Detecting Zero-Days Before Zero-Day
Classifying novel HTTP based exploits before they are disclosed is the ultimate challenge of any security defense software such as WAFs. This session will share new approaches that leverage network visibility and existing signature-based WAF to generate a high quality true positive training set. Augmented with additional automatically generated samples, users have built a classifier that has successfully "caught" payloads from new CVEs, even before POCs were available. This is a substantial improvement on existing signatures based systems, which often miss new attack vectors and require more frequent fast human intervention to update.