eBook | Cloud Application Security Blueprint: Architectures and Solutions
Download this eBook, “Cloud Application Security Blueprint: Architectures and Solutions. Leverage contextual AI analysis” to automate application security on Amazon Web Services (AWS) with Check Point CloudGuard. Discover how technologies like machine learning (ML) and artificial intelligence (AI) drive security solutions that match the pace of innovation with the power of the cloud to create a secure environment for your applications to thrive in.

Cloud Application Security Blueprint: Architectures and Solutions
Leverage contextual AI analysis to automate application security
TABLE OF CONTENTS
Introduction
01
Auto-Generated API Schema
07
Continuous Learning
06
Conclusion
10
Check Point WAF Contextual, Multilayer AI Engine
03
Check Point on AWS
09
Why Traditional WAFs are Insufficient for Modern Cloud Applications
02
Bot Attacks—Distinguish Between Human and Non-Human
08
INTRODUCTION The cloud has created an environment that empowers organizations to develop powerful web applications, driving better customer and internal experiences, enabling innovation, and increasing agility. The backbone of these web applications are application programming interfaces (APIs), making them common targets for cyber criminals. These new attack vectors mean that organizations must evolve how they protect their infrastructure. To get comprehensive protection beyond cloud web application firewalls, you need cloud web application and API protection (WAAP) services that include Web Application Firewall (WAF), API security, and Bot protection.
The cloud lets developers create, release, and update applications at an incredible pace. This means that traditional methods of securing applications—like rule-based methods that manually analyze every request in isolation and compare it to a set of pre-determined rules—struggle to match the pace of innovation. In addition, the speed that attracts developers also grows the attack surface and attracts threats. Organizations need fast and agile security tools that protect their cloud investment while empowering them to take advantage of powerful cloud-native solutions.
Discover how technologies like machine learning (ML) and artificial intelligence (AI) drive security solutions that match the pace of innovation with the power of the cloud to create a secure environment for your applications to thrive in.
1
WHY TRADITIONAL WAFS ARE INSUFFICIENT FOR MODERN CLOUD APPLICATIONS
IN A CLOUD ENVIRONMENT, TRADITIONAL WAFS FACE THE FOLLOWING CHALLENGES: 1. Diverse code sources: Cloud applications often integrate code from various sources,
including open-source repositories. These applications are composed of numerous, distinct code components, increasing potential vulnerabilities. Open-source code may have widely known vulnerabilities that attackers can easily exploit.
2. Faster application change rate: With the power and flexibility of cloud computing, applications can be a click away from production. A commit to GitHub automatically goes through testing/staging and then to production with little human involvement. Any solution requiring manual tuning of application security will never match the pace of development.
3. Open and connected applications: Because of the high number of resources interacting with third-party services outside of the “perimeter,” data can flow in and out of applications in many more ways than in the past. In effect, there are now hundreds of perimeters to secure.
4. Increasingly sophisticated cyber threats: Attack techniques continue to evolve. With attackers using bots and APIs as attack vectors, the cloud has a significant privilege escalation issue. Attackers infiltrating an application look for API keys to other applications or resources, gaining access to more of the system. Due to poorly configured role-based permissions, remote code execution can be much more harmful in the cloud.
Traditionally, web application firewalls (WAFs) are deployed at the network edge using rule-based filtering to block threats from accessing applications. This approach, however, is highly manual, requiring constant maintenance and frequent updates to address evolving attack vectors, as each new threat can demand new rule creation.
To overcome these challenges, organizations need a solution that does not require rule tuning and is based on automatic AI engines to make decisions. Check Point WAF is powered by a contextual AI engine that delivers high security performance with flexible and easy deployment options.
Check Point WAF, available in AWS Marketplace, simplifies WAF deployments while providing exceptional web application, generative AI, and API protection. Working together with AWS, Check Point WAF is shifting the web application, generative AI, and API security paradigm from rules to decisions fully managed by unique AI engines.
With services that can be tailored to meet your specialized security needs, you get automated application and API security, as well as precise threat prevention using contextual AI, access control, and IoT protection. By combining your AWS Cloud environment with Check Point WAF, you:
• Preemptively prevent zero-day attacks instead of reacting to them
• Block all malicious traffic
• Use intelligent AI to double-check and approve legitimate traffic
2
3
All organizations want to protect their web applications and APIs from security threats, but experiencing a high number of false positives can also be harmful. Traditional WAFs can mistakenly block legitimate users, creating a poor user experience.
