Article

Detection or Proof: Rethinking the Central Question Behind WAFs
This paper challenges the idea that WAFs should rely primarily on attack detection. It proposes a risk-based architecture where lower-risk endpoints use detection and anomaly analysis, while high-risk functions require validation of structure, authorization, context, and business logic. The paper concludes that effective WAF security is fundamentally a risk-routing problem.

Securing the RAN #4: From Security Standards to Operational Defense
A practical guide to operationalizing RAN security through base-station hardening, secure cryptographic and key-management practices, proactive threat detection, telemetry analysis, interface protection, and Zero Trust principles across 5G and O-RAN environments.

Addressing Modern SOC Challenges with Agentic Approaches
Modern SOCs are under increasing pressure from alert overload, fragmented investigations, scattered expertise, and complex incident coordination. This article explores how Agentic SOCs use AI agents to connect and streamline the security lifecycle, from alert triage and investigation to response and reporting, while preserving context, reducing repetitive work, and keeping human analysts focused on critical security decisions.

Securing the RAN #3: Security in Standardization Evolution from 3G to 5G-Advanced
How 3GPP has systematically hardened RAN security from 3G through 5G-Advanced, from SUCI encryption defeating IMSI catchers to Zero Trust O-RAN interfaces and next-gen protections for IoT, sensing, and satellite networks.

The Invisible Attack Surface: What Vulnerability Scanners Are Not Telling You!
Traditional vulnerability scanners only see known assets, leaving unknown systems and exposures invisible. As cloud, APIs, and third-party services expand the attack surface, continuous discovery becomes critical. This post shows how Attack Surface Management fills that gap by uncovering hidden risks before attackers do.

WAF Evasion 101: How Attackers Bypass “Security Gates”
Attackers reshape the same malicious payload just enough that the WAF no longer recognizes it, while the backend still executes it exactly as intended. This post walks through the real evasion playbook (encoding tricks, token splitting, noise injection, and reinforcement-learning-driven automated probing) and shows why the problem is structural, not a matter of sloppy engineering.

Why High Accuracy Can Still Mean Bad Security!
High accuracy in security does not guarantee real-world protection. Through the WAMM research study, this post examines what accuracy metrics hide, how false positives and false negatives manifest in production environments, and what a security-grade evaluation framework should actually measure.

Augmenting Security Datasets: A Technical Methodology for Modern Threat Simulation
A comprehensive enhancement of the SR-BH 2020 dataset for WAF training, combining LLM-assisted labeling, diverse benign traffic, and targeted attack injection to improve training data quality.

Securing the RAN #2: Attacks on the Radio Interface
This post explores different attack surfaces, attack vectors, and attack scenarios across the RAN, explaining categories of threats and attacker TTPs supported by attack flow illustrations.