Isolation (WAI), whereby an application is effectively public on the Internet, but only behind a required authentication controller, and then creates a secure tunnel.

Our view on this is two-fold:

  • For public or consumer applications, this can work. But it requires an immediate control for authorization. Too often, developers assume controlled inputs and no attempts at unauthorized access. But the provisioning of a “secure tunnel” is something that happens already via SSL / TLS, and there’s no need for another “secure tunnel”.
  • Applications need to have a security configuration of their own that defines authorization options around various API routes and methods, because the API is both the future of application development paradigms, and the API will become the most frequently attacked surface / vector.

Please contact us if you want to hear more about our view on WAFs for API security.

*** This is a Security Bloggers Network syndicated blog from FireTail - AI and API Security Blog authored by FireTail - AI and API Security Blog. Read the original post at: https://www.firetail.ai/blog/the-waf-must-die-some-interesting-thoughts


文章来源: https://securityboulevard.com/2025/12/the-waf-must-die-some-interesting-thoughts-firetail-blog/
如有侵权请联系:admin#unsafe.sh