Another Brick Off the Wall - Deconstructing Web Application Firewalls Using Automata Learning

Another Brick Off the Wall - Deconstructing Web Application Firewalls Using Automata Learning

Black Hat via YouTube Direct link

Intro

1 of 32

1 of 32

Intro

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Another Brick Off the Wall - Deconstructing Web Application Firewalls Using Automata Learning

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Overview
  3. 3 Code Injection Attacks
  4. 4 Code Injection is a Parsing Problem
  5. 5 Web Application Firewalls
  6. 6 WAFs Internals
  7. 7 WAF Rulesets
  8. 8 Why Bypasses Exist
  9. 9 Our Goal
  10. 10 Context Free Grammars
  11. 11 Attack of the Grammars
  12. 12 Why should I care?
  13. 13 However...
  14. 14 Learning to Parse
  15. 15 Learning Automata
  16. 16 Learning Model
  17. 17 Learning DFAs
  18. 18 Equivalence Query
  19. 19 Symbolic Finite Automata
  20. 20 Bootstrapping Automata Learning
  21. 21 Grammar Oriented Filter Auditing
  22. 22 SFADiff XSS Bypass
  23. 23 Generating Program Fingerprints
  24. 24 Modular Design
  25. 25 Core Modules
  26. 26 Built-in Query Handlers
  27. 27 HTTP Request Handler
  28. 28 Browser Parser Handler
  29. 29 Browser Filter Handler
  30. 30 Using GOFA module and HTTP Handler
  31. 31 Conclusions
  32. 32 black hat

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.