Edge cloud platform provider Fastly launched its new managed security service yesterday in an attempt to help organizations deal with the ongoing deluge of web Application attacks.

One of the tools organizations use to help defend against web Application attacks, is a Web Application Firewall (WAF).  As opposed to a regular network firewall, a WAF is purpose-built for layer 7 Application traffic and is designed to help mitigate Application attack risks. Fastly added WAF services to its portfolio in 2020 as part of the acquisition of Signal Sciences. The new managed security service is designed to enable Fastly's WAF customers to detect and remediate attacks faster.

The new service is not the first time that Fastly has offered managed security capabilities. In 2021, the company launched its Response Security Service offering, providing customers with on-demand support in near real-time if they found themselves under attack.

Gino Lang, Fastly’s vice president, customer security, told SDxCentral that with the new service, Fastly's Customer Security Operations Center team jumps in to start investigating and mitigating right away, all while keeping the customer updated. Fastly will also perform regular threat hunting to look for threats that are just emerging, or opportunities for additional tuning or configuration improvements.

Why You May Need a Web Application Firewall (WAF)

WAF technology when properly deployed and configured can be effective at blocking emerging threats.

For example, Lang noted that a next-generation WAF enables a virtual patching capability that can block attacks against potentially vulnerable applications that haven't yet been directly patched themselves. One such use case was triggered in December 2021 when the Log4J attacks first began and Fastly was able to support its WAF customers with a virtual patch.

“By monitoring customer traffic patterns and anomalous activity we can detect and mitigate threats to uptime from sophisticated DDoS attacks and other abuse, including credential stuffing and site scraping,” Lang said, adding that its WAF supports integration with third-party SIEMs [security information and event management] and other products.

A challenge with some security technologies is that the organization will deploy them in monitor-only mode to gain visibility into threats, but not in full blocking mode, which would actually block attacks. The concern in many cases is that false positives can impact overall user experience.

According to Lang, that's not the case with the Fastly Next-Gen WAF, with over 90% of users running in full blocking mode. Lang noted that the reason why users are confident enough to deploy in full blocking modes is because of the SmartParse detection technology used by Fastly. He claimed that it provides a lower false positive rate than competing products, which makes it easier to maintain and operate for organizations.

Some enterprises are still looking for fully managed solutions or to extend their own security staff and capabilities, Lang said.  Leveraging its Customer Security Operations Center team, which monitors what’s happening on the global Internet, the Fastly Managed Security Service is designed to detect and mitigate attacks faster and in most cases more effectively, he said.