כתבה
arXiv cs.AI ·
WAPP: Safe Learning of Positive Security WAF Policies from Live Traffic
תקציר מקורי באנגליתarXiv:2609.06840v1 Announce Type: cross Abstract: Web Application Firewalls (WAFs) mainly rely on signatures to detect known attacks, which can leave gaps against modified or previously unseen payloads. Positive security provides a complementary approach by learning legitimate traffic and blocking inputs that fall outside the learned profile. However, learning directly from live traffic can be unsafe when malicious requests contaminate the training data. This paper presents the Whitelisting Autonomous Policy Producer (WAPP), a framework that combines trust filtering, deterministic rule synthesis, confidence scoring, and validation before enforcement. WAPP is evaluated on three controlled applications using a live Coraza and OWASP Core Rule Set (CRS) stack. Results show that, on the tested
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית