WAF-A-MoLE: An adversarial tool for assessing ML-based WAFs

Andrea Valenza, Luca Demetrio, Gabriele Costa, Giovanni Lagorio · SoftwareX · 2019

Web Application Firewalls (WAFs) are plug-and-play security gateways that promise to enhance the security of a (potentially vulnerable) system with minimal cost and configuration. In recent years, machine learning-based WAFs are catching up with traditional, signature-based ones. They are competitive because they do not require predefined rules; instead, they infer their rules through a learning process. In this paper, we present WAF-A-MoLE, a WAF breaching tool. It uses guided mutational-based fuzzing to generate adversarial examples. The main applications include WAF ( i ) penetration testing, ( i i ) benchmarking and ( i i i ) hardening.

Read the paper · More papers on PaperTik