Hello!

I'm working on pro-active defense for Web applications from 0-day attacks.

If you, too, can't tolerate after the fact nature, poor accuracy, high setup costs, and routinely done by-pass of current so-called web app firewalls please do let me know -- sign up for early access:

http://phpice.com

My approach fundamentally redefines the problem. It embodies compiler principles to precisely nail down vulnerable code, and logical inference across the app stack to uncover multi-staged attacks. The solution requires no pre-training or tuning whatsoever.