Urgent.News

What's breaking now, across thousands of outlets.

AI

Cloudflare Uses an AI Harness to Probe and Harden Its WAF

Cloudflare placed frontier AI models inside a controlled testing harness to probe its Web Application Firewall (WAF), using blocked attacks as starting points for models to generate and refine new variations. By Matt Foster

Cloudflare has employed a controlled testing harness that incorporates frontier AI models to probe and strengthen its Web Application Firewall (WAF). The system was fed attack payloads that had previously been blocked by the WAF, and instead of merely replaying fixed test cases, the AI models proposed variations to the encoded, placed, or delivered requests based on previous responses.

The models were given no access to Cloudflare's WAF rules, source code, or internal security data, rendering the test effectively black-boxed from their perspective. A Python harness was responsible for the tasks that Cloudflare did not want to delegate to the AI models, including constructing and replaying HTTP requests, maintaining scenario state, enforcing limits, and collecting responses.

One scenario demonstrated how the feedback loop worked: the model generated multiple mutations of a cloud metadata address, eventually leading to a request blocked by the WAF. Subsequent attempts saw the model retain the same request shape but switch to a trailing-dot representation, resulting in a redirect instead of a WAF block.

Of the 1,107 mutation attempts recorded, 607 produced a post-triage result; 558 were blocked by the WAF and 49 findings were deemed relevant for further remediation work. The majority of these findings pertained to command injection or server-side request forgery (SSRF). Human reviewers then validated these findings, checking for factors like whether the requests had reached the target, remained malicious, were clearly unblocked, fell within the WAF's responsibility, and could be safely reproduced.

The AI harness led to three enhancements in Cloudflare's Managed Ruleset: two new detections (SSRF - Obfuscated Host and SSRF - Restricted Protocol) and an improvement to the existing SSRF - Cloud rule.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at infoq.com →

More in AI

[EXPLAINER] How AI emerged as new threat in Korea's bank hacking crisis

Hackers once had to manually test security defenses, identify vulnerabilities and work out how to exploit them. Now, artificial intelligence (AI) can do much of that work, requiring little human input. That possibility is at the center of Korea's latest security crisis in the financial sector, as investigators have found traces of an…

More from Wednesday 7 October →