API Security

Protecting gRPC applications and APIs

Wallarm has always stood out from its competitors when it comes to supporting modern stacks. For a long time Wallarm has been the only product to provide comprehensive protection for WebSockets-based web applications. Once again, Wallarm is glad to be the pioneer and add support for the gRPC protocol. The newly added WAF for gPRC feature is available to all the customers that use the latest 2.14 version of Wallarm Node. 

Adoption of gPRC

Many customers, especially among large tech companies, are adopting gRPC as a fundamental piece of technology while architecting their new APIs and microservices.

The protocol/framework advantages include plug-in support for load balancing, tracing, health checks, and authentication. gRPC was originally developed by Google for internal use and published for general access in 2015. Now it is used by companies such as Netflix, Cisco, Dropbox, and many others. To optimize connectivity gRPC uses HTTP/2 as a transport and, protobuf as a mechanism for serializing and defining data types.

Difference between HTTP/1.0 and HTTP/2 when it comes to requests and replies

Like any technology that is gaining popularity, gRPC has already attracted the attention of security researchers. Several vulnerabilities have already been discovered and fixed in the protocol itself. That being said, gPRC applications remain vulnerable to the exact same security issues and threats as any other apps and APIs. Therefore, they require proper protection and security controls.

gRPC framework

Intelligent Parsing

Support of gRPC protection is available with Wallarm Node 2.14. New and improved mechanism is a part of the Intelligent Parsing technology, a critical component of filter node that is in charge of super fast parsing and analyzing every request that comes to the web app or API.

For gRPC calls, Wallarm Node runs deep request inspection of an HTTP request, parses Protobuf messages and detects malicious payloads even if they are nested inside complex data structures. This allows you to protect gRPC based APIs against the modern-day challenges, ranging from OWASP Top10 threats to Account Takeover.

Protection and Development Velocity

To protect start your gRPC-based APIs, you do not need any additional configuration. Or require upload of any API schema or protobuf structures.

As with any other APIs (whether they are built on XML or JSON or whatever), Wallarm does not require extra configuration to conduct deep inspection of a request and apply attack detection mechanism for each and every parameter of the API call. 

You can protect the APIs that use gRPC and are frequently updated as a part of the CI/CD process. You can protect North-South traffic of the publicly exposed assets as well as East-West traffic between gRPC-based microservices. This new feature of Wallarm makes protecting gRPC applications and APIs truly straightforward and reliable. 

Recent Posts

CISO Spotlight: Dimitris Georgiou on Building Security that Serves People First

Dimitris Georgiou has been a self-professed computer geek since the early 80s. At university, he…

2 weeks ago

The CISO’s Dilemma: How To Scale AI Securely

Your board wants AI. Your developers are building with it. Your budget committee is asking…

4 weeks ago

Agent-to-Agent Attacks Are Coming: What API Security Teaches Us About Securing AI Systems

AI systems are no longer just isolated models responding to human prompts.  In modern production…

1 month ago

Everyone Knows About Broken Authorization – So Why Does It Still Work for Attackers?

Broken authorization is one of the most widely known API vulnerabilities.  It features in the…

1 month ago

From Shadow APIs to Shadow AI: How the API Threat Model Is Expanding Faster Than Most Defenses

The shadow technology problem is getting worse.  Over the past few years, organizations have scaled…

2 months ago

Inside Modern API Attacks: What We Learn from the 2026 API ThreatStats Report

API security has been a growing concern for years. However, while it was always seen…

2 months ago