You pay to serve unwanted traffic. For popular domains this can be a full time job without some form of rate limiting or identity verification.
I have integrated production WAF's and migrated between WAF providers in large production environments. That here are some tricks I've learned along the way to keep cost down. I can also talk through the differences in Cost which can be high if you serve a lot of traffic or content.
- AWS WAF & Cloudfront
- Cloudflare
- Fastly