Researchers have developed a new framework called WAPP (Whitelisting Autonomous Policy Producer) designed to safely learn positive security policies for Web Application Firewalls (WAFs) from live traffic. Traditional WAFs often rely on signatures, leaving them vulnerable to novel attacks, while positive security approaches learn legitimate traffic patterns. However, direct learning from live data can be compromised by malicious inputs. WAPP addresses this by integrating trust filtering, rule synthesis, confidence scoring, and validation before enforcing policies. Experiments on controlled applications demonstrated WAPP's effectiveness in enhancing poisoning resilience compared to existing methods, while offering comparable attack blocking to language models without the inference cost. AI
IMPACT This research could lead to more robust and secure web application firewalls by enabling safer and more effective learning from live traffic data.
RANK_REASON This is a research paper detailing a new framework for WAF policy learning. [lever_c_demoted from research: ic=1 ai=0.7]
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →