Website Security & Threat Management
Making the WAF 40% faster

Making the WAF 40% faster

7/1/2020 · Miguel de Moura

What this post added

This post details performance improvements to the WAF engine. Key contributions include: 1. Transitioning from PCRE to RE2 for regular expression matching, improving execution time predictability. 2. Implementing a regex cache to manage memory consumption. 3. Optimizing rule execution by introducing pre-filtering checks and leveraging memoization to cache intermediate function results. 4. Rewriting over 40 rules to improve cache hit rates and efficiency. 5. Observing a 40% reduction in average WAF request processing time and a 4.3% drop in edge CPU consumption. 6. Announcing plans to port the WAF to the wirefilter execution engine.

Read the original post ↗