Illegitimate Web Transaction Characterization for Adaptive WAF Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing web application firewalls (WAFs) are inefficient and prone to misconfigurations due to the need for advanced knowledge and frequent changes in web applications, leading to vulnerabilities and increased complexity in managing security policies.

Innovation Solution

A method and device for configuring WAFs using machine learning to analyze HTTP entities, tokenize them based on delimiters, and train models to detect malicious transactions, adapting to changes in web applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of WAF policies is used, then security coverage can be customized, but configuration time and complexity increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs automatic crawling of web applications to extract security policies without requiring manual configuration. The WAF autonomously analyzes HTTP traffic patterns, identifies attack vectors, and generates security rules, eliminating the need for manual policy setup while maintaining comprehensive security coverage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system proactively crawls and analyzes web application structures before attacks occur, extracting security policies in advance. By continuously monitoring and learning from legitimate traffic patterns, the system prepares security rules ahead of time, enabling rapid deployment without manual intervention.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration of WAF policies is used, then security coverage can be customized, but human error increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration accuracy
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The system automatically generates security policies through algorithmic analysis of web traffic patterns, eliminating human error in configuration. The WAF autonomously identifies attack vectors, maps them to security rules, and enforces policies consistently without manual intervention, ensuring high configuration accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors web traffic and adjusts security policies based on observed patterns. By learning from actual traffic data and attack attempts, the system refines its rule generation, improving configuration accuracy over time through feedback loops that adapt to changing application structures.

Inventive Principle:
Principle #23Feedback

3Device complexity

If static WAF policies are enforced, then configuration is simpler, but adaptability to application changes decreases

Engineering Contradiction:
Improvepolicy managementVSAvoidadaptability to changes
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static policies to dynamic, learning-based security rules. The WAF continuously crawls web applications, extracts current traffic patterns, and generates updated security policies that adapt to application changes. This dynamic approach maintains simplicity in policy enforcement while achieving high adaptability to evolving web structures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs continuous crawling and analysis of web applications, maintaining an ever-updated understanding of application structures. This continuous learning process ensures security policies remain current with application changes, providing both simple policy management and high adaptability through uninterrupted monitoring and adaptation.

Inventive Principle:
Principle #20Continuity of useful action

4Reliability

If advanced security solutions are deployed, then protection capability improves, but complexity of management increases

Engineering Contradiction:
Improveprotection capabilityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automates the entire security policy generation process, eliminating the need for manual configuration and complex management. The WAF autonomously crawls applications, analyzes traffic patterns, identifies security risks, and generates optimized policies, reducing management complexity while maintaining advanced protection capabilities through intelligent automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual mechanical configuration processes with automated algorithmic analysis. Instead of requiring human experts to manually create and manage security rules, the system uses machine learning and pattern recognition to automatically generate and update policies, simplifying management while enhancing protection through computational intelligence.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12432178B2Characterization of illegitimate web transactions
Publication Date: 2025.09.30 RADWARE LTD
  • US12432178B2 patent drawing
  • US12432178B2 patent drawing
  • US12432178B2 patent drawing

AI summary

A device and method for configuring a web application firewall (WAF) based on characterization of web attacks are provided. The method includes receiving a plurality of hypertext transfer protocol transactions (HTTP) entities; tokenizing the received plurality of HTTP entities based on at least one delimiter; analyzing statistical distribution of each of the at least one delimiter in the tokenized HTTP entities; training a model based on an analysis of the tokenized HTTP entities, when a sufficient number of HTTP entities have been analyzed; and configuring, based on the trained model, the WAF with at least one detection rule to detect at least malicious HTTP transactions.