F5 Expands AI-powered WAAP Solutions

Share

“Frontier AI has collapsed the window between discovery and exploitation. Attackers no longer need a CVE. They need a model and a target. We built a risk engine that learns continuously and scores every request dynamically, catching attack patterns before a signature exists to stop them. As APIs become the connective tissue for AI inference, we’ve extended that same security posture to air-gapped and on-prem environments, because the most sensitive workloads can’t phone home to the cloud,” said Kunal Anand, Chief Product Officer at F5.

Enhanced AI-powered WAF: Stop attacks before they can be exploited

Key capabilities of F5’s AI-powered Distributed Cloud WAF include:

  • Numerical risk scoring: Dynamic, multi-signal scores on every request give security teams precise, actionable context rather than a binary block-or-allow decision
  • Continuously trained shared model: The risk engine learns from multiple factors, including high-confidence signatures and attack indicators, so detections improve as the threat landscape evolves
  • Pre-exploit detection: Behavioral signals trained to reason like attackers are designed to identify attack activity before threats are formally classified, addressing a window that signatures and patches cannot reach

Introducing F5 API Security Local Edition: API discovery and protection for air-gapped and regulated environments

Organizations in highly regulated and sensitive industries, such as defense, intelligence, government, financial services, healthcare, and critical infrastructure, operate in environments where cloud-based security tools may not be an option. With the rapid adoption of AI, APIs have become even more critical, but they also bring increased security risks. APIs are the gateways for AI inference and data processing, making them a growing target for malicious activity. Until now, those environments have had limited access to the on-premises API discovery and security they need.

  • API discovery and visibility automatically identify API endpoints, map schemas, and surface security risks with no cloud dependency.
  • Risk scoring and blocking dynamically evaluate API risks and identify potential threats in real time, enabling the discovery, documentation, and monitoring of APIs effectively.
  • Local deployment and on-premises management deliver local analysis and visualizations via a dedicated console operated entirely within an organization’s on-premises infrastructure.

Virtual patching: Close the window between discovery and protection

In a world where frontier AI models are constantly probing for vulnerabilities, previous timelines of exploitation and remediation no longer apply. There needs to be a way to identify a potential stopgap to deter exploitation and provide a window of opportunity for organizations to patch vulnerabilities that face imminent exploitation.

Protecting every app and API in every environment

AI-accelerated exploitation, pre-CVE attacks, and the challenge of securing isolated environments are not future risks—they reflect current enterprise threats. The capabilities announced today extend the F5 Application Delivery and Security Platform to meet the threats that security teams in critical industries face, while reinforcing F5’s commitment to protecting apps and APIs in any environment.

Newsletter Subscription

Join our mailing list