What is our primary use case?
Imperva Managed Rules on AWS WAF protects our web-facing applications and APIs hosted on AWS by defending against OWASP Top 10 attacks. We use it for bot traffic management and to guard against different attacks including injection and server-side request forgery to protect our web-facing applications and APIs in our AWS environment.
A specific example of how I have used Imperva Managed Rules on AWS WAF to protect our web applications and APIs occurred when we experienced an influx of traffic and investigated a possible distributed denial-of-service attack from ranges in the target environment. We were able to enable Imperva to guard against the bot attack by activating Imperva Managed Rules alongside AWS to automatically block different forms of attacks such as SQL injection, which we were simultaneously receiving. We effectively blocked SQL injection, XSS attempts, and malicious bot traffic while allowing legitimate API requests. The managed rules significantly reduced false positives compared to our earlier custom rule sets, improved visibility into attack patterns, and reduced the time our team spends analyzing.
Beyond bot management, we use Imperva Managed Rules on AWS WAF to protect our web application from attacks and our API. We need to defend against different attack patterns, and we leverage the popular patterns specified by OWASP Top 10 for API protection. We use Imperva Managed Rules on AWS WAF to provide third protection across multiple AWS workloads, supporting our compliance and helping us to rapidly respond to newly discovered vulnerabilities through managed rules without having to develop and deploy custom rules.
My advice to others looking into using Imperva Managed Rules on AWS WAF would be to start by deploying the managed rules in a monitoring or count mode before enforcing them to identify false positives and tune policies based on your application's normal traffic. Additionally, combining managed rules with application-specific custom rules for comprehensive logging and monitoring, and regularly reviewing logs to optimize protection would be beneficial. Finally, keep the managed rule updates enabled to benefit from the latest threat intelligence while periodically validating that rules do not adversely affect legitimate traffic.
What is most valuable?
Some of the best features that Imperva Managed Rules on AWS WAF offers include continuous updates to managed rules, providing rapid protection against emerging threats without manual rule deployment. It also includes coverage of OWASP Top 10 and other common web attacks, going beyond that by covering bot and malicious IP detection that helps reduce automated attacks and credential stuffing attempts. Additionally, it integrates well with AWS WAF, making deployment and management straightforward within the AWS environment. We reduce the effort required to create and tune custom rules while maintaining strong protection, along with good visibility and logging which enables us to analyze attack patterns, tune policy, and respond to incidents more effectively.
Continuous updates with Imperva Managed Rules on AWS WAF make deployment and management straightforward within the AWS environment, helping us configure things easily. The continuous updates enable our team to not have to constantly create and maintain custom signatures for newly disclosed vulnerabilities. Since Imperva released updated managed rules, we can apply protection much faster, reducing our exposure window while minimizing operational effort. AWS WAF integration has also simplified our operations; we manage protection within our existing AWS security workflows, making it easier to deploy rules updates across our multiple applications, and it helps us monitor events through AWS logging and monitoring services.
Since we started using Imperva Managed Rules on AWS WAF, the biggest positive impact has been stronger application security with less operational overhead. We have been able to block common web attacks more consistently and reduce false positives through rule tuning, responding more quickly to emerging threats via managed rules updates. This has improved the reliability of our security protections and allowed my security team to focus on more proactive security activities instead of continuously maintaining custom WAF rules.
We have seen a number of metrics since deploying Imperva Managed Rules on AWS WAF. For instance, we have not encountered any breaches or attacks due to our web applications. We have also been able to reduce or stop some attack patterns and observed approximately a 40 to 50% reduction in the time we spend maintaining and updating WAF rules, as much of that work is handled through Imperva Managed Rules on AWS WAF updates. We have seen faster response to newly disclosed web application vulnerabilities, fewer false positives after tuning, and successful compromise of internal patient data has been noted due to the attack attributed earlier. This has enabled our team to focus more on proactive security initiatives rather than routinely managing the WAF.
What needs improvement?
Imperva Managed Rules on AWS WAF can be improved in several ways. First, better rule transparency would be beneficial, with more detailed explanations of why specific requests are blocked and what rules are designed to detect. More granular tuning options to reduce false positives without requiring custom exceptions would be helpful, as well as improved reporting and analytics. A richer dashboard that highlights attack trends, rule effectiveness, and actionable recommendations would enhance the overall experience.
It would also be beneficial for Imperva Managed Rules on AWS WAF to have faster customization workflows, making it easier to test, deploy, and validate rule changes across different environments. Enhanced API-specific protection and visibility, particularly for modern REST and GraphQL APIs, with more detailed insights into API attack patterns and recommendations, would also improve usability.
I rated Imperva Managed Rules on AWS WAF an eight out of ten because it provides strong security value and is reliable in production, but there is still room for improvement in usability and visibility. To rate it nine out of ten, I would like to see more detailed explanations of rule matches and blocking decisions to simplify troubleshooting, more granular policy tuning and exception management to reduce false positives, a richer dashboard, and actionable insights on threats and rule effectiveness.
For how long have I used the solution?
I have been using Imperva Managed Rules on AWS WAF for the past five years.
What do I think about the stability of the solution?
Imperva Managed Rules on AWS WAF is stable.
What do I think about the scalability of the solution?
The scalability of Imperva Managed Rules on AWS WAF is good, and I would rate it nine out of ten, as it deploys through AWS WAF and scales well with our cloud-native applications and APIs without requiring additional infrastructure.
How are customer service and support?
My experience with customer support has been positive.
Which solution did I use previously and why did I switch?
Before adopting Imperva Managed Rules on AWS WAF, we primarily relied on native AWS managed rules combined with internally developed and deployed AWS WAF rules. We switched because we wanted broader threat coverage and more frequent managed rules updates driven by threat intelligence.
What was our ROI?
We have seen a significant return on investment from Imperva Managed Rules on AWS WAF. We have been able to reduce the time spent maintaining and updating our WAF by 50%, achieved faster responses to newly disclosed vulnerabilities with no need for additional headcounts to manage the WAF, resulting in low incident investigation effort and reduced operational costs. The total cost of ownership is very reasonable.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is positive.
Which other solutions did I evaluate?
We evaluated other options before choosing Imperva Managed Rules on AWS WAF, including F5, Cloudflare, and Akamai.
What other advice do I have?
Regarding Imperva Managed Rules on AWS WAF's AI capabilities, I rate its governance and security as good, although it is still evolving. The platform does a strong job of using threat intelligence and automated rule updates to protect against common web attacks, reducing manual effort and improving response to emerging threats. However, when it comes to AI-specific governance, such as protecting AI applications and LLMs, particularly in detecting prompt injections, monitoring AI-specific user patterns, and enforcing AI usage policies, it is not yet as advanced as dedicated AI security tools. Overall, its AI capabilities are valuable for enhancing traditional web application security, but organizations deploying generative AI or AI-powered APIs may need additional AI security controls and governance solutions alongside Imperva Managed Rules on AWS WAF.
I would describe the accuracy and reliability of Imperva Managed Rules on AWS WAF as good, and rate it an eight out of ten because the managed rules are generally effective at identifying and blocking common web attacks with relatively low false positives.
Overall, Imperva Managed Rules on AWS WAF is a strong solution for organizations running their web applications and APIs on AWS. It provides solid protection against common web attacks, reduces the operational burden of maintaining WAF rules, and benefits from regular threat intelligence updates. My overall rating for this solution is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)