1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
//! Evasion result — a transformed request with metadata.
//!
//! Carries the mutated request, which techniques were applied, a
//! human-readable description, and a confidence score estimating
//! bypass probability.
use std::fmt;
use serde::{Deserialize, Serialize};
use crate::Request;
use crate::Technique;
/// A transformed request ready to send.
///
/// Carries the mutated request, which techniques were applied, a
/// human-readable description, and a confidence score estimating
/// how likely this is to bypass the WAF.
///
/// # Construction
///
/// Use [`EvasionResult::new`] or [`EvasionResult::with_confidence`].
/// Direct struct construction is prevented by `#[non_exhaustive]`.
#[derive(Debug, Clone, Serialize, Deserialize)]
#[non_exhaustive]
pub struct EvasionResult {
/// The transformed request with evasion techniques applied.
pub request: Request,
/// Which techniques were applied.
pub techniques: Vec<Technique>,
/// Human-readable description of what was done.
pub description: String,
/// Estimated bypass probability (0.0–1.0).
///
/// Higher values indicate more aggressive or historically successful
/// techniques. Updated by the evolution engine after feedback.
pub confidence: f64,
}
impl EvasionResult {
/// Create a new evasion result with heuristic confidence.
#[must_use]
pub fn new(request: Request, techniques: Vec<Technique>, description: String) -> Self {
let confidence = Self::estimate_confidence(&techniques);
Self {
request,
techniques,
description,
confidence,
}
}
/// Create with an explicit confidence score (used by evolution engine).
#[must_use]
pub fn with_confidence(
request: Request,
techniques: Vec<Technique>,
description: String,
confidence: f64,
) -> Self {
Self {
request,
techniques,
description,
confidence: confidence.clamp(0.0, 1.0),
}
}
// ── Accessors ────────────────────────────────────────────────
/// Returns a reference to the transformed request.
#[must_use]
pub fn request(&self) -> &Request {
&self.request
}
/// Returns a mutable reference to the transformed request.
pub fn request_mut(&mut self) -> &mut Request {
&mut self.request
}
/// Returns a slice of the techniques applied.
#[must_use]
pub fn techniques(&self) -> &[Technique] {
&self.techniques
}
/// Returns the description of what was done.
#[must_use]
pub fn description(&self) -> &str {
&self.description
}
/// Returns the bypass confidence score (0.0–1.0).
#[must_use]
pub fn confidence(&self) -> f64 {
self.confidence
}
/// Update the confidence score (used by evolution feedback loop).
pub fn set_confidence(&mut self, confidence: f64) {
self.confidence = confidence.clamp(0.0, 1.0);
}
// ── Internals ────────────────────────────────────────────────
/// Heuristic confidence estimation based on technique composition.
///
/// Multi-layered evasions score higher. Grammar mutations score higher
/// than encoding-only because they defeat semantic analysis, not just
/// pattern matching.
fn estimate_confidence(techniques: &[Technique]) -> f64 {
if techniques.is_empty() {
return 0.0;
}
let mut score: f64 = 0.0;
for t in techniques {
score += match t {
Technique::PayloadEncoding(_) | Technique::BoundaryManipulation => 0.15,
Technique::ContentTypeSwitch(_) => 0.20,
Technique::JsonUnicodeEscape
| Technique::TlsFingerprint(_)
| Technique::HeaderObfuscation(_) => 0.10,
Technique::UserAgentRotation | Technique::Http2Settings => 0.05,
Technique::GrammarMutation(_) => 0.30,
Technique::RequestSmuggling(_) => 0.35,
Technique::H2Evasion(_) => 0.25,
Technique::DifferentialProbe => 0.0,
Technique::BodyPadding(_) => 0.20,
// ML boundary attack: high confidence bypass.
Technique::MlEvasion { .. } => 0.40,
};
}
// Multi-layer bonus: stacking techniques is more effective
if techniques.len() >= 3 {
score += 0.10;
}
score.min(1.0)
}
/// Number of techniques applied.
#[must_use]
pub fn technique_count(&self) -> usize {
self.techniques.len()
}
/// Check if a grammar mutation technique was used.
#[must_use]
pub fn uses_grammar(&self) -> bool {
self.techniques
.iter()
.any(|t| matches!(t, Technique::GrammarMutation(_)))
}
/// Check if smuggling was used (high-impact but high-risk).
#[must_use]
pub fn uses_smuggling(&self) -> bool {
self.techniques
.iter()
.any(|t| matches!(t, Technique::RequestSmuggling(_)))
}
/// Check if header obfuscation was used.
#[must_use]
pub fn uses_header_obfuscation(&self) -> bool {
self.techniques
.iter()
.any(|t| matches!(t, Technique::HeaderObfuscation(_)))
}
}
impl fmt::Display for EvasionResult {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
write!(
f,
"[{:.0}%] {} technique(s): {}",
self.confidence * 100.0,
self.techniques.len(),
self.description
)
}
}
#[cfg(test)]
#[allow(clippy::float_cmp)]
mod tests {
use super::*;
#[test]
fn evasion_result_confidence() {
let req = Request::get("https://example.com");
let result = EvasionResult::new(
req,
vec![
Technique::GrammarMutation("sql_tautology".into()),
Technique::PayloadEncoding("UrlEncode".into()),
],
"grammar + encoding".into(),
);
assert!(
result.confidence > 0.3,
"grammar + encoding should have decent confidence"
);
assert!(result.uses_grammar());
assert!(!result.uses_smuggling());
}
#[test]
fn evasion_result_empty_zero_confidence() {
let result = EvasionResult::new(
Request::get("https://example.com"),
vec![],
"no evasion".into(),
);
assert_eq!(result.confidence, 0.0);
}
#[test]
fn evasion_result_display() {
let result = EvasionResult::new(
Request::get("https://example.com"),
vec![Technique::GrammarMutation("xss_polyglot".into())],
"polyglot XSS".into(),
);
let s = result.to_string();
assert!(s.contains('%'));
assert!(s.contains("polyglot XSS"));
}
#[test]
fn with_confidence_clamps() {
let result = EvasionResult::with_confidence(
Request::get("https://example.com"),
vec![],
"test".into(),
1.5,
);
assert_eq!(result.confidence, 1.0);
let result2 = EvasionResult::with_confidence(
Request::get("https://example.com"),
vec![],
"test".into(),
-0.5,
);
assert_eq!(result2.confidence, 0.0);
}
#[test]
fn accessor_methods() {
let result = EvasionResult::new(
Request::get("https://example.com"),
vec![Technique::GrammarMutation("sql".into())],
"test desc".into(),
);
assert_eq!(result.request().url(), "https://example.com");
assert_eq!(result.techniques().len(), 1);
assert_eq!(result.description(), "test desc");
assert!(result.confidence() > 0.0);
}
#[test]
fn set_confidence_clamps() {
let mut result =
EvasionResult::new(Request::get("https://example.com"), vec![], "test".into());
result.set_confidence(2.0);
assert_eq!(result.confidence(), 1.0);
result.set_confidence(-1.0);
assert_eq!(result.confidence(), 0.0);
}
}