All glossary terms
Glossary

False positive (WAF)

A WAF false positive is a legitimate request that the WAF blocks or flags as an attack, such as a real customer's checkout, login or form submission.

False positives happen when generic rules meet real application behavior: a product name containing an apostrophe looks like SQL injection, a long tracking cookie looks like an overflow attempt, a rich-text editor's HTML looks like cross-site scripting.

The cost is usually invisible. Blocked customers rarely complain; they leave. Teams often discover false positives only when conversion drops, and the common fix (disabling the rule) quietly reduces protection.

Where Huskeys fits

Huskeys finds rules that block legitimate traffic per application and recommends narrower versions instead of turning them off.

Related terms

Further reading