By using contextual AI, Check Point WAF continuously learns from your traffic patterns. This dramatically reduces false positives, minimizes rule management time, enhances customer experience, and ensures legitimate traffic flows uninterrupted for AWS customers.
Check Point WAF’s contextual machine-learning enforcement engine operates in two stages:
AI STAGE 1 Attack Indicator Analysis is an ML-based enforcement engine that looks for attack indicators within the HTTP request. It takes the request and breaks it up into short patterns that each indicate a potential likelihood of the HTTP request being used to exploit a vulnerability. The incoming HTTP requests are evaluated using a supervised, offline ML model. Built in an on-going offline supervised training process, it uses millions of malicious and benign requests to identify indicators and associate them with the specific, statistical likelihood “score” of being part of an attack.
These scores are aggregated, allowing Check Point WAF to make an effective and accurate initial decision about the HTTP request’s attack likelihood.
CHECK POINT WAF CONTEXTUAL, MULTILAYER AI ENGINE
ATTACK INDICATOR ANALYSIS
4
All organizations want to protect their web applications and APIs from security threats, but experiencing a high number of false positives can also be harmful. Traditional WAFs can mistakenly block legitimate users, creating a poor user experience.
AI STAGE 2 Context Analysis Engines use contextual ML to further analyze the potentially suspicious requests based on the indicators observed in stage 1. This process delivers further confidence that any HTTP request indicated as potentially malicious is indeed an attack, effectively ruling out false positives.
TO ACHIEVE THIS, CHECK POINT WAF CONSIDERS VARIOUS FACTORS, SUCH AS:
• Application structure
• User behavior—both general and individual interactions with content
• Crowd behavior by continuously learning from users with a good reputation
These factors enable the system to adapt to the application automatically. Trusted users further accelerate learning by helping create allow lists for permitted inputs. This assessment uses an online, unsupervised ML model continuously built and updated in real time based on the incoming traffic within the protected environment.
CHECK POINT WAF CONTEXTUAL, MULTILAYER AI ENGINE (CONT.)
CONTEXT ANALYSIS ENGINE
CHECK POINT WAF CONTEXTUAL, MULTILAYER AI ENGINE (CONT.) All organizations want to protect their web applications and APIs from security threats, but experiencing a high number of false positives can also be harmful. Traditional WAFs can mistakenly block legitimate users, creating a poor user experience.
For example, an application can have an expected field be a command execution. Any traditional WAF engine would identify that field value as remote code execution and block it. By looking at other sources that requested the same parameter and checking how many other users requested similar values, false positives are eliminated. The understanding of the patterns of the field is derived from any of the engines above.
This type of contextual analysis is critical for web applications, as they are usually customer-facing. False positives can prevent real customers from accessing a site. Combining the risk analysis of multiple engines results in a more accurate decision, with an understanding of the context, allowing security admins to operate comfortably in Prevent Mode without the worry of blocking legitimate requests.
By implementing Check Point WAF’s powerful two-stage contextual AI, organizations can augment the built-in security controls of AWS to strengthen cloud security for their enterprise applications.
5
CONTINUOUS LEARNING Preventing Security Incidents with Automatic Adjustments
Check Point WAF’s contextual AI starts in Learn/Detect mode, which stores data about your messages, traffic, applications, and other workload information for your entire AWS environment in an agent in the AWS Cloud. The mechanism is distributed over several CPUs that work independently and store information to memory. This information is then synchronized between themselves every hour. Every distributed CPU runs all of the engines mentioned earlier. By getting this data, they can better understand the application in terms of the source, HTTP method, types of HTTP requests, every key/value pair in the HTTP request, and where they specifically reside. This information is parsed and then fed into the engines. This is completed in only a few days and can be switched to Prevent mode once finished.
AI processing can be resource-intensive, but because Check Point WAF and AWS work seamlessly together, it will not impact your cloud environment.
The Supervised Learning mode enables the system to learn faster by looking at user logs for the previous week and identifying which events were labeled as malicious with High or Critical severity. It finds the similarities and presents them grouped in a specific pattern. For example, one possible pattern group is by a specific source identifier, such as a source IP or email. The user is presented with a tuning suggestion:
“70% of requests from this source identifier were marked as critical. A true positive means this is an attacker—mark it as malicious, and will be blocked. Mark as benign for a false positive—indicating the system has marked too many requests as malicious.”
This assists ML in understanding this is a benign request, a finding it would have reached in time. However, by using Check Point WAF in your AWS infrastructure, you discovered this faster, eliminating its impact on your environment.
