Lie to Me: Bypassing Modern Web Application Firewalls

No ratings

Presented at phdays 2013 by

The report considers analysis of modern Web Application Firewalls. The author provides comparison of attack detection algorithms and discusses their advantages and disadvantages. The talk includes examples of bypassing protection mechanisms. The author points out the necessity of discovering a universal method of masquerading for vectors of various attacks via WAFs for different algorithms. Vladimir Vorontsov is the founder, head and leading expert of the company ONsec. He is engaged in researche in the field of web application security since 2004. The author of many studies in the field of web application security. Awarded by Google for identifying vulnerabilities of their browser Chrome; by the company Yandex for achievements in the competition "Vulnerability Scan Month”; by Trustwave for the achievements in ModSecurity SQLi Challenge, "1C Bitrix" for successful participation in the competition for the circumvention of proactive protection. At the present time he is actively engaged in the development of self-learning systems for detecting attacks on Web applications and heuristic analysis.Vladimir Vorontsov Vladimir Vorontsov