# Solution Brief | Check Point WAF

## Benefits
- **Real-time pre-emptive protection**: Prevent advanced threats including OWASP Top-10 and zero-day attacks with ML-based security without signature updates. For example, Check Point WAF successfully blocked Log4Shell and Spring4Shell without any updates.
- **Precise detection**: Check Point WAF reduces operational overhead by continuously adapting to evolving threats. It delivers accurate detection with minimal false positives, eliminating the fine-tuning and exception handling required by traditional WAFs.
- **Cloud native by design**: Check Point WAF features CI/CD-friendly deployment and automation. From installation to upgrades to configuration, Check Point WAF uses declarative infra-as-code APIs and seamless DevOps integration.

## Challenges
- **Security must evolve as attacks become more sophisticated**: As cyber threats rise, web applications, generative AI workloads, and APIs have become prime targets. Web application firewalls (WAFs) are a critical first line of defense, but modern attacks increasingly rely on evasion methods, payload padding, and zero-day techniques designed to bypass traditional signature-based WAFs. In addition, according to a study by the Ponemon Institute, only 40% of organizations are satisfied with their traditional web application firewalls, in part due to high false positives, high cost, and a reactive approach to security. Today’s security requirements demand real-time prevention with low (or ideally, no) false positives—and a solution that can integrate with AWS services for streamlined, effective prevention against these security issues.

## The Check Point WAF solution
- **Prevention-first unified AI-driven security**: Check Point WAF is an automated solution that delivers superior benefits of a top-tier WAF with generative AI, agentic AI, and API protection, requiring minimal manual intervention. The AI engine continuously learns the behavior of your application, tracking changes throughout its lifecycle. This ensures a minimal false positive rate and reduces tedious rule tuning after each application change.
- Check Point WAF is also available as-a-Service. This version delivers an agentless WAF that can be deployed in less than 15 minutes. Traffic is effortlessly routed through Check Point servers, which automatically issue SSL certificates. Upon redirection, any HTTP requests are intercepted for inspection and forwarded to the application only after validating their security.

## Case Study: Visiativ
### The rise of bot and API cyber issues
Visiativ reported a shocking rise in the number of security issues using automated bots, as well as unauthorized users attempting to deface customer websites and compromise APIs.

### Features
- Incoming requests are analyzed using two AI engines. The attack-indicator AI engine is trained on millions of malicious and legitimate requests, identifying subtle variants for near-perfect detection of zero-day threats. The content analysis AI engine continuously learns from real-time traffic patterns and adapts to each application’s unique behavior, accurately detecting anomalies and reducing false positives to nearly zero.

## Check Point on AWS
Check Point is an AWS Software Partner. Check Point WAF enhances and complements native AWS controls with AI-powered contextual analysis, automated API schema, API gateway security, and structure awareness. The solution preemptively blocks known and unknown threats including padding evasion attacks, generative AI prompt injections, data leakage, SQL injections, insecure direct object references, path traversal, cross-site scripting, XXE, command execution, and many more unauthorized access techniques. Check Point WAF can be easily deployed directly via the AWS Marketplace, and its as-a-Service offering can be deployed in less than 15 minutes.

## Real-time AI-powered protection
Check Point WAF features preemptive zero-day protection, detecting and blocking unknown and zero-day attacks such as Log4Shell and Spring4Shell before signatures even exist. No rule maintenance is needed, eliminating the manual effort of tuning rules and signatures. And Check Point WAF’s near-zero false positives minimize operational overhead with contextual detection that adapts over time.

### Complete visibility and integration
Visiativ customers receive complete visibility for early detection of unauthorized users attempting to access applications and APIs. Integrations with AWS services mean time savings for admins. After implementing Check Point WAF, the solution prevented a Russian bot attempting unauthorized access on a Visiativ customer’s e-commerce website. The security team praises Check Point WAF’s ability to prevent security issues.

**Contact:** aws@checkpoint.com

[Check Point WAF on AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-wctbkjip42idi)  
[Check Point CloudGuard](https://www.checkpoint.com/cloudguard/amazon-aws-security/)
