Get a free application, infrastructure and malware scan report - Scan Your Website Now

Preventing WAF Bypass: How AppTrana Protects Origin Servers with Resilient Architecture

Posted DateDecember 10, 2024
Posted Time 3   min Read

A recent discovery by Zafran.io reveals critical vulnerabilities in web application firewalls (WAFs) from providers like Akamai and Cloudflare.  

Misconfigured origin validation allows attackers to bypass WAF protections and directly access backend servers, creating opportunities for data breaches, DDoS attacks, and more. 

While most WAF vendors offer IP whitelisting as a solution, implementing it presents significant challenges such as: 

  • Extensive and Dynamic IP Lists  – Many WAF vendors also serve as CDN providers, leading to vast and frequently changing IP lists for customers to whitelist. This complexity increases the likelihood of errors and creates a maintenance burden. 
  • Operational Complexity  – Whitelisting ties customers to the WAF vendor’s architecture. In emergencies requiring WAF bypass, the customer must undo and reconfigure the whitelisting—a time-intensive process that can delay response and increase exposure to attacks. 
  • Whitelist Bypass Risks – For vendors like Cloudflare, which also provide workers, IP whitelisting may not be a secure option. Attackers could exploit workers to launch attacks, bypassing the whitelisting. In such cases, customers must exercise extra caution and consider alternative validation methods, such as header validation. However, this approach is more complex to implement and still less secure.

How AppTrana Ensures Origin Server Protection 

At Indusface, we’ve addressed these issues head-on with  AppTrana, a platform designed to eliminate the risks of misconfiguration while maintaining security and ease of operation: 

1. Mandatory Origin Server Protection 

AppTrana incorporates origin server protection into the onboarding process. All traffic to the backend is restricted to a  whitelisted, controlled IP pool, minimizing the chance of exposure due to dynamic IP lists or manual errors. 

2. Dual-Layer Architecture for Simplified Security 

How does AppTrana's architecture prevent WAF bypass?

Unlike providers combining CDN and WAF into one layer, AppTrana’s two-layer architecture separates these functionalities. This simplifies origin server validation and reduces operational complexity, ensuring only secure traffic flows between the WAF and the backend server. 

3. “Design for Failure” Philosophy 

By adhering to the design for failure principle, AppTrana ensures resilience and high availability, even in adverse conditions. Its bypass fleet provides an additional layer of reliability during emergencies.

When the WAF is bypassed, traffic is still routed through the same trusted IPs, ensuring security and continuity. This eliminates the need for customers to undo whitelisting during crises, resolving a key operational challenge faced by other WAF providers.

Its built-in safeguards ensure customers remain protected against vulnerabilities highlighted by Zafran.io.

Why AppTrana Stands Out

The WAF bypass vulnerabilities revealed by Zafran.io show that even top-tier providers fail to adequately address origin server misconfigurations. AppTrana’s proactive design, mandatory safeguards, and streamlined architecture eliminate these risks, ensuring robust protection for all customers. 

For many WAF providers, origin server protection is offered as an add-on feature, requiring additional configuration and costs. AppTrana includes this protection by default in all its plans. This ensures every customer benefits from robust security without any extra effort or investment.

Conclusion

The challenges of implementing IP whitelisting and maintaining origin server protection are common when using a single provider for CDN and WAF. With AppTrana, Indusface delivers a solution that overcomes these hurdles, providing reliable, easy-to-manage protection against direct to origin attacks. 

Stay tuned for more relevant and interesting security articles. Follow Indusface on FacebookTwitter, and LinkedIn.

AppTrana WAAP

Vivek Gopalan

Vivekanand Gopalan is a seasoned entrepreneur and currently serves as the Vice President of Products at Indusface. With over 12 years of experience in designing and developing technology products, he has a keen eye for building innovative solutions that solve real-life problems. In his previous role as a Product Manager at Druva, Vivek was instrumental in creating the core endpoint data protection solution which helped over 1500 enterprises protect over a million endpoints. Prior to that, he served as a Product Manager at Zighra, where he played a crucial role in reducing online and offline payment fraud by leveraging mobile telephony, collective intelligence, and implicit user authentication. Vivek is a dynamic leader who enjoys building and commercializing products that bring tangible value to customers. In 2010, before pursuing MBA, he co-founded a technology product company, Warmbluke and created a first-of-its-kind innovative Civil Engineering estimator software called ATLAS. The software was developed for both enterprise and for SaaS users. The product helps in estimating the construction cost using CAD drawings. Vivek did his MBA from Queen's University with Specialization in New Ventures. He also holds a Bachelor of Technology degree in Information Technology from Coimbatore Institute of Technology, Anna University, one of the prestigious universities in India. He is the recipient of the D.D. Monieson MBA Award, Issued by Queen's School of Business, presented to a student team which has embraced the team-learning model and applied the management tools and skills to become a peer exemplar. In his spare time, Vivek likes to go on hikes and read books.

Share Article:

Join 51000+ Security Leaders

Get weekly tips on blocking ransomware, DDoS and bot attacks and Zero-day threats.

We're committed to your privacy. indusface uses the information you provide to us to contact you about our relevant content, products, and services. You may unsubscribe from these communications at any time. For more information, check out our Privacy Policy.

Related Posts

Radware WAF Alternatives
Top 5 Radware Alternatives for WAF 2025

Uncover Radware WAF’s pros and cons and explore top alternatives like AppTrana, Akamai, Imperva, Fastly, and AWS WAF to enhance your web application security.

Read More
Gartner Peer Insights Customer Choice 2024
Indusface Recognized as a 2024 Gartner® Peer Insights™ Customers’ Choice for Cloud WAAP

Indusface has once again been recognized as a Gartner® Peer Insights™ Customers’ Choice for Cloud WAAP for three consecutive years (2024, 2023 and 2022).

Read More
Imperva Vs. Cloudflare WAF
Imperva vs Cloudflare WAF 2024

Compare Imperva vs Cloudflare WAF: Key differences in DDoS protection, API security, and pricing to help you choose the best solution for your needs.

Read More

AppTrana

Fully Managed SaaS-Based Web Application Security Solution

Get free access to Integrated Application Scanner, Web Application Firewall, DDoS & Bot Mitigation, and CDN for 14 days

Get Started for Free Request a Demo

Gartner

Indusface is the only cloud WAAP (WAF) vendor with 100% customer recommendation for 4 consecutive years.

A Customers’ Choice for 2024, 2023 and 2022 - Gartner® Peer Insights™

The reviews and ratings are in!