Pully
Internship / Master Thesis: Closing the Patch Gap with AI: Exploring Automated WAF Rule Generation from Published CVEs
- 02 octobre 2026
- 100%
- Pully
À propos de cette offre
Start date: February 2027 · Duration: 6 months
Please include your latest academic transcripts with your application. Applications submitted without transcripts will not be considered.
In this 6-month internship or master thesis starting in February 2027, you will tackle a growing challenge: AI is dramatically reducing the time between CVE publication and active exploitation. Exploits can emerge within hours, while patch deployment in complex environments often takes days or weeks.
You will investigate how an AI-driven system could generate WAF (Web Application Firewall) rules from published CVEs to protect systems until permanent fixes are deployed. The exact scope will be defined together with you: a broad proof-of-concept, or a deeper study of a specific topic such as CVE analysis, attack pattern extraction, WAF rule generation or rule validation.
Your tasks
- Explore how AI can analyze newly published CVEs and extract relevant attack patterns
- Design and prototype a mechanism that automatically translates vulnerability information and attack patterns into WAF protection rules
- Evaluate the effectiveness and limitations of AI-generated rules against known exploits, measuring detection accuracy and operational impact
What we offer
- A dynamic, collaborative workplace with a highly motivated, multicultural team working across international sites
- The chance to make a difference in people's lives by building innovative solutions
- Internal coding events such as Hackathons and Brownbag sessions, plus our technical blog
- Monthly After-Works organized at each location
About your profile
- Knowledge of web application security and OWASP concepts
- Knowledge of AI and LLMs
- Interest in security automation
- Familiarity with WAF technologies is a plus