Cloudflare Tests WAF Against Frontier AI Models, Identifies SSRF and CMDi Gaps
Key point
The test generated 1,107 mutation attempts, resulting in 49 validated findings that led to new SSRF detection rules in the Managed Rules update.
Details
Cloudflare conducted a dynamic security test to evaluate its Web Application Firewall (WAF) against frontier AI models acting as adaptive attackers. The project utilized a custom harness where LLMs iterated on attack payloads by mutating encodings, request structures, and delivery methods, leveraging real-time responses to refine subsequent attempts. Unlike static analysis, this approach mimicked human-like adaptation but at machine speed, focusing on six attack categories including Cross-Site Scripting (XSS), Command Injection (CMDi), Server-Side Request Forgery (SSRF), Path Traversal/LFI, and Log Injection.
The testing framework executed 45 scenarios against a live WAF configuration, generating 1,107 recorded mutation attempts. The LLMs were restricted to observing HTTP responses and could not access internal WAF rules or IDs. After rigorous triage to filter out false positives and non-malicious requests, 49 validated findings remained. Notably, 48 of these 49 findings were concentrated in the CMDi and SSRF categories, highlighting specific areas where adaptive AI could bypass existing protections more effectively than in other vectors.
These findings directly informed updates to Cloudflare's Managed Rules. Engineers analyzed the bypass techniques, particularly those involving non-standard host representations, and developed new detection logic. The July 21 release of Managed Rules included:
- SSRF - Obfuscated Host: A new rule targeting requests using non-standard host encodings (e.g., trailing dots) to mask internal addresses.
- SSRF - Restricted Protocol: A new rule detecting attempts to use restricted protocols.
- SSRF - Cloud: An updated rule to improve coverage for cloud metadata services.
The test underscored that while LLMs are effective at generating diverse attack vectors, human validation remains essential. Many AI-generated attempts were harmless or failed to reach the target, requiring a multi-step triage process. Cloudflare emphasizes that WAFs are just one layer of defense; customers are advised to keep Managed Rules enabled, consider Attack Signature Detection, and ensure their underlying applications are patched, as a WAF bypass still requires an exploitable application to succeed.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.