The application security technology of Web Application and API Protection (WAAP) is based on a positive security model that ensures correct application behavior. The model is based on HTTP industry standards and best coding practices for APIs, HTML and JavaScript. Application behavior deviating from the positive security model is treated as potentially malicious and is blocked by the WAAP.
Through its understanding of good application behavior, the positive security model does not require attack signatures or pattern matching techniques to detect and block attacks. It is the only proven approach delivering zero day protection against unpublished exploits. The positive security model:
- Models application behavior
- Verifies best practices
- Ensures RFC compliance
- Enforces security in real-time
- Is not signature-based