
Overview

Product video
Imperva SecureSphere WAF for AWS extends all of the security and management capabilities of the world's most-trusted web application firewall to Amazon Web Services environments. SecureSphere for AWS is the first enterprise-class Web Application Firewall tailored specifically for Amazon Web Services. Running natively in AWS, and leveraging all its capabilities, SecureSphere for AWS scales on-demand with AWS applications. SecureSphere applies multiple defenses and correlates results to offer laser-accurate attack detection. Certified by ICSA Labs, SecureSphere addresses PCI 6.6 and provides ironclad protection against the OWASP Top Ten, including SQL Injection, XSS and CSRF. Note that AV1000 provides up to 100 Mbps throughput. If more is required, see SecureSphere Web Application Firewall AV2500 Gateway for AWS (On-Demand).
Highlights
- Automated Protection - Patented Dynamic Profiling technology streamlines management and lowers operations costs by learning application changes over time. Security updates from the Imperva ADC protect applications against the latest threats.
- Flexible Deployment Options - The SecureSphere WAF offers organizations automated, adaptable security and easy deployment into Amazon environments with full support for elastic load balancing and CloudFormation.
- Fraud and Automated Attack Protection - With advanced bot detection capabilities, IP Reputation, granular custom rules, and fraud integration, SecureSphere stops dangerous threats like site scraping, application DDoS, comment spam, and web fraud.
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
c5a.2xlarge Recommended | $1.37 |
c4.2xlarge | $1.37 |
c5a.4xlarge | $1.37 |
c5.2xlarge | $1.37 |
c4.4xlarge | $1.37 |
c6i.xlarge | $1.37 |
c5.4xlarge | $1.37 |
c7i.xlarge | $1.37 |
c5a.8xlarge | $1.37 |
c7i.2xlarge | $1.37 |
Vendor refund policy
We do not support refunds, but customers can cancel at any time. Contact Imperva for more information.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
AUTOMATIC DEPLOYMENT (RECOMMENDED)
Imperva simplifies the deployment of your WAF Gateway infrastructure on AWS by providing dynamically generated CloudFormation and Terraform templates tailored to your specific requirements via the Imperva Cloud Template Tool.
For detailed instructions and additional information: https://docs.imperva.com/bundle/v15.4-waf-on-amazon-aws-byol-installation-guide/page/10450.htm
MANUAL DEPLOYMENT
DISCLAIMER:
- This procedure is not intended for use in large-scale production environments. For a best-practice installation, use the automated deployment method.
- You must obtain an account-unique unseal key from Imperva to complete this procedure.
- You need a running Imperva WAF Gateway Management Server to use this product.
-
Create a VPC, a key pair and at least one subnet.
-
Create a security group for the Gateway instances.
-
Create the following inbound rules:
- [Management Server SG] ==> [Gateway SG] @ TCP:443
- [Gateway SG] ==> [Management Server SG] @ TCP:8083, TCP:8085
- [Administrative IP ranges] ==> [Gateway SG] @ TCP:22
- [Client ranges] ==> [Gateway SG] @ [reverse proxy ports] (variable)
-
Launch one or more instances using the product's AMI. Assign the Gateway security group and set the following user data (providing your own unseal key): ModelType : AV1000OD Component : gateway ProductLicensing : OnDemand ImpervaLicenseKey : <unseal_key>
-
Once all instance status checks have passed, SSH into each instance as ec2-user, enter 'admin' to access root, and execute the following First-Time Login commands to configure it as a Gateway:
bootstrap_set //bootstrap/product/components/gateway/cloud gateway_group "aws"
/opt/imperva/impcli/commands/ftl --silent --component Gateway --model_type AV1000OD --management_ip <management_server_ip> --secure_password <secure_password> --system_password <system_password> --imperva_password <imperva_password> --grub_password <grub_password> --product WAF --timezone UTC --gateway_mode reverse-proxy-hades --gateway_group aws --is_advanced_bridge Disabled
- Replace all <variables> with your own values.
- For <management_ip>, supply the private IP of your Management Server.
