WAFFLED: Exploiting Parsing Discrepancies to Bypass Web Application Firewalls
Fuente:
arXiv
Saved in:
| Main Authors: | Akhavani, Seyed Ali, Jabiyev, Bahruz, Kallus, Ben, Topcuoglu, Cem, Bratus, Sergey, Kirda, Engin |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
HTTP Request Synchronization Defeats Discrepancy Attacks
by: Topcuoglu, Cem, et al.
Published: (2025)
by: Topcuoglu, Cem, et al.
Published: (2025)
PriveShield: Enhancing User Privacy Using Automatic Isolated Profiles in Browsers
by: Akhavani, Seyed Ali, et al.
Published: (2025)
by: Akhavani, Seyed Ali, et al.
Published: (2025)
ENOLA: Efficient Control-Flow Attestation for Embedded Systems
by: Armanuzzaman, Md, et al.
Published: (2025)
by: Armanuzzaman, Md, et al.
Published: (2025)
Open Source, Open Threats? Investigating Security Challenges in Open-Source Software
by: Akhavani, Seyed Ali, et al.
Published: (2025)
by: Akhavani, Seyed Ali, et al.
Published: (2025)
The HTTP Garden: Discovering Parsing Vulnerabilities in HTTP/1.1 Implementations by Differential Fuzzing of Request Streams
by: Kallus, Ben, et al.
Published: (2024)
by: Kallus, Ben, et al.
Published: (2024)
Introducing the Generative Application Firewall (GAF)
by: Farreny, Joan Vendrell, et al.
Published: (2026)
by: Farreny, Joan Vendrell, et al.
Published: (2026)
Secure IP Address Allocation at Cloud Scale
by: Pauley, Eric, et al.
Published: (2022)
by: Pauley, Eric, et al.
Published: (2022)
Local Frames: Exploiting Inherited Origins to Bypass Content Blockers
by: Ukani, Alisha, et al.
Published: (2025)
by: Ukani, Alisha, et al.
Published: (2025)
Indirect Prompt Injections: Are Firewalls All You Need, or Stronger Benchmarks?
by: Bhagwatkar, Rishika, et al.
Published: (2025)
by: Bhagwatkar, Rishika, et al.
Published: (2025)
Physical-Layer Signal Injection Attacks on EV Charging Ports: Bypassing Authentication via Electrical-Level Exploits
by: Shi, Hetian, et al.
Published: (2025)
by: Shi, Hetian, et al.
Published: (2025)
Involuntary In-Context Learning: Exploiting Few-Shot Pattern Completion to Bypass Safety Alignment in GPT-5.4
by: Polyakov, Alex, et al.
Published: (2026)
by: Polyakov, Alex, et al.
Published: (2026)
Firewall Regulatory Networks for Autonomous Cyber Defense
by: Duan, Qi, et al.
Published: (2025)
by: Duan, Qi, et al.
Published: (2025)
Firewalls to Secure Dynamic LLM Agentic Networks
by: Abdelnabi, Sahar, et al.
Published: (2025)
by: Abdelnabi, Sahar, et al.
Published: (2025)
HackWorld: Evaluating Computer-Use Agents on Exploiting Web Application Vulnerabilities
by: Ren, Xiaoxue, et al.
Published: (2025)
by: Ren, Xiaoxue, et al.
Published: (2025)
Advancing Obfuscation Strategies to Counter China's Great Firewall: A Technical and Policy Perspective
by: Li, Li
Published: (2025)
by: Li, Li
Published: (2025)
AI-Driven Dynamic Firewall Optimization Using Reinforcement Learning for Anomaly Detection and Prevention
by: Ahmad, Taimoor
Published: (2025)
by: Ahmad, Taimoor
Published: (2025)
Securing Generative AI Agentic Workflows: Risks, Mitigation, and a Proposed Firewall Architecture
by: Bahadur, Sunil Kumar Jang, et al.
Published: (2025)
by: Bahadur, Sunil Kumar Jang, et al.
Published: (2025)
Exploring and Exploiting the Resource Isolation Attack Surface of WebAssembly Containers
by: Yu, Zhaofeng, et al.
Published: (2025)
by: Yu, Zhaofeng, et al.
Published: (2025)
TraceGuard: Process-Guided Firewall against Reasoning Backdoors in Large Language Models
by: Guo, Zhen, et al.
Published: (2026)
by: Guo, Zhen, et al.
Published: (2026)
Adaptive Dual-Layer Web Application Firewall (ADL-WAF) Leveraging Machine Learning for Enhanced Anomaly and Threat Detection
by: Sameh, Ahmed, et al.
Published: (2025)
by: Sameh, Ahmed, et al.
