arXiv · 2609.25892
Rethinking Web Application Firewalls
Abstract
In recent years, the threat of application-layer (L7) distributed denial-of-service (DDoS) attacks is ever increasing. To defend against them, network operators deploy web application firewalls (WAFs). WAFs are stateful scoring systems which are configured with a rule set that specifies what malicious traffic looks like, and how to handle it. While effective, WAFs are expensive and can increase the request latency of realistic applications by up to $4\times$. This paper introduces Shimmer, a highly optimized WAF. Shimmer JIT-compiles the rule set and applies advanced optimizations to avoid unnecessary work in the scoring pipeline.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Laurin Brandner, Laurent Vanbever. 2026-09-22. Rethinking Web Application Firewalls. https://doi.org/10.3929/ethz-c-000804191
Cite the original work for its findings. Save a collection to share your selection of sources.