Cheap Triggers, Expensive Verdicts: Cost Amplification in Tiered Web Application Firewalls
Web application firewalls frequently do tiering to minimize the cost of inspection: low-cost prefiltering discards obviously benign traffic and only flagged requests are passed to high-cost deep inspection. The optimisation works well in the context of its traffic distribution, in which escalations are not common. We note that it also gives the attacker a control input. The prefilter is designed to be as broadly inclusive as possible, so that an attacker can easily submit requests that cause it to flag with little effort but carry no information the deep rule could validate. These requests are then escalated, fully examined, and allowed. They consume the deep-inspection budget but do not generate any block, log entry, or other security alert. We refer to this as trigger amplification and describe it as a cost asymmetry between attackers and defenders. A testbed using the same two-stage pipeline behind two concurrency models (an event-loop gateway and a thread-per-connection gateway) found that an escalated trigger-only request takes about an order of magnitude more time end to end than a clean request. Measured as processor time the gap is about twofold for a minimal trigger, widening toward an order of magnitude once the request body is padded; in both cases the multiplier tracks the ratio of deep to prefilter cost that the operator widens each time a rule is added. The escalated work fills the deep-inspection pool under load; whether it appears as refused connections or as unbounded queue latency depends on the concurrency model, so asynchrony relocates the saturation point rather than removing it. Throughout, the attack is security-invisible: no request is blocked, logged, or alerted. We argue that escalation rate should be treated as an attacker-controlled security parameter, and discuss mitigations that target the asymmetry rather than the concurrency model.
Authors
- Basyal (ORCID: https://orcid.org/0009-0006-4633-6409)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-03
- DOI
- https://doi.org/10.5281/zenodo.23124708
- Primary Topic
- Network Packet Processing and Optimization
- Type
- article
- Field-Weighted Citation Impact
- 0.00