Cloudflare vs Imperva Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Average Rating
8.4
Number of Reviews
57
Ranking in other categories
CDN (1st), Distributed Denial of Service (DDOS) Protection (1st), Cloud Security Posture Management (CSPM) (13th)
Imperva Web Application Fir...
Average Rating
8.6
Number of Reviews
47
Ranking in other categories
Web Application Firewall (WAF) (6th)
 

Market share comparison

As of June 2024, in the Distributed Denial of Service (DDOS) Protection category, the market share of Cloudflare is 15.5% and it decreased by 19.8% compared to the previous year. The market share of Imperva Web Application Firewall is 0.7% and it decreased by 53.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial of Service (DDOS) Protection
Unique Categories:
CDN
23.5%
Cloud Security Posture Management (CSPM)
2.7%
Web Application Firewall (WAF)
7.0%
 

Featured Reviews

BC
May 26, 2023
Good agility and security with a great load balancer
The first use case was to administer the main domain of the organization where I worked. We have the entire registration process for the main domain and its subdomains, and we create web application firewall (WAF) and load balancer rules. We did a major MX migration from Google to Microsoft, and…
Mitesh D Patel - PeerSpot reviewer
Apr 18, 2024
Effectively defends against threats like cross-site scripting (XSS), SQL injection, and others
It does bring value. For example, consider a BFSI customer. Their application is critical and represents their brand. Without a WAF, an attack could take their application down, harming their reputation. It leads to hampering the customer's workflow. With an Imperva WAF, they protect against attacks like DDoS or SQL injection, ensuring their application remains available and customers are happy. That's the main benefit for both the customer and the organization. The impact depends on the customer's use case. If their business primarily operates online, a CDN is beneficial for traffic optimization. Moreover, the integration options depend on the specific use case of our customers. Generally, integration capabilities are good with SIEM (Security Information and Event Management) parts.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is the web application firewall."
"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"It's very user-friendly."
"Generally, I am satisfied with this product."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"Cloudflare has many features."
"Cloudflare is a security SaaS provider that provides security and protects us from any application layer attack."
"The solution integrates seamlessly with other tools and has a good alert mechanism."
"Its inline transferring mode is the most valuable because it is 100% transparent. When you change the IP, there is no change on the network side. If you can't and want to try to reach an IP, you can reach the server IP. There are many other advanced security features in it. The smallest appliances of Imperva can handle the highest traffic at a customer site. For example, a smaller appliance from Imperva can provide you the same security as an F5 product."
"Imperva monitors all traffic, even customer access, to the web application. Then, Imperva uses features like signatures to identify attacks like cross-site scripting or SQL injection."
"The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand."
"I have had a positive experience with Imperva Web Application Firewall's tech support so far. They are knowledgeable and respond on time."
"The solution is cloud-based and offers us good uptime. It has combined web and API security. Therefore, with one license, you access both application security and also API security."
"Very intuitive and granular configuration - It does not require much time, or advanced knowledge, for configuration and maintenance."
"The solution can scale."
 

Cons

"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"If they improve on the placement of their data centers, it would be better. I'm living in a remote area. I would like to connect to them without any kind of lag."
"The product needs to improve its automation."
"The solution could use more analytics on the backend to give us more insights into everything. More reports would be helpful."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"For the free and Pro plans, Cloudflare could use a simple bot to provide information to users. This would improve support, especially for less advanced users who utilize the free components."
"It would be good if Cloudflare could have more servers for better traffic routing or an increase in the traffic routed. This is what I'd like to improve in Cloudflare."
"They recently separated the WAF and the DAM management gateways in order for each of these to be managed from different areas, so I believe it now requires additional investments for what was previously a single complete solution."
"There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."
"The reporting is missing some features, such as: only two export formats, and the time period does not include the last day, week, year."
"Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis."
"I am looking for more data enrichment. We should have the ability to add our own custom data to the system, to the live traffic."
"The support for the on-premises version needs improvement."
"The signature updates could be faster. Sometimes we have to upload signatures to the Imperva portal for checking and analysis before we can use them."
"It would be nice to have more security control over mobile applications so I would suggest adding more mobile security features. It would also be beneficial to see improvements in regards to interface bandwidth performance, CPU time, and RAM size. Learning capability of the device is quite weak."
 

Pricing and Cost Advice

"The price is reasonable."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"We don't have any issues with the price."
"I give the price a five out of ten."
"The cost primarily depends on the size of the organization."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"It is very costly, but the return on investment is very high. Its cost was around $70,000, and we got it back in just six months."
"Licensing can range from one to twenty thousand dollars annually. Additionally, some features, including software support, require an annual subscription as well."
"It is a very affordable solution."
"Make sure you understand the way that Imperva charges. It's very affordable. However, I would like to see a package with the Virtual Patching included. You get to do patching separately."
"The cost of this solution depends on the platform."
"Imperva’s pricing is a bit higher in the market since it offers a full-blown WAF."
"The solution's pricing is an issue."
"We sell three-year licenses for Imperva Web Application Firewall to our customers. The price is a little expensive."
report
Use our free recommendation engine to learn which Distributed Denial of Service (DDOS) Protection solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Educational Organization
38%
Computer Software Company
11%
Financial Services Firm
8%
Manufacturing Company
4%
Financial Services Firm
18%
Computer Software Company
14%
Manufacturing Company
7%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GRE tunnels. We have decreased site load times on Mobile 3G from 8 to 1,6 seconds ...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you have to look for other ADC's like F5, Imperva, Radware, Fortinet, etc.
DDoS solutions: Any other solutions to consider aside from Radware DefensePro and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot of DDoS attacks that were well managed (even not seen by the customer) by Imperv...
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Cloudflare vs. Imperva Web Application Firewall and other solutions. Updated: February 2023.
787,061 professionals have used our research since 2012.