- Log in to your Management Server's user interface, navigate to Setup > Gateways and verify that all Gateways appear as Running under the aws Gateway group. This might take up to 5 minutes after completing the FTL for each instance.
- Refer to the user guide to configure your environment as desired and protect your applications: https://docs.imperva.com/bundle/v15.4-waf-user-guide/page/70414.htm
Resources
Support
Vendor support
Imperva's team of Support Engineers is positioned across the globe to provide 24x7x365 coverage, and can be contacted by phone, email, or online via our Self Service Support Portal. Visit the Imperva Support page above for more details.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Strong protection has improved legacy app security and currently reduces risky server connections
What is our primary use case?
Imperva Application Security Platform is generally used for legacy-type applications that cannot be migrated to the cloud. A specific example of how I use this tool to protect legacy applications in my organization is that we have an intranet which has not been fully developed or technologically advanced enough to run in the cloud, so by having this, we secure it effectively.
What is most valuable?
Imperva Application Security Platform allows you to enhance your application security posture. Among the best features that Imperva Application Security Platform offers, the policies are very dynamic, and it also has profiling at the application level that allows you to work in this mode.
I would like to highlight especially the ThreatRadar feature, which is an additional subscription, and ThreatRadar helps with threat intelligence by allowing you to block advanced attacks as well as mitigate risks more effectively.
Imperva Application Security Platform positively impacts us because we have a critical website, so by placing a WAF of Imperva's quality, it allows us to have visibility and granular control over the various attacks that can occur on the website.
A concrete improvement I have seen thanks to Imperva Application Security Platform is that it has decreased the level of connections to the final server. The specific improvement is that the connections that reach the server are fewer because Imperva is already filtering them at the WAF stage.
What needs improvement?
Imperva Application Security Platform could be improved if it allowed integration with Active Directory in the cloud, or if it provided visibility of user roles and permissions.
For how long have I used the solution?
I have been using Imperva Application Security Platform for a little more than three years.
What do I think about the stability of the solution?
I consider Imperva Application Security Platform to be a stable solution.
What do I think about the scalability of the solution?
I would rate the scalability of Imperva Application Security Platform as very good since it adapts well and you can grow independently because the interfaces support one and ten gigs.
How are customer service and support?
Imperva Application Security Platform customer support has been very good; the ticketing platform allows us to have visibility of the case, and the staff makes the effort to respond quickly.
Which solution did I use previously and why did I switch?
I did not previously use any other solution before Imperva Application Security Platform.
How was the initial setup?
The advice I would give to others who are considering using Imperva Application Security Platform is to start with learning mode and then move to blocking mode slowly for approximately one week so that Imperva can identify the website and the connections that are made to it.
What was our ROI?
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time. The clarification on time savings is that it refers to the time spent on alerts.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing, implementation cost, and licenses of Imperva Application Security Platform is that it is high compared to a traditional WAF solution, but it meets expectations.
Which other solutions did I evaluate?
Before choosing Imperva Application Security Platform, I did not evaluate other options, as we went directly with Imperva due to recommendations.
What other advice do I have?
I would rate Imperva Application Security Platform an eight on a scale from one to ten. Imperva Application Security Platform is a very good platform; even though it is not in Gartner, clients request it and trust the brand. I would rate customer support on a scale from one to ten as an eight. My overall review rating for Imperva Application Security Platform is eight out of ten.
Web defenses have blocked unauthorized access and protect sensitive health data effectively
What is our primary use case?
My main use case for Imperva Application Security Platform is to block unauthorized IPs, users, and source applications, as we configured the Web Application Firewall to monitor internet-based applications during my previous project.
To decide which policies to configure for blocking unauthorized users and sources, we identify authorized users and source IP addresses, ensuring only those belonging to the organization are validated and whitelisted in Imperva Application Security Platform to effectively block unauthorized sources. Imperva Application Security Platform works on a whitelisting concept, meaning only whitelisted users are allowed while others are treated as unauthorized.
