Rule-Based versus Semantic Web Application Firewalls under LLM-Driven Adaptive SQL-Injection Evasion at the Maximum Protection Setting - Cybersecurity Conference

Rule-Based versus Semantic Web Application Firewalls under LLM-Driven Adaptive SQL-Injection Evasion at the Maximum Protection Setting

Web application firewalls (WAFs) defend against SQL injection either by matching regular-expression signatures or by parsing the request and reasoning about its intent. Prior evasion studies typically drive mutation against detectors with fixed or machine-learning search, and rarely compare a signature engine and a production semantic engine at their strongest settings against an adversary that adapts online. We evaluate both families at the maximum protection setting: Coraza with the OWASP Core Rule Set at Paranoia Level 4, and Chaitin SafeLine in Strict mode, using a closed-loop attacker: a large-language-model generator selects sqlmap tamper transformations, the mutated payload is sent through the live WAF to a self-hosted vulnerable application, and a language-model judge scores the observed HTTP result and steers the next attempt, for up to eight rounds per seed. Across 20 verified injection seeds, the semantic engine (SafeLine) was bypassed on 60% (12/20) and the signature engine (Coraza) on 85% (17/20), with the semantic engine forcing roughly 1.4–1.5× more attacker effort in rounds, tokens, and time. At n = 20 the bypass-rate difference is not statistically significant (McNemar exact p = 0.125). The implication is that at the maximum protection setting the residual bypass channel for both engines is character encoding, an input-normalization problem rather than a detection-logic one.

Karan Khatri Regmi – SecureIQ Lab

Karan Khatri Regmi (Karan KC) is a Senior Security Solutions Architect on the Research & Validation team at SecureIQLab, specializing in web application and API security, WAAP testing and validation methodologies, and GenAI security research. His career spans application security engineering, security consulting, and security architecture roles across banking, financial services, and enterprise environments. He is a Wazuh Ambassador and regularly writes on security research topics. Karan is based in Kathmandu, Nepal, and his work centers on evaluating and validating the effectiveness of security defenses against evolving, adversary-driven attack techniques.