The goal of the WAFEC project is to help organizations evaluate WAFs, said project leader Ivan Ristic, founder of Web application security company Thinking Stone Ltd. in London. The project group, which is made up of WAF vendors, security professionals and WAF users, spent most of 2005 debating the various requirements.
A WAF can use a proxy-based architecture, a deep packet inspection-based architecture — or both. The intent, said Jeremiah Grossman, a project contributor and founder and chief technology officer of WhiteHat Security in Santa Clara, Calif., is not to recommend certain features, but rather to “give someone a way to compare one firewall to another.” Categories covered in the document include deployment architecture, HTTP and HTML support, detection techniques, protection techniques, logging, reporting, management, performance and XML.
WAFs target the application layer, not the network WAFs address different issues than network firewalls, which defend the perimeter of a network, Kraynak said. If you don’t have a Web application firewall in front of the application, you don’t know what’s happening and you’re not in control,” he said. Grossman added: “We’ve had network firewalls for many years, and nobody claims they stop everything.
WAFs haven’t taken hold Boston-based Yankee Group has labeled the WAF market “mature” but says it has not really gained traction. In comparison, the overall security market has grown at a 20% to 30% pace during the past five years, according to Yankee Group. Yankee Group predicts that the WAF market as it exists today will be subsumed in a few years by a larger market: application assurance platforms, which will combine WAFs, database security, XML security gateways and application traffic management segments.
http://searchappsecurity.techtarget.com/originalContent/0,289142,sid92_gci1163145,00.html