As enterprises struggle to defend against advanced bots and novel API attacks, they are moving away from stand-alone web application firewalls (WAFs) and instead choosing a web application and API protection (WAAP) provider, according to Gartner’s latest Magic Quadrant. There’s also two WAAP leaders in the field, according to Gartner: Akamai and Imperva.

In addition to traditional, web-based applications, organizations need to protect APIs, which now represent 83% of all network traffic, according to Akamai. Because of this, companies “looked for an evolution in their security providers,” beyond a WAF, said Jeremy D’Hoinne, research VP at Gartner. “Many [WAFs] treat APIs like traditional applications, with the same set of signatures and not any specific API protection,” he added. “They need good bot mitigation, good DDoS protection, and API security.”

The WAAP market is the evolution of the WAF. It started with cloud-delivered WAF services, and then some vendors began bundling WAFs with application-layer distributed denial of service (DDoS) protection before eventually adding more advanced bot management and API protection, D’Hoinne explained. These four capabilities now define WAAP, which Garner says is usually delivered as a cloud service.

Which WAAP Vendors Made Gartner’s Cut?

In 2020, Gartner says it saw 15% growth in WAAP inquiries compared with the previous year. This was less because of the pandemic and instead due to organizations expanding their digital transformation initiatives and adding more applications and APIs to their portfolios, according to the analyst firm.

By 2026, Gartner says 40% of companies will select a WAAP provider based on the advanced API protections they offer as well as web application security features, compared to less than 10% this year.

While Gartner always recommends that organizations consider products from at least a couple vendors in all four quadrants (leaders, challengers, visionaries, and niche players), the report authors say this is especially true for the WAAP market because it includes a large number of small players as well as large vendors that only have a small share of their revenue coming from WAAP products.

Still, only two of the 11 vendors that Gartner evaluated made it into the “leaders” quadrant: Akamai and Imperva.

Meanwhile Gartner calls Cloudflare, F5, Fastly, Amazon Web Services, and Barracuda “challengers.” Radware and ThreatX made the “visionaries” quadrant, and Fortinet and Microsoft are the “niche players” of the bunch.

Akamai, a global content delivery network provider that has invested heavily in its security services over the past several years, boasts the most global points of presence (PoP) compared to the rest of the WAAP vendors, according to Gartner. It's also named a Magic Quadrant for WAF “leader” for the past four years.

Akamai Leans Into WAAP

Akamai has two WAAP products: Kona Site Defender (KSD) and Web Application Protector (WAP), which is a lower-priced, limited-feature version of KSD.

Earlier this year, it introduced a new Adaptive Security Engine for web app and API security. It’s designed to automatically adapt protections as attacks become more sophisticated while reducing the effort to maintain and tune policies. It also includes bot visibility and mitigation capabilities.

“The one constant in web application and API security is change,” said Amol Mathur, VP of application and network security product management at Akamai, in a statement about the WAAP Magic Quadrant.

“Akamai has continued to deliver significant advancements in our WAAP products that make it easier for our customers to keep pace with the rapidly accelerating and changing threat landscape, while simultaneously increasing operational efficiencies and developer tooling,” Mathur continued. “We believe these important advancements in our WAAP portfolio contributed to our leader position in this Gartner Magic Quadrant report.”

The Gartner report agrees that Akamai offers more mature API security features compared to its competitors, such as applying behavior anomaly detections for API usage. It also gives Akamai high marks for its API gateway that allows for tighter integration with its API security features.

Additionally, customers praise Akamai’s customer support, including technical and managed services support, Gartner says.

It does, however, caution potential buyers that Akamai doesn’t have a physical appliance WAAP, which means it can’t do hybrid deployments. Also, KSD is complex and its high price may make it unappealing to some enterprise buyers.

And while its Adaptive Security Engine looks promising, it remains “unproven,” Gartner notes. The analyst firm adds that the recommendation engine does not automatically enforce changes, and it says the vendors analytics capabilities remain fragmented over multiple consoles.

“Akamai lags behind several competitors for dedicated mitigation controls to detect human click farms,” according to the Magic Quadrant.

Imperva Makes API Security ‘Top Priority’

While Akamai started with a CDN before moving into security, Imperva is a pure-play security company that has been around for about 20 years. When it comes to securing applications, the vendor is best known for its WAF, but it has been steadily adding capabilities with DDoS, bot, runtime, and account-takeover protection.

Most recently, Imperva has honed in on API security, and says that this year it made protecting customers’ APIs a “top priority.”

To this end, it acquired CloudVector earlier this year. In addition to expanding Imperva’s existing API threat detection and protection capabilities, “the other thing that we really like about the CloudVector acquisition is that it also gives us a better view into what internal APIs and microservices are doing,” Imperva Director of Technology Peter Klimek said.

The vendor has also recently rolled out a new product to secure AWS Lambda serverless functions, a unified management and monitoring platform called Imperva Sonar (based on its  jSonar acquisition), and an improved management console for its WAF gateway, along with a managed DNS service and advanced reporting.

Klimek names Akamai and Cloudflare as Imperva’s top competitors, but while those two started as CDNs before moving into security, “it’s in our DNA,” he said. “We are a security-first company. That is what we focus on. We think about everything from the attacker’s perspective. For [Akamai and Cloudflare], it’s more of something they added later.”

While it provides strong security for hybrid and cloud-only organizations, however, Gartner says Imperva remains challenged to differentiate itself from these leading CDN competitors with its cloud products.

Gartner also notes Imperva’s API discovery is one of its WAAP strengths and adds the CloudVector acquisition “shows the vendor’s willingness to make API security a major component of Imperva Cloud.”

The report authors also like Imperva’s vision with Sonar as a unified management and monitoring console for all of its application security products. Additionally, they note the Imperva Account Takeover module has “several interesting features.” This module can detect credential stuffing and malicious intent from successful logins, plus it lets users chose different actions based on the risk level associated with the account login.

But while Imperva is one of the largest WAAP vendors, Gartner cautions that its worldwide PoPs are limited, particularly in the Asia-Pacific region, and its visibility isn’t growing as quickly as some of its competitors. The report authors estimate that Imperva lost market share because of these factors.

Also, Imperva doesn’t offer a containerized WAAP or the ability to deploy its WAAP as a Kubernetes sidecar.

And Gartner says customers would like the vendor to be more responsive in supporting “low-hanging fruit” like single-sign on for back-end applications and better certificate management. “With the exception of the bot mitigation engines, Imperva Cloud is very signature based, and lags behind some competitors for machine learning-based capabilities,” the report says.