Imperva DDoS vs Imperva Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 18, 2022
 

Categories and Ranking

Imperva DDoS
Ranking in Web Application Firewall (WAF)
18th
Average Rating
8.6
Number of Reviews
75
Ranking in other categories
CDN (6th), Distributed Denial of Service (DDOS) Protection (7th)
Imperva Web Application Fir...
Ranking in Web Application Firewall (WAF)
6th
Average Rating
8.6
Number of Reviews
47
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2024, in the Web Application Firewall (WAF) category, the mindshare of Imperva DDoS is 2.1%, down from 2.3% compared to the previous year. The mindshare of Imperva Web Application Firewall is 6.7%, down from 7.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF)
Unique Categories:
CDN
6.5%
Distributed Denial of Service (DDOS) Protection
8.4%
No other categories found
 

Featured Reviews

SA
Mar 3, 2020
Stops web attacks from denying services and endangering the security of sensitive data
If I had the opportunity to recommend an enhancement to Imperva it would be to have more POP (Point of Presence) in East and West Africa, and in Central Africa as well. There is only one POP in South Africa. There are other ones are in Europe, America, and Asia and sometimes the latency can be an issue because for your traffic to hit the website — say in East Africa. First, it has to first go to the nearest point of presence. Because of the distance, there can be some problems. So if they have a POP closer to manage customers around Africa this could be a better service to clients.
HV
Feb 28, 2024
Stops bot attacks completely and has easy deployment
We were facing issues related to web servers and OWASP Top 10. We had bots rather than human traffic. We went with Imperva for a single-stack solution. We have bot protection, DDoS protection, web application firewall, and database security from Imperva. It is one of the best solutions that I have worked with. After deploying it, bot attacks have completely stopped. When it comes to OWASP Top 10, it responds very clearly when we do testing, so we are not facing any threats. Compliance is also very good. So, overall, it is very good for security and compliance. Imperva is known in the market for customization and deployments according to the use cases of the customers. You can deploy it the way you want. You can deploy it in the inline mode, reverse proxy mode, or transfer and bridge mode. You can deploy it according to the environment or infra of the company. In terms of integration, with one click of a button, you can integrate it with your SIEM solution. You have preconfigured SIEM codes. You just need to run that code in the SIEM application, and that is it. You will start getting the logs. It is pretty easy. For certain web servers, I have it on-prem, and for certain web servers, I have it on the cloud. A basic use case of the customers is that they want a single dashboard for the cloud WAF or on-prem WAF. There is a solution called attack analytics in Imperva. It integrates with on-prem and the cloud, so in a single dashboard, you can see what is happening in your on-prem as well as cloud setup. It is very easy. When it comes to reporting, you can take reports anywhere anytime and you can take logs anywhere anytime. Someone who does not know about cybersecurity can understand the logs. Logs are in English instead of the raw format. Anybody who knows English can understand them. Reporting is very easy. These reports can also be used for audit and compliance. We use SIEM solutions. We use Splunk, and we use Elastic. We use Datadog and Securonix. I integrated Imperva with Elastic and Splunk. We have a pre-written code. We just have to download that code and run the code in the SIEM solution server. After that, the logs start showing. It is that easy. Integration is that easy. I have also done integration with multifactor authentication, security key, HSM, etc. I have worked with RSA and YubiKey. Both of them were very easy. The integration happened with the click of a button. The integration is seamless and is working perfectly. Our clients are happy. We are happy.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"On the site security, I can see which countries have incidents, whether it was a robot attack, a real human user, or non-human user."
"Its unique interface for managing security performance and ease of use are the most valuable features of this solution."
"Scalability is pretty easy on the base platform. You just add another, and you're ready to go."
"Provides Anti-DDoS protection, as well as other protections like SQL injection, Cross-Site Scripting, and antiscanner. These types of protection are valuable to the business due to the daily attacks on our portals, and that often cannot be seen without a tool like this."
"The solution has a very good interface."
"The most valuable features are DDoS protection."
"There is no need to have an appliance in house for the services because it is on the cloud."
"On the activity log, I can see the exact details, the visit, and the threat."
"Imperva WAF's strongest features are the detection of web application threats and vulnerabilities in the source code."
"The solution is scalable."
"The compliance is the most valuable aspect."
"The tool's profiling feature maps all the web application directories and related components on the profile directory. It has improved the security of my client's website applications."
"The solution is very scalable. It is one of the most important features. You can also expand resources and features as well."
"It mitigates all of the availabilities of risks around web applications."
"Imperva is easy to use and deploy. The UI is excellent."
"There is a quick switch between any of the the nodes if something goes wrong, where there's a there's an attack against a specific area. The security setup is reasonably easy. It's not a problem to do setups and rules and integrations. And, yeah, just the the back end team is also very willing to insist if there's questions that that we cannot answer or with these questions that we do have"
 

