Rethinking Web Application Firewalls

📅 2026-09-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
为解决应用层DDoS攻击防御成本高和延迟问题,本文提出Shimmer,一种通过JIT编译规则集并进行高级优化以减少不必要工作的高效WAF。
📝 Abstract
In recent years, the threat of application-layer (L7) distributed denial-of-service (DDoS) attacks is ever increasing. To defend against them, network operators deploy web application firewalls (WAFs). WAFs are stateful scoring systems which are configured with a rule set that specifies what malicious traffic looks like, and how to handle it. While effective, WAFs are expensive and can increase the request latency of realistic applications by up to $4\times$. This paper introduces Shimmer, a highly optimized WAF. Shimmer JIT-compiles the rule set and applies advanced optimizations to avoid unnecessary work in the scoring pipeline.
Problem

Research questions and friction points this paper is trying to address.

application-layer DDoS
web application firewalls
request latency
Innovation

Methods, ideas, or system contributions that make the work stand out.

Shimmer
JIT-compiles
advanced optimizations
scoring pipeline
🔎 Similar Papers
No similar papers found.
L
Laurin Brandner
ETH Zürich
L
Laurent Vanbever
ETH Zürich