What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Product naming has changed since the Fastly acquisition: confirm current naming and packaging
- Full current list of supported modules and deployment integrations: verify against vendor documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Signal Sciences, now delivered as Fastly's next-generation WAF, splits the work between a module and an agent. The module lives in the web server, reverse proxy, language runtime or service mesh sidecar and hands request data to a local agent over a socket. The agent inspects and returns a verdict in the same request cycle, so the decision never leaves the host. The console receives metrics, aggregates them across your estate, and is where rules and thresholds are managed.
The detection model is the distinguishing part. The agent tags requests with signals: classifications like SQL injection attempt, traversal attempt or malicious scanner, alongside custom signals you define for your own application semantics such as a failed login. Blocking is then driven by how many signals a source accumulates in a window, not by one request matching one rule. That changes the failure mode. A lone false positive does not take a user offline, while a source systematically probing your application gets blocked once its behavior is unambiguous. Custom signals extend the same machinery to account takeover and enumeration.
Where it fits
This is production traffic protection, deployed by platform teams and operated day to day by security. Deployment flexibility is the practical advantage: modules in application hosts, a reverse proxy in front of services, sidecars in Kubernetes, or the Fastly edge, mixed across an estate that is not uniform. What has to be true first is that you can insert something into the request path and are prepared to define custom signals, because the default ruleset alone leaves most of the value unclaimed.
Strengths
- Threshold-based blocking on sources sharply reduces the operational pain of false positives.
- Decisions are made locally by the agent, so the vendor cloud is not a hard dependency for serving traffic.
- Custom signals encode application-specific abuse patterns that no generic ruleset addresses.
- Deployment spans host modules, proxies, containers and the edge, suiting heterogeneous estates.
Limitations
- An attacker who needs only one successful request against a known critical vulnerability is a weaker case for a threshold model than for strict per-request blocking.
- The agent and module architecture means software to deploy and update at every host or ingress point.
- Real value requires investment in custom signals and rules, which is analyst time most teams underestimate.
Who it suits
Well suited to teams running web applications and APIs at scale who have been burned by WAF false positives and want a model they can leave in blocking mode, especially where automated abuse matters as much as injection. Less compelling for small estates served adequately by an edge WAF, or for teams with no capacity to develop custom detections.
Used Signal Sciences? Recommend it under your own name and title.
Recommend this tool