Sunday, January 18, 2015

RvR, WAFEP and WAVSEP results update

Most of my time these days is spent on creating a dynamic interface for updating benchmark results, and on two major projects aimed at enhancing the WAVSEP evaluations and adding additional comparison content, in addition to accuracy, crawling and automation.

The first project, RvR (Relative Vulnerability Rating), is a project I already mentioned in the past which merges vulnerabilities from well known vulnerability classifications (WASC, CWE, CAPEC, OWASP, Blogs, Conferences, etc) into a list customized specifically for product feature evaluations.

The list, originally planned to include 233 attack vectors, already includes 284 (!!!) different attack vectors with unique classifications, links, repository mapping and videos,
A web site containing the content was published last week, and although all the content is very much usable, I'm still delaying the publication until I get some vendor feedback (expect an official publication soon).

The purpose of the project is not only to evaluate features of dynamic vulnerability scanners (DAST), but also to cover source code analysis tools (SAST), interactive application testing tools (IAST), and in contrast to the past - various software protection products, including application-level IDS/IPS mechanisms and web application firewalls (WAF).

Which leads me to the second project -

WAFEP - The Web Application Firewall Evaluation Project

WAFEP is an upcoming project aimed to serve a WAVSEP-like role for various application-level protection products.

Unlike WAVSEP, WAFEP is planned on being completely automated in terms of payload execution AND result calculation, and would enable the evaluation of web application firewalls in relatively short timeframes.

The "accuracy" aspect is implemented as attack vector specific payloads meant to simulate context-specific exploits that an IDS/IPS/WAF should identify and/or prevent, false positive scenarios that should not be identified, and in the future, evasion techniques that may circumvent the detection process.

The project already includes thousands of payloads imitating flavors of +-10 high-impact attack vectors, some of which were already published in an early alpha version uploaded to the project source forge repository last week.

The published alpha version is just a technology POC, and does not include most of the vector payloads or content, but in the upcoming weeks I'll make an effort to finish up some sections in the platform and release a v1.0 public version.
I'll also publish updated versions with relevant payloads in the meantime, at least until I reach the 1.0 goal.

WAVSEP Results Update

Finally, from time to time, I still try to squeeze in additional WAVSEP product assessments for additional vendors, the latest of which is Tinfoil Security, alongside certain version upgrades,

As always, the full list is found in SecToolMarket, and the following image summarizes the updates:

If all goes well, in the near future, the list will be updated with the results of a couple of more.

I didn't update the results of any of the open source products, and will try to find the time to do so in the near future, at least for some of the projects - a task that should be much easier once the dynamic interface is finally online.


  1. SecToolMarket still shows "The current information is based on the results of the *2011/2012* benchmarks" is that still true or is it based on the 2014 [1] results? (Plus hopefully this Jan 2015 info as an update [green and yellow icons as stated?])


    1. No, its based on the 2014 benchmark, plus all the updates that came afterwards, including the Jan 2015 updates.
      Completely forgot about that comment, which was true only prior to the 2014 publication.

      The green/yellow icons system however only function properly in some cases, and after double checking it, seems not to point out some key updates that were made, another item to my todo list.

      Thanks for mentioning it, I'll remove it as soon as I get the chance.

      In any event, the content of SecToolMarket is planned to be merged into a new website recently published which will also include scores for other security products -
      I'll post a twitter / blog announcement as soon as its up.

    2. Thanks for the followup Shay.

  2. RvR, WAFEP and WAVSEP results update and better blog more information our site
    NPO network planning and optimization

  3. Easy readable post with many important information. I must back again for something new. Keep up posting and share with us. Thanks for your great staff....
    Safety Spray Shields

  4. This is really an important blog with many helpful information. I have been searching for a long time for this types of content. Keep up posting more and thanks for your great staff.
    Battery Operated Ultrasonic Level Sensor

  5. Thanks, You wrote awesome, I have learn lots of things from your article. Its really helpful for any readers.
    Battery Operated Flow Meter

  6. Great post, you have pointed out some excellent points, I as well believe this is a very superb website.
    Plastic Flow Meter

  7. I want to thank you for writing this article.. It also more very informative & awesome. I expect more articles from you in future. Awesome information. Earning Money Online

  8. Nice article. This blog is very informative and I found very helpful information on IAST. Thanks for sharing.

  9. Thanks for posting the useful information.
    Manasmicro is best Ultrasonic flow meter and ultrasonic water flow meter supplier in pune India.
    ultrasonic flow meter – Manasmicro

  10. A debt of gratitude is in order for offer this post and keep share for Mobiles articles. Its important and pleasant data .Thanks for sharing it.


  11. zapya
    zapya app
    zapya apk
    zapya download
    The development of technology is undeniable and very useful, but it has this type of disadvantage.