We implement multiple policies for sensitive data in the Web Application Firewall because users may attempt to access sensitive health-related information. In a healthcare project, we set up patterns to alert if sensitive data is accessed within the organization and block it if accessed externally.
What is most valuable?
The best features of Imperva Application Security Platform include its ease of use, as it offers both on-premises and cloud options, with minimal maintenance downtime during patching due to the recommended three gateways setup, allowing for resource monitoring while upgrading.
Imperva Application Security Platform positively impacts my organization by reducing CVE-related issues significantly, as we monitor and learn from reports generated during collaboration with respective teams.
We track the reduction in CVE-related issues through weekly and monthly meetings using Imperva Application Security Platform reports. Initially, there were over 1,500 vulnerabilities, but we managed to fix almost all of them within three months, leaving only two low severity issues outstanding.
What needs improvement?
Imperva Application Security Platform can be improved as it currently lacks integration with other tools under the Data Security Fabric, particularly the WAF feature, which would enhance overall functionality.
Generally, I am satisfied with the user experience of Imperva Application Security Platform; however, I would suggest streamlining the patching process for larger environments as it becomes time-consuming when applying multiple patches across many gateways.
For how long have I used the solution?
I have been working in IT security for 10 years out of my overall 17 plus years of experience.
What do I think about the stability of the solution?
Imperva Application Security Platform is always stable, having encountered issues infrequently across my usage of their products.
What do I think about the scalability of the solution?
The scalability of Imperva Application Security Platform is indeed good, effectively accommodating growth for larger organizations despite internal data management policies.
Imperva Application Security Platform handles scalability effectively, allowing for growth when appropriately understood through policies and configurations, although understanding the platform takes time.
How are customer service and support?
Customer support from Imperva has been very good as I have raised over 100 cases, with responsive support addressing urgent needs, even offering early support despite initial SLA challenges.
Which solution did I use previously and why did I switch?
We did not previously use a different solution, starting with DAM and moving directly into a full implementation due to an incident that required rapid deployment.
How was the initial setup?
We utilized AWS for our private cloud environment, finding it satisfactory, although I only used Imperva Application Security Platform Cloud once for DAM, not WAF.
What was our ROI?
While I would not say we have saved money, we have certainly saved time through effective documentation and support for compliance-related issues, streamlining the necessary processes with fewer employees.
What's my experience with pricing, setup cost, and licensing?
We faced challenges with high costs, as the customer perceived pricing for gateways to be excessive, but we handled multiple billing instances with sophisticated setups.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Imperva Application Security Platform, opting for it directly because it fit our needs for an on-premises solution.
What other advice do I have?
Beyond the WAF, Imperva DAM is beneficial because it features Imperva Security Fabric and Data Security Fabric, including tools like File Access Activity Monitoring, though the WAF is still using previous functionalities.
I can confirm that Imperva Application Security Platform is stable, though we have not purchased Imperva Application Security Platform cloud environment from the AWS Marketplace.
It is important to decide the purpose for using Imperva Application Security Platform; I recommend it for monitoring internet-based applications, while for internal tasks, it may not be worthwhile due to its costs. I would rate this review as a 9.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Advanced protection has secured our websites and reduces DDoS and zero‑day attack incidents
What is our primary use case?
What is most valuable?
The best features Imperva Application Security Platform offers are for speed and protection. There is runtime and zero protection, and we have the sub and sub plus protection.
The speed and protection features of Imperva Application Security Platform help my team day-to-day by providing safe and clear access to the website. For example, my company is a multinational company that experiences many attacks, such as DDoS attacks, hitting the general website of the company before. The protection protects all of the websites in Imperva, so accessing the website is safer right now, not disrupted by DDoS attacks.
Imperva Application Security Platform has positively impacted my organization by making the website more secure. It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva. This is very helpful for my company as it reduces the incidents from the website.
What needs improvement?
I would suggest that Imperva Application Security Platform should include new features combined with AI. When I was using Imperva, it was not yet combined with AI. I believe that AI can now be used to make things easier, to track the attacks or IPs, or perhaps to determine the best configuration for each company that is using Imperva.
