Juan Berner


Talk Title:

Rage against the IDOR’s: Using Machine Learning models to detect and stop authorization bypass vulnerabilities


One of the most common vulnerabilities that can be found in web applications is authorization bypass vulnerabilities. These vulnerabilities exploit a lack of authorization controls or bugs in them which would allow unauthorized parties to access user’s data. While many solutions attempt to detect when a possible attack might be happening, alert fatigue can affect teams trying to detect these types of attacks allowing real attacks to go unnoticed. This talk will focus on how we can leverage open-source machine learning tools and techniques to detect when those attempts are successful and blocking them before the user’s data can be compromised.


Juan Berner is a security researcher with over 9 years of experience in the field, currently working as Security Lead Developer at Booking.com, as SME for Application Security and Architect for security solutions.

He has given talks in the past on how to build an open-source SIEM (https://www.ekoparty.org/security-monitoring-like-the-nsa.php), exploiting A/B Testing frameworks (Exploiting A/B Testing for Fun and Profit) or building open source WAF architectures that do not incur on latency or false positives (https://conference.auscert.org.au/speaker/juan-berner/).

Copyright © 2019-20 | Nullcon India | International Security Conference | All Rights Reserved