What is web app and API protection (WAAP)?
Web App and API Protection (WAAP) is a specialised tool for protecting web applications and APIs (including web or micro services).
Core functions of a WAAP solution:
- Bot Management: Protection against malicious bots (incl. automated attacks from vulnerability scanners or content scrapers).
- Protection against DDoS attacks at application level (L7)
- Web Application Firewall (WAF): Protection against web application attacks such as OWASP Top 10 vulnerabilities
- API Protection: Defence against attacks and unauthorised access to internal and public APIs, incl. protection of OWASP API Top 10 vulnerabilities
- Access Management: Modern WAAP solutions cooperate with an IAM system to offer upstream authentication and to achieve continuous adaptive trust.
In the past, these functions were often performed by separate components such as a web application firewall (WAF) or an API security gateway. Because the boundaries between APIs and web applications are becoming increasingly blurred, these markets have consolidated. A WAAP solution can be operated either in the cloud or on-premise.