Cons

"The log analytics interface within Incapsula isn't really good. For example, if you have to get all logs from there, it's a very cumbersome process."
"Imperva always needs to adjust to new versions of cyber attacks, it needs to be faster, improve the resiliency of the software of the solution."
"It needs to be improved every time there are new attacks."
"Imperva DDoS does not provide version control."
"I would like to see automated reporting to improve visibility."
"The weakest point of Imperva is their first level of support, which should be improved. They should also improve the access and security logs viewing directly on the portal. I would like to see better access and security logs through the portal and not only through a SIM solution. Currently, if you want to explore your access and security logs from Imperva, you need a SIM tool or a SIM infrastructure on your side to do it. You can't do it manually or directly through the portal, which is a big problem for us. I had a call yesterday with Imperva for the roadmap, and I just told them this. They agreed that this is an improvement point from their side."
"Incapsula services also provides load balancing services for their service IP address environment. So far, with monitoring their services, the IP address was only changed once."
"Certificate management could be improved."
"I am looking for more data enrichment. We should have the ability to add our own custom data to the system, to the live traffic."
"The support for the on-premises version needs improvement."
"Imperva Web Application Firewall can improve by adding more features to the dashboard. increasing the visibility of the real-time events, besides configuring the administration itself."
"I think that better bot protection is needed in this solution."
"They recently separated the WAF and the DAM management gateways in order for each of these to be managed from different areas, so I believe it now requires additional investments for what was previously a single complete solution."
"Sometimes, support tickets don't get addressed quickly."
"It would be useful if the solution used more intelligence in attack protection. For example, firewalls are to be dependent on the configuration, but if they could have some data science around it the solution would be even better. The profiling of the traffic, and making decisions surrounding that should be intelligence-based, instead of being based on the configuration of the firewall itself."
"Some of the features should be included in the next release is a file integrating monitoring tool. This feature should be improved."
 

Pricing and Cost Advice

"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a five out of ten."
"The cost is somewhere around $10,000 a site. For every site, you pay individually. For every DNS entry, you have you pay."
"​Although the pricing can be a little high, it is worth the protection and security that it offers.​"
"It is expensive."
"For enterprise contracts you will be in touch with a dedicated account manager who will guide you regarding licensing."
"Pricing could be more competitive."
"We are satisfied with the pricing."
"There is a license or subscription renewal that our customers pay."
"The tool is expensive."
"The solution's pricing is an issue."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"It is a very affordable solution."
"It's an excellent product, but it can be very costly."
"Imperva Web Application Firewall's pricing is expensive."
"The price of this solution is a little bit high compared to competitors."
"There is a license for this solution and we purchase the license annually with no additional fees."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
16%
Manufacturing Company
8%
Government
6%
Financial Services Firm
18%
Computer Software Company
14%
Manufacturing Company
7%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Imperva Incapsula?
We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping.
What is your experience regarding pricing and costs for Imperva Incapsula?
The solution is very affordable. It's based on the traffic utilization, the average traffic utilization, not the DDoS traffic. Therefore, if you're being DDoSed, you don't pay extra for the absorpt...
What needs improvement with Imperva Incapsula?
It’s hard to think of an improvement. The three-second service level agreement is already better than the competition. You would ordinarily say something like API protection. However, they've got t...
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you have to look for other ADC's like F5, Imperva, Radware, Fortinet, etc.
DDoS solutions: Any other solutions to consider aside from Radware DefensePro and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot of DDoS attacks that were well managed (even not seen by the customer) by Imperv...
 

Also Known As

Imperva Incapsula
No data available
 

Learn More

 

Overview

 

Sample Customers

Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Imperva DDoS vs. Imperva Web Application Firewall and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.