

Imperva and AWS WAF compete in the web application security category. Imperva seems to have the upper hand due to its advanced security features and comprehensive deployment options.
Features: Imperva offers advanced features like DDoS protection, WAF, CDN, and real-time traffic analysis. Its threat radar and virtual patching are crucial for large enterprises. AWS WAF provides essential WAF services with cloud-native scalability, ease of use, and integration with other AWS services.
Room for Improvement: Imperva could improve in areas such as reliability, reporting, real-time visibility, mobile app interfaces, and caching rules. AWS WAF can work on enhancing rule management, geographical restrictions, and better initial setup documentation.
Ease of Deployment and Customer Service: Imperva supports diverse infrastructure needs with on-premises and hybrid cloud deployment, though it has been reported as unstable by some. Its customer service, though knowledgeable, is critiqued for slow response times. AWS WAF is optimized for public cloud deployments with strong integration for AWS users. While some praise its rapid support, AWS service quality can be inconsistent.
Pricing and ROI: Imperva typically charges higher premiums due to its advanced features, making it expensive for full-scale deployment. AWS WAF offers a pay-as-you-go model that is cost-efficient for small to medium enterprises, though costs can increase with higher rule usage or traffic. Both solutions provide solid protection with potential for significant ROI against web attacks.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
I would rate the technical support of Imperva DDoS as ten.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
We faced issues with AWS WAF when writing the custom rules.
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
I switched from other vendors to prioritize AWS WAF for better control within our infrastructure.
I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website.
| Product | Market Share (%) |
|---|---|
| AWS WAF | 5.8% |
| Imperva Application Security Platform | 7.6% |
| Other | 86.6% |

| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 12 |
| Large Enterprise | 26 |
| Company Size | Count |
|---|---|
| Small Business | 83 |
| Midsize Enterprise | 25 |
| Large Enterprise | 61 |
AWS Web Application Firewall (WAF) is a firewall security system that monitors incoming and outgoing traffic for applications and websites based on your pre-defined web security rules. AWS WAF defends applications and websites from common Web attacks that could otherwise damage application performance and availability and compromise security.
You can create rules in AWS WAF that can include blocking specific HTTP headers, IP addresses, and URI strings. These rules prevent common web exploits, such as SQL injection or cross-site scripting. Once defined, new rules are deployed within seconds, and can easily be tracked so you can monitor their effectiveness via real-time insights. These saved metrics include URIs, IP addresses, and geo locations for each request.
AWS WAF Features
Some of the solution's top features include:
Reviews from Real Users
AWS WAF stands out among its competitors for a number of reasons. Two major ones are its user-friendly interface and its integration capabilities.
Kavin K., a security analyst at M2P Fintech, writes, “I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through.”
Imperva Application Security Platform delivers comprehensive and continuous web threat protection. Renowned for its ease of use, it shields web applications and databases from various cyber threats while integrating seamlessly with cloud and on-premises environments.
Imperva Application Security Platform protects web environments by offering advanced security measures against threats like DDoS attacks, SQL injections, and cross-site scripting. As a robust web application firewall, it provides extensive monitoring and bot management capabilities. The platform integrates content delivery networks for enhanced performance and scalability, while real-time traffic analysis ensures consistent protection. Despite its strengths, improvements can be made in policy management and customization options. Users seek better integration with third-party tools and more competitive pricing models. The inclusion of AI for enhanced analytics is also anticipated.
What are the key features of Imperva Application Security Platform?Imperva Application Security Platform is implemented in industries needing strong database and application protection. Companies use it to enforce geolocation restrictions and manage bots, benefiting sectors like finance and e-commerce where data security and threat monitoring are critical. Its ability to protect and ensure data accessibility makes it integral to business operations prioritizing cyber resilience.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.