Enhancing web defense through machine learning and active response mechanism integration in WAF

Authors

  • Antonio Varialle
  • Gerard Borg
  • Agung Prasetiawan

Keywords:

Web Application Security, Machine Learning, Web Application Firewall, WAF, Dynamic Security Framework, Zeroday

Abstract

Web applications are vital in today's digital infrastructure, offering fast and flexible access to services and information. However, they face security challenges due to increasingly sophisticated cyber attacks. This study addresses the problem of conventional Web Application Firewalls (WAFs) struggling to adapt to evolving threats like zero-day attacks because of their reliance on static rules and ssignatures. We propose a novel approach that integrates machine learning and active response mechanisms to enhance WAF adaptability. The methodology involves training a machine learning model on diverse datasets to identify and categorize malicious activities, ensuring robustness against various attack scenarios. Additionally, we develop a library to predict future attack patterns, facilitating an active response system. The results demonstrate improved detection and response to current and future threats by combining supervised and unsupervised learning for both initial training and ongoing adaptation, effectively enhancing WAF capabilities.

Downloads

Download data is not yet available.

References

Applebaum, S., Gaber, T., & Ahmed, A. (2021). Signature-based and machine-learning-based web application firewalls: A short survey. Procedia Computer Science, 189, 359–367.

Calvo, M., & Beltrán, M. (2022). An adaptive web application firewall. In Proceedings of the 19th International Conference on Security and Cryptography (pp. 96–107). SCITEPRESS – Science and Technology Publications.

Chicco, D., Warrens, M. J., & Jurman, G. (2021). The Matthews correlation coefficient (MCC) is more informative than Cohen’s kappa and Brier score in binary classification assessment. IEEE Access, 9, 78368–78381.

Coscia, A., Dentamaro, V., Galantucci, S., Maci, A., & Pirlo, G. (2023). An innovative two-stage algorithm to optimize firewall rule ordering. Computers & Security, 134, Article 103423.

Dawadi, B., Adhikari, B., & Srivastava, D. (2023). Deep learning technique-enabled web application firewall for the detection of web attacks. Sensors, 23(4), 2073.

Jemal, I., Haddar, M. A., Cheikhrouhou, O., & Mahfoudhi, A. (2022). SWAF: A smart web application firewall based on convolutional neural network. In 2022 15th International Conference on Security of Information and Networks (SIN) (pp. 1–6). IEEE.

Kar, D., Panigrahi, S., & Sundararajan, S. (2016). SQLiGoT: Detecting SQL injection attacks using graph of tokens and SVM. Computers & Security, 60, 206–225.

Manaseer, S., & Al Hwaitat, A. K. (2018). Centralized web application firewall security system. Modern Applied Science, 12(10), 164.

Mohammadi Rouzbahani, H., Karimipour, H., Rahimnejad, A., Dehghantanha, A., & Srivastava, G. (2020). Anomaly detection in cyber-physical systems using machine learning. In H. Jahankhani (Ed.), Handbook of Big Data Privacy (pp. 219–235). Springer International Publishing.

Riera, T. S., Higuera, J.-R. B., Higuera, J. B., Herraiz, J.-J. M., & Montalvo, J.-A. S. (2022). A new multi-label dataset for web attacks CAPEC classification using machine learning techniques. Computers & Security, 120, Article 102788.

Sepczuk, M. (2022). Dynamic web application firewall detection supported by cyber mimic defense approach. SSRN Electronic Journal.

Shaheed, A., & Kurdy, M. H. D. B. (2022). Web application firewall using machine learning and features engineering. Security and Communication Networks, 2022, 1–14.

Shahid, W. B., Aslam, B., Abbas, H., Afzal, H., & Khalid, S. B. (2022a). A deep learning assisted personalized deception system for countering web application attacks. Journal of Information Security and Applications, 67, Article 103169.

Shahid, W. B., Aslam, B., Abbas, H., Khalid, S. B., & Afzal, H. (2022b). An enhanced deep learning based framework for web attacks detection, mitigation and attacker profiling. Journal of Network and Computer Applications, 198, Article 103270.

Sun, L., & Li, L. (2012). Improve Aho-Corasick algorithm for multiple patterns matching memory efficiency optimization. Journal of Convergence Information Technology, 7(19), 162–168.

Surendhar, K., Pandey, B. K., Geetha, G., & Gohel, H. (2023). Detection of payload injection in firewall using machine learning. In 2023 IEEE 12th International Conference on Communication Systems and Network Technologies (CSNT) (pp. 186–190). IEEE.

Tiwari, C., Pillai, S., Obaid, A. J., Saear, A. R., & Sabri, A. K. (2023). Integration of artificial intelligence/machine learning in developing and defending web applications. In AIP Conference Proceedings (Vol. 2990, Article 060038). AIP Publishing.

Tundis, A., Ruppert, S., & Mühlhäuser, M. (2022). A feature-driven method for automating the assessment of OSINT cyber threat sources. Computers & Security, 113, Article 102576.

Wang, S., Liu, R., Guo, X., & Wei, G. (2022). Design of web application firewall system through convolutional neural network and deep learning. In 2022 International Conference on Computers, Information Processing and Advanced Education (CIPAE) (pp. 454–457). IEEE.

Xuan, C. D., Nguyen, N., & Dinh, H. N. (2020). An adaptive anomaly request detection framework based on dynamic web application profiles. International Journal of Electrical and Computer Engineering (IJECE), 10(5), 5335–5346.

Downloads

Published

2026-01-31 — Updated on 2026-06-20

Versions