WAPP: Safe Learning of Positive Security WAF Policies from Live Traffic

📅 2026-09-06
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出WAPP框架,通过信任过滤、规则合成等方法从实时流量中安全地学习正向安全策略,以解决WAF对未知或变种攻击的防护不足问题。
📝 Abstract
Web Application Firewalls (WAFs) mainly rely on signatures to detect known attacks, which can leave gaps against modified or previously unseen payloads. Positive security provides a complementary approach by learning legitimate traffic and blocking inputs that fall outside the learned profile. However, learning directly from live traffic can be unsafe when malicious requests contaminate the training data. This paper presents the Whitelisting Autonomous Policy Producer (WAPP), a framework that combines trust filtering, deterministic rule synthesis, confidence scoring, and validation before enforcement. WAPP is evaluated on three controlled applications using a live Coraza and OWASP Core Rule Set (CRS) stack. Results show that, on the tested DVWA username field, unfiltered learning becomes Degraded at 0.2\% poisoned traffic and Broken at 0.5%, while the evaluated free text field can admit malicious inputs even without poisoning. On the frozen poisoning dataset, the ablation configuration with all seven candidate signals improves the measured poisoning resilience from 53% to 90%, compared with 62% for the Kruegel--Vigna baseline. The deterministic synthesizer provides attack blocking comparable to the tested language model without model inference cost. WAPP blocks confirmed CRS bypasses on constrained fields, while free text inputs remain a precision challenge that requires character level operator control.
Problem

Research questions and friction points this paper is trying to address.

Web Application Firewalls
Positive Security
Live Traffic Learning
Malicious Requests
Innovation

Methods, ideas, or system contributions that make the work stand out.

Whitelisting Autonomous Policy Producer
trust filtering
deterministic rule synthesis
confidence scoring
🔎 Similar Papers
No similar papers found.
H
Heba Osama
Cyshield Company, Cairo, Egypt
Zeyad Ahmed
Zeyad Ahmed
Student, University of Prince Edward Island
computational text analysismachine learningcomputational genomics
Mohamed Amgad
Mohamed Amgad
Dept. of Pathology, Northwestern University
Gastrointestinal PathologyComputational PathologyPathologyMachine LearningMedical Education
A
Ahmed Saafan
Cyshield Company, Cairo, Egypt
J
Jana Elfeky
Cyshield Company, Cairo, Egypt
M
Mariam Abdelati
Ethical Hacking and Cybersecurity, Coventry University – Egypt Branch, hosted at The Knowledge Hub Universities, New Cairo, Egypt
H
Haitham Ghalwash
Ethical Hacking and Cybersecurity, Coventry University – Egypt Branch, hosted at The Knowledge Hub Universities, New Cairo, Egypt