{"id":11777,"date":"2026-03-25T13:59:09","date_gmt":"2026-03-25T13:59:09","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11777"},"modified":"2026-03-25T13:59:10","modified_gmt":"2026-03-25T13:59:10","slug":"when-firewalls-go-blind-custom-tools-ai-agents-and-the-fall-of-traditional-network-inspection","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/when-firewalls-go-blind-custom-tools-ai-agents-and-the-fall-of-traditional-network-inspection\/","title":{"rendered":"When Firewalls Go Blind: Custom Tools, AI Agents, and the Fall of Traditional Network Inspection"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">When Firewalls Go Blind: Custom Tools, AI Agents, and the Fall of Traditional Network Inspection<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As TLS adoption surpasses 90% of global web traffic, the visibility once provided by deep packet inspection (DPI) is rapidly fading. Full SSL\/TLS decryption\u2014once a pillar of network threat detection\u2014has fallen out of favor due to performance degradation, operational complexity, legal concerns, and evolving protocols like HTTP\/3, QUIC, and encrypted DNS. As organizations move toward zero trust and adopt cloud-native security like SASE (Secure Access Service Edge), the practicality of full-payload inspection continues to decline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here, we explore how this reduced visibility affects threat detection, particularly as attackers leverage generative AI to craft exploits, obfuscate payloads, automate reconnaissance, and scale phishing attacks with unprecedented precision. AI agents and LLMs have significantly lowered the barrier to entry for complex attack campaigns, which now blend seamlessly into encrypted traffic flows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We compare how traditional NGFWs and SASE platforms handle SSL decryption today, analyze their limitations in modern encrypted environments, and evaluate how security features like HSTS, certificate pinning, and DNS-over-HTTPS break legacy inspection methods. The paper also examines how attackers increasingly craft \u201csignatureless\u201d payloads, rendering DPI ineffective without access to decrypted traffic. As payload access becomes rare, defenders must shift toward metadata inspection, behavior-based analytics, and AI-driven anomaly detection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This work highlights the pressing need to rethink network security visibility in an encryption-first, AI-assisted threat landscape. It calls for new strategies that balance privacy, performance, and detection fidelity, and maps a path forward for enterprises caught between compliance limitations and escalating adversarial capabilities.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sangay-Lama.png\" alt=\"\" class=\"wp-image-11778\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sangay-Lama.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sangay-Lama-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sangay-Lama-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Sangay-Lama-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong>Sangay Lama &#8211; SecureIQLab<\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sangay Tamang is a Security Researcher and Team Manager at SecureIQLab LLC, where he leads the Security Research and Validation division. He specializes in evaluating cloud-native security platforms, including Web Application Firewalls, API protection, and next-generation cloud firewalls, against real-world threats. Sangay has led multiple validation projects with industry-leading vendors, producing widely recognized comparative reports. Alongside his research, he has contributed to academia as a tutor and project supervisor, mentoring students in networking, robotics, and IoT. His passion lies in applied cybersecurity research, developing custom tools, and advancing strategies for resilience in an encryption-first world.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Cameron-Camp.png\" alt=\"\" class=\"wp-image-11779\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Cameron-Camp.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Cameron-Camp-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Cameron-Camp-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Cameron-Camp-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong>Cameron Camp &#8211; SecureIQLab<\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cameron Camp, CISSP, is a Senior Security Researcher at SecureIQLab with extensive security background all the way up the stack from embedded hardware, firmware and IoT hacking, to medical devices and industrial control systems, with a specific focus on Linux-powered platforms. He&#8217;s now focusing on cloud security, with an emphasis on understanding how to secure the connective tissue holding all the pieces together in an adversarial environment.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back When Firewalls Go Blind: Custom Tools, AI Agents, and the Fall of Traditional Network Inspection As TLS adoption surpasses 90% of global web traffic, the visibility once provided by deep packet inspection (DPI) is rapidly fading. Full SSL\/TLS decryption\u2014once a pillar of network threat detection\u2014has fallen out of favor due<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/when-firewalls-go-blind-custom-tools-ai-agents-and-the-fall-of-traditional-network-inspection\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11777","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11777"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11777\/revisions"}],"predecessor-version":[{"id":11780,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11777\/revisions\/11780"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}