All glossary terms
Glossary

False negative (WAF)

A WAF false negative is a malicious request the WAF lets through because no rule matched it, or because the matching rule was disabled or set to log only.

False negatives are the mirror of false positives, and the two are linked: every rule switched off to stop blocking customers creates room for false negatives.

They are also harder to measure, because nothing is logged as blocked. Finding them takes testing, threat intelligence and comparing coverage against known vulnerabilities in each application.

Where Huskeys fits

Huskeys measures coverage gaps per application, so missing protection shows up before an attacker finds it.

Related terms

Further reading