Radware has announced a new cloud-based Web DDoS Protection service designed to block sophisticated encrypted application-layer attacks without requiring SSL certificate sharing or traffic decryption a capability the company says represents an industry first.
As encrypted traffic now accounts for the majority of web communications, many organisations rely on SSL decryption to inspect traffic for threats targeting the application layer, also known as Layer 7 attacks. However, decrypting traffic in the cloud often introduces operational, regulatory and privacy challenges, particularly for industries subject to strict data governance requirements.
Radware’s new service aims to remove that barrier.
According to the company, the cloud-based deployment enables organisations to mitigate encrypted DDoS attacks without exposing SSL certificates or decrypting traffic, allowing security teams to maintain strong protection while preserving privacy and compliance frameworks.
“Many organisations want strong Web DDoS protection but are hesitant or unable to share SSL certificates or decrypt traffic in the cloud,” said Haim Zelikovsky, vice president of cloud security business at Radware. “This release makes our proven Web DDoS protections available as a cloud service designed to eliminate that requirement.”
AI-Powered Protection for Encrypted Applications
The solution uses behavioural analysis, machine learning models and traffic baselining to detect anomalies associated with DDoS activity. Once abnormal patterns are identified, the system automatically generates mitigation rules designed to block malicious traffic while allowing legitimate user activity to continue.
The AI-powered detection engine is designed to adapt as traffic patterns change, reducing the need for manual policy tuning and enabling real-time mitigation of Layer 7 attacks.
Application-layer DDoS attacks are increasingly difficult to detect because they mimic legitimate user behaviour while targeting web applications directly. When these attacks are delivered over encrypted connections, visibility becomes even more limited.
Radware’s approach focuses on analysing traffic behaviour rather than inspecting decrypted payloads, allowing protection to operate even when encryption remains intact.
Flexible Deployment Options
In addition to the new cloud-based service, organisations can deploy the technology through several different environments depending on operational requirements.
Options include deployment via Radware’s Cloud Security Platform, on-premise installations using the company’s DefensePro appliances, or integrated application delivery and security through Alteon Protect appliances. For cloud-native architectures, the solution can also be deployed within Kubernetes environments using Radware Kubernetes WAAP.
This range of deployment models enables organisations to implement DDoS protection across cloud, on-premise, hybrid and containerised environments.
With encrypted traffic continuing to grow and compliance requirements tightening worldwide, Radware’s new service reflects a broader shift in the cybersecurity industry towards security models that protect applications without compromising encryption or data privacy.








