Loading…
BSides Cymru has ended
Saturday, September 28 • 2:50pm - 3:50pm
An overview of Project Ava - Can machine learning be used to complement web penetration testing?

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
This talk will provide an overview of Project Ava – a 400 day research project that we performed to explore whether machine learning could ever be used to complement web application penetration testing. The research began from ground zero with very little prior knowledge to machine learning and the various techniques that it offers. Over the course of the research we developed four different proofs of concept using different machine learning techniques, each with their own signs of promise and limitation. In addition to exploring neural networks and anomaly detection to uncover SQL injection flaws, we also explored reinforcement learning and use of expert systems to uncover XSS vulnerabilities. During the research we also went off on a brief yet curious tangent exploring use of machine learning in social engineering situations, leveraging the power of Natural Language Processing (NLP) and personality trait analysis in this regard.

This talk will walk through the various phases of our research, what we did, what we learned with some demos along the way. We hope that the talk will help stimulate thought and discussion on the role of machine learning in penetration testing.



Speakers
avatar for Matt Lewis

Matt Lewis

Commercial Research Director, NCC Group
Matt is an experienced Technical Research Director with over 20 years of experience in cyber security. His specialisms include general security consultancy, scenario-based penetration testing, vulnerability research and development of security testing tools. He studied Computer Science... Read More →


Saturday September 28, 2019 2:50pm - 3:50pm BST
Track 2 - Tramshed Tech Workspace

Attendees (6)