HabrSeptember 17, 2026🇷🇺Translated from Russian

WAF Connected — What Next? How to Configure Web Application Firewalls for Real Protection Without Disruption

After investing significant time and budget in selecting and integrating a Web Application Firewall, many teams assume the hard work is over. In reality, the most critical phase begins only after initial deployment. Even a well-executed pilot can fail to predict challenges that appear when protecting production applications at scale.

Pilot projects typically involve two or three carefully chosen applications with thoroughly tuned rules. When the same configuration is applied to dozens of additional systems, problems quickly surface. Applications use different technology stacks, exhibit unique traffic patterns, and contain legitimate anomalies that conflict with standard rules. One application may rely on WebSocket connections, while another processes file uploads or uses NTLM authentication through MS Exchange.

A real-world example involved a large online retailer whose main site ran on Bitrix. The pilot succeeded within one week. During full rollout, the CRM system required proxy configuration changes for WebSocket support, the file storage triggered false positives on uploads, and MS Exchange demanded specialized load-balancer settings for NTLM authentication.

Security teams should begin in monitoring (Detect) mode instead of immediately enabling blocking. This approach allows collection of real traffic data, identification of false positives, and creation of targeted exceptions before any legitimate requests are dropped. The monitoring phase usually lasts two to four weeks, or longer for complex applications.

Connecting every application at once is rarely feasible. Organizations should apply a Risk Score calculated from five weighted factors: exposure to attackers, business impact, weakness of existing controls, technical risks such as legacy code, and sensitivity of processed data. This score is then adjusted by threat intelligence signals and organizational resistance to produce a Priority Score that determines connection order.

Even after an application moves to blocking mode, ongoing maintenance remains essential. New releases, changes in access methods, updated regulatory requirements, or fresh threat intelligence can all invalidate previous configurations. Teams must regularly review logs, update rules, and re-evaluate the application registry at least quarterly.

Operationally, a mature WAF should demonstrate a low false-positive rate, allow exception changes within minutes rather than hours or days, and maintain performance during traffic spikes without becoming a single point of failure. The goal is effective protection that does not generate excessive manual workload or create new business risks.

Related articles

SecuritylabOther

Where to Find Scientific Articles and Full Texts in 2026: Russian and International Databases Guide

Finding complete scientific papers often requires navigating multiple platforms because search engines show only titles and abstracts while publishers may demand payment for PDFs. The guide explains the differences between bibliographic databases that help locate publications and full-text repositories that provide actual documents. It covers Russian resources such as CyberLeninka, eLIBRARY.RU with RINC, Math-Net.Ru, and the national platform of scientific journals, along with international tools including Google Scholar, PubMed, arXiv, ACM Digital Library, IEEE Xplore, Scopus, and Web of Science. Additional sections address book catalogs, archives, AI-powered search tools like Consensus, and scientific social networks such as ResearchGate. The material emphasizes that presence in any database does not guarantee quality or validity, urging readers to verify methods, results, and publication status independently. Practical advice is given on locating open-access versions, using library subscriptions, and contacting authors directly.

AntiMalwareOther

Avanpost SmartPAM Adds 60 MITRE ATT&CK Signatures for Privileged Session Threat Detection

Avanpost has released an update to its SmartPAM 1.4 solution that incorporates a library of 60 signatures mapped to the MITRE ATT&CK framework. The new capability allows the Privileged Access Management system to monitor and analyze actions performed by administrators inside privileged sessions rather than simply controlling initial access. The signatures cover common attack techniques including credential access, persistence, lateral movement, and defense evasion such as disabling audit logs, antivirus, or firewalls and clearing system events. A built-in signature analysis engine normalizes session data, matches observed behavior against known attack patterns, and triggers automated responses including command blocking, session termination, or SIEM alerts. Customers can combine the vendor-supplied rules with custom policies and will receive regular subscription-based updates at no cost until the end of 2026. Avanpost claims SmartPAM is the first PAM product to offer a MITRE ATT&CK-structured signature library, shifting the tool from a basic access gatekeeper to an active behavioral observer capable of identifying malicious activity even when valid credentials are used.

AntiMalwareOther

Positive Technologies Discontinues Active Development of PT AF 3, Shifts Focus to PT AF PRO and PT Cloud AF

Positive Technologies is halting active development of its PT Application Firewall 3 product and redirecting resources toward PT AF PRO and the cloud-based PT Cloud AF. Existing customers of the legacy WAF will continue to receive technical support, though no significant new capabilities are expected. The company cites the dramatic expansion of modern web infrastructure, which now spans hundreds of applications, APIs, and microservices across data centers, clouds, branches, and subsidiaries. Positive Technologies notes that exploitation of internet-facing web application vulnerabilities remains the leading initial access vector, accounting for 36 percent of successful corporate network intrusions. PT AF PRO, developed from the ground up over more than six years, is positioned as the new flagship solution for large-scale, distributed environments. The cloud offering PT Cloud AF provides a hardware-free alternative that organizations can manage themselves or fully outsource to partners. Client adoption of PT AF PRO has doubled over the past year.

AntiMalwareOther

StormWall Releases StormWall Appliance for On-Premises DDoS Protection

StormWall has introduced StormWall Appliance, a software solution that filters DDoS attacks inside the customer's own infrastructure rather than routing traffic to an external cloud. The product is aimed primarily at banks, hosting providers, internet service providers, and organizations with strict requirements for infrastructure availability and data control. It supports fully isolated networks through offline licensing with a hardware key and can operate independently or in a hybrid mode with StormWall's cloud platform. The appliance handles attacks at OSI layers L3 through L5, including volumetric floods, TCP stack attacks, reflection and amplification schemes, DNS attacks, and gaming protocols. It also processes TLS and QUIC traffic without decryption using DPDK and proprietary algorithms. Deployment takes as little as one day, with a 30-day free trial available after installation.