WAPP:从实时流量中安全学习正向安全WAF策略
WAPP: Safe Learning of Positive Security WAF Policies from Live Traffic
浏览论文内容
中文总结 AI 辅助
WAPP框架通过信任过滤、确定性规则合成和验证,从实时流量安全学习正向安全WAF策略,显著提升污染韧性并有效阻断攻击。
中文摘要 AI 辅助
Web应用防火墙(WAF)主要依赖签名来检测已知攻击,这可能会对修改过或此前未见过的载荷留下防护缺口。正向安全提供了一种补充方法,通过学习合法流量并阻断超出所学配置文件的输入。然而,当恶意请求污染训练数据时,直接从实时流量中学习可能是不安全的。本文提出了白名单自主策略生成器(WAPP),这是一个在实施前结合信任过滤、确定性规则合成、置信度评分和验证的框架。WAPP在三个受控应用上使用实时Coraza和OWASP核心规则集(CRS)技术栈进行了评估。结果表明,在测试的DVWA用户名字段上,未过滤学习在0.2%的污染流量下变得退化,在0.5%时变得失效,而评估的自由文本字段即使在无污染情况下也可能允许恶意输入。在冻结的污染数据集上,包含全部七个候选信号的消融配置将测量的污染韧性从53%提高到90%,而Kruegel-Vigna基线为62%。确定性合成器提供了与所测试语言模型相当的攻击阻断能力,且无需模型推理成本。WAPP在受限字段上阻断了已确认的CRS绕过,而自由文本输入仍然是精度挑战,需要字符级操作符控制。
英文摘要
Web Application Firewalls (WAFs) mainly rely on signatures to detect known attacks, which can leave gaps against modified or previously unseen payloads. Positive security provides a complementary approach by learning legitimate traffic and blocking inputs that fall outside the learned profile. However, learning directly from live traffic can be unsafe when malicious requests contaminate the training data. This paper presents the Whitelisting Autonomous Policy Producer (WAPP), a framework that combines trust filtering, deterministic rule synthesis, confidence scoring, and validation before enforcement. WAPP is evaluated on three controlled applications using a live Coraza and OWASP Core Rule Set (CRS) stack. Results show that, on the tested DVWA username field, unfiltered learning becomes Degraded at 0.2\% poisoned traffic and Broken at 0.5%, while the evaluated free text field can admit malicious inputs even without poisoning. On the frozen poisoning dataset, the ablation configuration with all seven candidate signals improves the measured poisoning resilience from 53% to 90%, compared with 62% for the Kruegel--Vigna baseline. The deterministic synthesizer provides attack blocking comparable to the tested language model without model inference cost. WAPP blocks confirmed CRS bypasses on constrained fields, while free text inputs remain a precision challenge that requires character level operator control.
发表机构
- Cyshield Company(赛盾公司)
- Coventry University(考文垂大学)
机构由 AI 辅助整理,请以论文原文为准。