6
8
AUTO-GENERATED API SCHEMA IN-APP SCREENSHOT
Provides Full Visibility And Strict Enforcement
Our system provides auto-generated API schemas that offer significant benefits in terms of visibility, developer efficiency, and security.
Deep Visibility into APIs By automatically generating comprehensive schemas for each API – including methods, URI parameters, and request body structures – we offer deep visibility into your API ecosystem. This extends beyond basic endpoint and method identification, allowing you to understand the exact parameters and data structures used in API requests. Such granular insight enables a thorough understanding of API behaviors and data flows within your applications.
Developer Efficiency and Time Savings The auto-generated schemas serve as a valuable baseline for developers, significantly reducing the manual effort required to create and maintain API documentation. This automation saves time and minimizes the potential for errors associated with manual schema writing. Developers can focus on core development tasks instead of spending hours on schema creation, especially in environments where APIs frequently change.
Precise Malicious Change Detection By analyzing API parameters and request body structures in detail, our system can detect even the slightest changes or anomalies in API behavior. This precise monitoring enables the early detection of unauthorized modifications, such as unexpected parameters or altered data structures introduced by malicious actors. Early identification of such changes is critical for maintaining security and allows for swift response to potential threats.
8
BOT ATTACKS—DISTINGUISH BETWEEN HUMAN AND NON-HUMAN Validating Legitimate Traffic from Bots
Threat actors have utilized malicious bots in everything from distributed denial of service attacks to buying out the newest Nike sneakers in a matter of seconds. Utilizing bots for automated attacks is a regular practice among threat actors. Threat actors weaponize bots for:
• Reconnaissance
• Scraping
• Credential stuffing
• Automated account creation
• Token cracking
Check Point WAF utilizes Client-Side Behavioral Analysis to distinguish human behavior.
Once a client connects to a server, it performs a GET operation.
The client receives data from the server page, including a Javascript developed by Check Point that is injected into the client’s browser.
This script collects the client’s behavioral information.
When the client performs a POST operation on the server, it will include the decision of this script, which defines if the request originated from a bot or a human.
9
CHECK POINT ON AWS Gain the confidence to use, access, and move between all points in your cloud environment
Check Point works seamlessly in your AWS environment, offering dozens of integrations with AWS services. Check Point WAF meets the security and compliance requirements of the most stringent regulations. This high-performance, prevention-first security platform keeps teams moving forward and protects applications from emerging threats. Check Point’s cloud-native solution minimizes disruption to the development process.
SAFEGUARD YOUR APPLICATIONS AND APIs WITH CONTEXTUAL AI: • Zero-day attack prevention—proactively
ensures applications remain secure
• Reduce false positives—ensure legitimate traffic flows uninterrupted
• Precise prevention—eliminate false positives and remain secure
• Comprehensive API discovery and security— reduces the attack surface and ensures safe, monitored API use
• File security—prevent the upload of harmful files to minimize breaches
• No rules, no training—lower TCO with no ongoing maintenance
• Auto deploy on any environment— deployment to protection in hours
• Simplified management for enhanced usability—using a combination of web UI, API, and Kubernetes-native tools ensures simplified, effective management
Available via AWS Marketplace, Check Point’s simplified deployment and automation process removes security obstacles, so you can spend more time innovating with the power of the AWS Cloud. With Check Point on AWS, you get consistent security everywhere, with the automated cloud benefits of AWS.
10
CONCLUSION Applications are every organization’s primary business driver, and with the proliferation of APIs, attack surfaces are expanding rapidly. DevOps updates applications with increasing regularity, and traditional application security is unable to keep up with the speed and scale of change. Cloud applications demand modern security, providing precise prevention without generating false positives. They need coverage from a fully automated security solution, continuously learning the application, content, and user behavior to make the right decision each time a web request comes in.
Check Point WAF provides application security, generative and agentic AI security, and API protection powered by contextual AI. It examines the parameters associated with a web application, generative AI request, or API request to build a risk score. By automatically identifying malicious and non-malicious requests, Check Point WAF reduces operational overheads by providing high threat prevention precision.
Start a free trial of Check Point WAF or request a demo today!
Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599 | Email: info@checkpoint.com U.S. Headquarters 100 Oracle Parkway, Suite 800, Redwood City, CA 94065 | Tel: 1-800-429-4391 ; 650-628-2000 | Fax: 650-654-4233 www.checkpoint.com
© 2026 Check Point Software Technologies Ltd. All rights reserved.