Published: (2025)
AEGIS: No Tool Call Left Unchecked -- A Pre-Execution Firewall and Audit Layer for AI Agents
by: Yuan, Aojie, et al.
Published: (2026)
by: Yuan, Aojie, et al.
Published: (2026)
ControlNET: A Firewall for RAG-based LLM System
by: Yao, Hongwei, et al.
Published: (2025)
by: Yao, Hongwei, et al.
Published: (2025)
Exploiting Leakage in Password Managers via Injection Attacks
by: Fábrega, Andrés, et al.
Published: (2024)
by: Fábrega, Andrés, et al.
Published: (2024)
Web Execution Bundles: Reproducible, Accurate, and Archivable Web Measurements
by: Hantke, Florian, et al.
Published: (2025)
by: Hantke, Florian, et al.
Published: (2025)
Differentially Private Quasi-Concave Optimization: Bypassing the Lower Bound and Application to Geometric Problems
by: Nissim, Kobbi, et al.
Published: (2025)
by: Nissim, Kobbi, et al.
Published: (2025)
Enabling Privacy-preserving Model Evaluation in Federated Learning via Fully Homomorphic Encryption
by: Baykara, Cem Ata, et al.
Published: (2024)
by: Baykara, Cem Ata, et al.
Published: (2024)
Exploiting Timing Side-Channels in Quantum Circuits Simulation Via ML-Based Methods
by: Dong, Ben, et al.
Published: (2025)
by: Dong, Ben, et al.
Published: (2025)
Adaptive Cybersecurity: Dynamically Retrainable Firewalls for Real-Time Network Protection
by: Ahmadi, Sina
Published: (2025)
by: Ahmadi, Sina
Published: (2025)
Semantic-Aware Parsing for Security Logs
by: Piet, Julien, et al.
Published: (2025)
by: Piet, Julien, et al.
Published: (2025)
An Analysis of Modern Web Security Vulnerabilities Inside WebAssembly Applications
by: Corrias, Lorenzo, et al.
Published: (2026)
by: Corrias, Lorenzo, et al.
Published: (2026)
LlamaFirewall: An open source guardrail system for building secure AI agents
by: Chennabasappa, Sahana, et al.
Published: (2025)
by: Chennabasappa, Sahana, et al.
Published: (2025)
Enforcing Benign Trajectories: A Behavioral Firewall for Structured-Workflow AI Agents
by: Dang, Hung
Published: (2026)
by: Dang, Hung
Published: (2026)
A Large Language Model Approach to Generating Bypass Rules for Malware Evasion in Analysis Sandbox
by: Sui, Zhiyong, et al.
Published: (2026)
by: Sui, Zhiyong, et al.
Published: (2026)
AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications
by: Yang, Ruozhao, et al.
Published: (2026)
by: Yang, Ruozhao, et al.
Published: (2026)
Ancora: Accurate Intrusion Recovery for Web Applications
by: Peng, Yihao, et al.
Published: (2025)
by: Peng, Yihao, et al.
Published: (2025)
Security Analysis of Web Applications Based on Gruyere
by: Ni, Yonghao, et al.
Published: (2025)
by: Ni, Yonghao, et al.
Published: (2025)
Demystifying Progressive Web Application Permission Systems
by: Wang, Mengxiao, et al.
Published: (2025)
by: Wang, Mengxiao, et al.
Published: (2025)
BioShield: A Context-Aware Firewall for Securing Bio-LLMs
by: Das, Protiva, et al.
Published: (2026)
by: Das, Protiva, et al.
Published: (2026)
Casper: Prompt Sanitization for Protecting User Privacy in Web-Based Large Language Models
by: Chong, Chun Jie, et al.
Published: (2024)
by: Chong, Chun Jie, et al.
Published: (2024)
Securing Stack Smashing Protection in WebAssembly Applications
by: Michaud, Quentin, et al.
Published: (2024)
by: Michaud, Quentin, et al.
Published: (2024)
Similar Items
-
HTTP Request Synchronization Defeats Discrepancy Attacks
by: Topcuoglu, Cem, et al.
Published: (2025) -
PriveShield: Enhancing User Privacy Using Automatic Isolated Profiles in Browsers
by: Akhavani, Seyed Ali, et al.
Published: (2025) -
ENOLA: Efficient Control-Flow Attestation for Embedded Systems
by: Armanuzzaman, Md, et al.
Published: (2025) -
Open Source, Open Threats? Investigating Security Challenges in Open-Source Software
by: Akhavani, Seyed Ali, et al.
Published: (2025) -
The HTTP Garden: Discovering Parsing Vulnerabilities in HTTP/1.1 Implementations by Differential Fuzzing of Request Streams
by: Kallus, Ben, et al.
Published: (2024)