For how long have I used the solution?
What other advice do I have?
I would add that I have a unique observation about the features of Imperva Application Security Platform. For protection to protect more safely and restrictively, I have another use case with an internal website. This website is internal, and those people who want to access it can use the VPN or the internal network. I have encountered cases where a person from the internal company wants to access the website without using the API and got blocked by Imperva because there is a feature or configuration that allows specific IPs. I had to log all of the ways to access the web and allow only a few IPs from the internal IPs. I think Imperva is very secure, very restricted, and good for protecting websites, especially for internal websites and production servers.
Regarding improvements to Imperva Application Security Platform, I think all aspects of Imperva Web Application Firewall, including the UI/UX, are good, and I can operate it smoothly with the application. I give this product a rating of 8.5 out of 10.
Continuous monitoring has strengthened our web defenses and has reduced malicious incidents
What is our primary use case?
Regarding my main use case, I first log into the WAF applications, then access the Alerts section. In that section, I can see different types of activity happening in the firewall. I review each alert to determine whether it is legitimate or suspicious activity. I can also view the target IP address and locations, target servers, and the payload that the attacker was using in that alert. I can see the OWASP Top 10 alerts and the event timing to identify when the attack occurred.
What is most valuable?
There are many alerts in Imperva Application Security Platform. For example, there is an OWASP Top 10 alert called SSRF, which is server-side request forgery. If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address. That is very effective.
Imperva Application Security Platform has positively impacted my organization because every time an attacker uses a malicious payload or malicious signature that is already included in the signature database of the WAF application or Imperva application, the application directly blocks that particular signature immediately. This capability can help any organization achieve better security outcomes.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
What was our ROI?
What other advice do I have?
I gave it a 10 because it is useful for private organizations and it is very safe to have WAF applications, particularly Imperva Application Security Platform.
The advice I would give to others looking into using Imperva Application Security Platform is that it is safer to use or to have it. My overall rating for this product is 10 out of 10.
Custom policies and rate limiting have strengthened our application security and compliance
What is our primary use case?
Imperva Application Security Platform is used primarily for web application firewall security. My organization has a significant number of applications running through the platform, and to monitor those applications, we require firewalls. Imperva Application Security Platform 's Web Application Firewall performs the deep inspection necessary for this monitoring.
What is most valuable?
Imperva Application Security Platform offers customization of security policies, allowing me to create policies tailored to my environment.
The rate limiting policy in Imperva Application Security Platform works based on usage numbers and has proven valuable for our operations.
Imperva Application Security Platform is user-friendly, and I can maintain a customized dashboard to monitor the utilization of all gateways in day-to-day operations.
Imperva Application Security Platform serves as the base pillar for applications to grant or deny access appropriately.
From a compliance perspective, Imperva Application Security Platform has been an improvement, as it has passed all compliance processes.
What needs improvement?
Imperva Application Security Platform could be improved by providing a more user-friendly dashboard.
I would recommend that support for Imperva Application Security Platform be enhanced to be more effective.
For how long have I used the solution?
I have been using Imperva Application Security Platform for three years.
What do I think about the stability of the solution?
Imperva Application Security Platform is stable.
What do I think about the scalability of the solution?
Scalability in Imperva Application Security Platform depends on the region. Imperva Application Security Platform can handle more applications or increased traffic easily as my organization grows. Currently, we are running approximately 1000 applications, and it can handle more.
How are customer service and support?
Customer support for Imperva Application Security Platform is good, though it could be better. I would rate the customer support of Imperva Application Security Platform an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
What was our ROI?
We have seen a return on investment with Imperva Application Security Platform, as we started with a few devices and gradually increased the number of on-premises devices for Imperva Application Security Platform.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing for Imperva Application Security Platform were user-friendly and good.
Which other solutions did I evaluate?
What other advice do I have?
I would recommend Imperva Application Security Platform compared to Akamai WAF. It has been good to use Imperva Application Security Platform, as I have been using it for three years. I would rate this review a nine on a scale of one to ten.