Wave 1 is classic attacks — SQL injection, XSS, path traversal — things with a recognisable payload shape. A rule-based WAF catches most of those. Wave 2 is a newer class that carries no signature: prompt injection against an app’s AI, requests that ask it to leak data, and business-logic abuse. They read as ordinary English, so pattern rules never fire. Below, a signature WAF and Jev see the same set of these semantic attacks.
| Semantic attack (the actual request) | Type | Regex WAF | Jev |
|---|