peer reviewedWeb application firewalls (WAF) are an essential protection mechanism for online software systems. Because of the relentless flow of new kinds of attacks as well as their increased sophistication, WAFs have to be updated and tested regularly to prevent attackers from easily circumventing them. In this paper, we focus on testing WAFs for SQL injection attacks, but the general principles and strategy we propose can be adapted to other contexts. We present ML-Driven, an approach based on machine learning and an evolutionary algorithm to automatically detect holes in WAFs that let SQL injection attacks bypass them. Initially, ML-Driven automatically generates a diverse set of attacks and submit them to the system being protected by...
Abstract A web application is a software system that provides an interface to its users through a we...
Recent work has shown that adversarial examples can bypass machine learning-based threat detectors r...
In recent times, there is an alarming increase in web application attacks, with significant cases, s...
Web application firewalls (WAF) are an indispensable mechanism to protect online systems from attack...
peer reviewedTesting and fixing WAFs are two relevant and complementary challenges for security anal...
Web application firewalls are an indispensable layer to protect online systems from attacks. However...
International audienceInjections flaws which include SQL injection are the most prevalent security t...
Web Application Firewalls are widely used in production environments to mitigate security threats li...
International audience—Injections flaws which include SQL injection are the most prevalent security ...
Web services are increasingly adopted in various domains, from finance and e-government to social me...
In recent years, SQL injection attacks have been identified as being prevalent against web applicati...
Injection vulnerabilities, such as SQL injection (SQLi), are ranked amongst the most dangerous types...
Web services are increasingly adopted in various domains, from finance and e-government to social me...
In the current era, SQL Injection Attack is a serious threat to the security of the ongoing cyber wo...
Web Application Firewalls (WAFs) are plug-and-play security gateways that promise to enhance the sec...
Abstract A web application is a software system that provides an interface to its users through a we...
Recent work has shown that adversarial examples can bypass machine learning-based threat detectors r...
In recent times, there is an alarming increase in web application attacks, with significant cases, s...
Web application firewalls (WAF) are an indispensable mechanism to protect online systems from attack...
peer reviewedTesting and fixing WAFs are two relevant and complementary challenges for security anal...
Web application firewalls are an indispensable layer to protect online systems from attacks. However...
International audienceInjections flaws which include SQL injection are the most prevalent security t...
Web Application Firewalls are widely used in production environments to mitigate security threats li...
International audience—Injections flaws which include SQL injection are the most prevalent security ...
Web services are increasingly adopted in various domains, from finance and e-government to social me...
In recent years, SQL injection attacks have been identified as being prevalent against web applicati...
Injection vulnerabilities, such as SQL injection (SQLi), are ranked amongst the most dangerous types...
Web services are increasingly adopted in various domains, from finance and e-government to social me...
In the current era, SQL Injection Attack is a serious threat to the security of the ongoing cyber wo...
Web Application Firewalls (WAFs) are plug-and-play security gateways that promise to enhance the sec...
Abstract A web application is a software system that provides an interface to its users through a we...
Recent work has shown that adversarial examples can bypass machine learning-based threat detectors r...
In recent times, there is an alarming increase in web application attacks, with significant cases, s...