WAF Traffic Analysis for Targeted SAST/DAST Exposure Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network traffic analysis systems fail to accurately identify and address security exposures in web applications, leading to inefficient resource usage and potential security threats.
Innovation Solution
A system that retrieves information from a Web Application Firewall's traffic data log, implements security testing protocols on host applications, determines exposures, generates notifications, and updates access control rules to block relevant traffic portions, using SAST and DAST methodologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network traffic analysis is performed using traditional methods, then basic security monitoring is achieved, but security exposures cannot be accurately identified and addressed
Solution Approach 1:
The patent introduces a code analysis subsystem as an intermediary component that bridges network traffic monitoring and application security testing. This subsystem receives blocked traffic information from the WAF, identifies associated host applications, and performs comprehensive security testing (SAST/DAST) to accurately determine exposures, thereby resolving the contradiction between basic monitoring accuracy and effective security detection.
Solution Approach 2:
The system implements feedback by using blocked traffic instances from WAF logs to trigger security testing protocols on host applications. The results of these tests feed back into the system to generate notifications and refine access control rules, creating a continuous improvement loop that enhances both measurement precision and reliability of security exposure identification.
2Reliability
If comprehensive security testing is performed on all host applications, then security exposures are thoroughly identified, but resource consumption increases
Solution Approach 1:
The patent segments the security testing process by first analyzing blocked traffic instances to identify specific host applications that require testing. Instead of testing all applications comprehensively, the system segments the workload to test only those applications associated with actual blocked traffic, thereby reducing resource consumption while maintaining reliable exposure identification for affected systems.
Solution Approach 2:
The system applies partial action by performing security testing only on host applications associated with blocked traffic instances rather than all applications. This selective approach ensures thorough testing of affected systems while avoiding excessive resource consumption on applications that are not currently experiencing security issues.
3Reliability
If access control rules are updated to block specific traffic portions, then security exposures are mitigated, but system complexity increases
Solution Approach 1:
The system implements self-service by automatically generating and updating access control rules based on security test results. The code analysis subsystem autonomously identifies exposures, generates appropriate access control modifications, and updates the WAF rules without requiring manual intervention, thereby reducing operational complexity while maintaining effective security mitigation.
Solution Approach 2:
The system uses feedback from security testing results to automatically generate and update access control rules. This closed-loop approach where test results feed back into rule generation and update processes simplifies manual rule management while ensuring reliable security exposure mitigation through data-driven decision making.
Data Source
AI summary
Systems, computer program products, and methods are described herein for advanced network traffic analysis in a computing environment. The present disclosure is configured to retrieve, from a traffic data log of a Web Application Firewall (WAF), information associated with a blocked traffic instance; implement, using a code analysis subsystem, a security testing protocol on a host application associated with the blocked traffic instance; determine an exposure associated with the host application based on at least implementing the security testing protocol; generate a notification comprising information associated with the exposure; and transmit a signal configured to cause a computing device associated with the host application to display the notification.


