Unprotected web-based applications are often the easiest point of entry for hackers. Traditional technologies cannot provide complete protection from these threats. Web application firewalls (WAFs) have proven effective in preventing attacks that target known vulnerabilities and detecting zero-day events. However, while WAFs provide behavioral-based capabilities using application-learning methods, they incur a high volume of false-positive detections. Click here to learn more about the shortfalls of web application security and why application learning is not enough.”]
Source: https://www.bankinfosecurity.com/whitepapers/pitfalls-traditional-web-application-security-w-4645