It is better to prevent than to react
When it comes to improving the security level of your applications and services, WAFs are effective security solutions, but they too have limitations.
Zero-day attacks are not prevented by them
Web Application Firewalls do not evaluate the context in which applications and services operate, but rather focuses on statistics (known signatures). When an attack falls outside the stats, the ability to protect is drastically diminished.
They don’t learn in adversarial environments
Web Application Firewalls cannot learn under attacks, which means that they won’t recognize a fresh threat and won’t block it.
They do not create new protection rules
An application firewall reacts according to predetermined signature rules, but can’t generate new ones on its own.