Rethinking Web Application Firewalls
In the authors' words
In recent years, the threat of application-layer (L7) distributed denial-of-service (DDoS) attacks is ever increasing. To defend against them, network operators deploy web application firewalls (WAFs). WAFs are stateful scoring systems which are configured with a rule set that specifies what malicious traffic looks like, and how to handle it. While effective, WAFs are expensive and can increase the request latency of realistic applications by up to . This paper introduces Shimmer, a highly optimized WAF. Shimmer JIT-compiles the rule set and applies advanced optimizations to avoid unnecessary work in the scoring pipeline.
Main resultThe abstract does not state a limitation.
Appeared: Wednesday, September 23. arXiv. Preprint with a published version.
Published version: 10.3929/ethz-c-000804191