Cheap Triggers, Expensive Verdicts: Cost Amplification in Tiered Web Application Firewalls

Web application firewalls frequently do tiering to minimize the cost of inspection: low-cost prefiltering discards obviously benign traffic and only flagged requests are passed to high-cost deep inspection. The optimisation works well in the context of its traffic distribution, in which escalations are not common. We note that it also gives the attacker a control input. The prefilter is designed to be as broadly inclusive as possible, so that an attacker can easily submit requests that cause it to flag with little effort but carry no information the deep rule could validate. These requests are then escalated, fully examined, and allowed. They consume the deep-inspection budget but do not generate any block, log entry, or other security alert. We refer to this as trigger amplification and describe it as a cost asymmetry between attackers and defenders. A testbed using the same two-stage pipeline behind two concurrency models (an event-loop gateway and a thread-per-connection gateway) found that an escalated trigger-only request takes about an order of magnitude more time end to end than a clean request. Measured as processor time the gap is about twofold for a minimal trigger, widening toward an order of magnitude once the request body is padded; in both cases the multiplier tracks the ratio of deep to prefilter cost that the operator widens each time a rule is added. The escalated work fills the deep-inspection pool under load; whether it appears as refused connections or as unbounded queue latency depends on the concurrency model, so asynchrony relocates the saturation point rather than removing it. Throughout, the attack is security-invisible: no request is blocked, logged, or alerted. We argue that escalation rate should be treated as an attacker-controlled security parameter, and discuss mitigations that target the asymmetry rather than the concurrency model.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-03
DOI
https://doi.org/10.5281/zenodo.23124708
Primary Topic
Network Packet Processing and Optimization
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Cheap Triggers, Expensive Verdicts: Cost Amplification in Tiered Web Application Firewalls

Basyal
Zenodo (CERN European Organization for Nuclear Research)
Network Packet Processing and Optimization
article

Cheap Triggers, Expensive Verdicts: Cost Amplification in Tiered Web Application Firewalls

Basyal
article en

Abstract

Web application firewalls frequently do tiering to minimize the cost of inspection: low-cost prefiltering discards obviously benign traffic and only flagged requests are passed to high-cost deep inspection. The optimisation works well in the context of its traffic distribution, in which escalations are not common. We note that it also gives the attacker a control input. The prefilter is designed to be as broadly inclusive as possible, so that an attacker can easily submit requests that cause it to flag with little effort but carry no information the deep rule could validate. These requests are then escalated, fully examined, and allowed. They consume the deep-inspection budget but do not generate any block, log entry, or other security alert. We refer to this as trigger amplification and describe it as a cost asymmetry between attackers and defenders. A testbed using the same two-stage pipeline behind two concurrency models (an event-loop gateway and a thread-per-connection gateway) found that an escalated trigger-only request takes about an order of magnitude more time end to end than a clean request. Measured as processor time the gap is about twofold for a minimal trigger, widening toward an order of magnitude once the request body is padded; in both cases the multiplier tracks the ratio of deep to prefilter cost that the operator widens each time a rule is added. The escalated work fills the deep-inspection pool under load; whether it appears as refused connections or as unbounded queue latency depends on the concurrency model, so asynchrony relocates the saturation point rather than removing it. Throughout, the attack is security-invisible: no request is blocked, logged, or alerted. We argue that escalation rate should be treated as an attacker-controlled security parameter, and discuss mitigations that target the asymmetry rather than the concurrency model.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 6%
Network Packet Processing and Optimization
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Cheap Triggers, Expensive Verdicts: Cost Amplification in Tiered Web Application Firewalls — Basyal · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS