
DEF CON 32 - BOLABuster-Harnessing LLMs for Automating BOLA Detection - Ravid Mazon, Jay Chen
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 32:39
Palo Alto Networks researchers developed Bola Buster, an AI-powered methodology that automates detection of Broken Object Level Authorization (BOLA) vulnerabilities using LLMs, achieving 100% true positive rate in testing 2:00-3:14.
Key Takeaways:
• BOLA vulnerabilities allow unauthorized access to other users' data, ranked #1 in OWASP API Top 10 with severe consequences including data leaks and account takeovers 2:32-4:24
• Bola Buster analyzes OpenAPI specs to identify vulnerable endpoints, uncovers dependencies between endpoints, and generates automated test scripts using LLMs 7:36-9:42
• Testing against deliberately vulnerable apps showed Bola Buster found all BOLA vulnerabilities with less than 1% API calls compared to existing tools like Restler 21:14-22:41
• The methodology discovered 17 new BOLA vulnerabilities in popular projects including Harbor, Grafana, and Easy Appointments, with 7 rated critical (CVSS 9.9) 28:02-29:06
• Key lessons: Don't use AI for problems with classical solutions, always validate AI output, and simplify AI tasks using divide-and-conquer 31:37-32:33
Bola Buster demonstrates the effective application of AI for security testing, achieving superior results in detecting critical BOLA vulnerabilities with significantly fewer API calls than traditional tools.
Sources:
- 2:00-3:14 Introduction to Bola Buster methodology
- 2:32-4:24 Explanation of BOLA vulnerability and risks
- 7:36-9:42 Detailed methodology stages
- [21:14-22:41](https://www.youtube.com
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all right it is my fantastic uh opportunity to introduce Ravid and Jay talking about babster all right all right check check everybody hear me okay great uh so good morning everybody and uh thanks for joining uh we are really excited to present in the UPC Village and today we are going uh to talk about bolab Buster uh our methodology that we developed uh in order to automate Bol detection at scale using uh llms but first uh let's introduce ourself so my name is Ravid I'm a security researcher at Palo Alto networks I expertise in the was field which is a web application and API security mainly and in my free time I enjoy watching football games uh traveling the world and take care of my dog Maple hi my name is Jay I am a security researcher with Pilato networks and my research has been focu…