[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124647-en":3,"doc-seo-124647-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124647,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",6,"Technology","Adversarial ModSecurity - Countering Adversarial SQL Injections with Robust Machine Learning","ModSecurity is a widely used open-source web application firewall whose Core Rule Set (CRS) assigns heuristic weights to rules and flags a request when the summed activated weights exceed a threshold. This scoring strategy can produce poor trade-offs for SQL injection, blocking legitimate traffic while remaining vulnerable to adversarial SQLi crafted to evade detection. The proposed robust model, AdvModSec, uses CRS rules as features and applies adversarial training to improve detection while reducing false positives.","Adversarial ModSecurity: Countering Adversarial SQL Injections  \nwith Robust Machine Learning  \narXiv :2308 .04964v2 [ cs .LG] 17 Aug 2023  \nBiagio Montaruli  \n[biagio.montaruli@sap.com](biagio.montaruli@sap.com)[ ](biagio.montaruli@sap.com)SAP Security Research and EURECOM Mougins, France  \nLuca Compagna  \nluca.compagna@sap.com  \nSAP Security Research Mougins, France  \nLuca Demetrio  \n[luca.demetrio@unige.it](luca.demetrio@unige.it)[ ](luca.demetrio@unige.it)University of Genova and Pluribus One Genova, Italy  \nDavide Ariu  \n[davide.ariu@pluribus-one.it](davide.ariu@pluribus-one.it)[ ](davide.ariu@pluribus-one.it)Pluribus One Cagliari, Italy  \nAndrea Valenza  \n[andrea.valenza@prima.it](andrea.valenza@prima.it)[ ](andrea.valenza@prima.it)Prima Assicurazioni Milano, Italy  \nLuca Piras  \n[luca.piras@pluribus-one.it](luca.piras@pluribus-one.it)[ ](luca.piras@pluribus-one.it)Pluribus One Cagliari, Italy  \nDavide Balzarotti  \n[davide.balzarotti@eurecom.fr](davide.balzarotti@eurecom.fr)[ ](davide.balzarotti@eurecom.fr)EURECOMBiot, France  \nBattista Biggio  \n[battista.biggio@unica.it](battista.biggio@unica.it)[ ](battista.biggio@unica.it)University of Cagliari and Pluribus One Cagliari, Italy  \nABSTRACT  \nModSecurity is widely recognized as the standard open-source Web Application Firewall (WAF), maintained by the OWASP Foundation. It detects malicious requests by matching them against the Core Rule Set (CRS), identifying well-known attack patterns. Each rule in the CRS is manually assigned a weight, based on the severity of the corresponding attack, and a request is detected as malicious if the sum of the weights ofthe firing rules exceeds a given threshold. In this work, we show that this simple strategy is largely ineffective for detecting SQL injection (SQLi) attacks, as it tends to block many legitimate requests, while also being vulnerable to adversarial SQLi attacks, i.e., attacks intentionally manipulated to evade detection.  \nTo overcome these issues, we design a robust machine learning model, named AdvModSec, which uses the CRS rules as input features, and it is trained to detect adversarial SQLi attacks. Our experiments show that AdvModSec, being trained on the traffic directed towards the protected web services, achieves a better tradeoff between detection and false positive rates, improving the detection rate of the vanilla version of ModSecurity with CRS by 21% . Moreover, our approach is able to improve its adversarial robustness against adversarial SQLi attacks by 42%, thereby taking a step forward towards building more robust and trustworthy WAFs.  \nKEYWORDS  \nweb application firewalls, sql injection, machine learning, adversarial training  \n1 INTRODUCTION  \nWeb applications are constantly evolving and deployed at a broad scale, thus enabling organizations to offer rich services over the Internet. However, this imposes serious challenges in securing web applications against an increasing number of attacks [16] . Among these, SQL injection (SQLi) consists of injecting a malicious SQL code payload inside regular queries, causing the target  \nweb application to behave in an unintended way or expose sensitive data. Even if many countermeasures to this attack have been proposed [3, 4, 19, 22], the OWASP Foundation still classifies it as one of the top-10 most dangerous web threats [30] . To counter such attacks and protect web applications, WAFs are commonly used asa defense tool in enterprise systems [3, 5]. They work by filtering the incoming requests directed towards the protected applications, blocking suspicious connections.  \nModSecurity [15] is an established open-source WAF solution that builds its defense on top of signatures of well-known attacks, collected by the OWASP Foundation and known as the Core Rule Set (CRS) . If ModSecurity is largely used as WAF solution, the CRS is even more adopted, being considered the de-facto standardized set of rules in the WAFs domain. Many commercial and open-source WAF soluti","cbCaij4bku2KjSG8","https://ap.wps.com/l/cbCaij4bku2KjSG8","pdf",1040693,1,11,"English","en",105,"# Introduction\n## Background on SQL injection and WAFs\n## ModSecurity and the Core Rule Set (CRS)\n## Limitations of heuristic CRS weighting\n# Proposed Approach: AdvModSec\n## Training on CRS rules as features\n## Adversarial training with SQLi fuzzing","[{\"question\":\"Why can ModSecurity’s CRS weight-summing strategy fail against SQL injection?\",\"answer\":\"Because heuristic weights can create an unfavorable balance between detection and false alarms, and the same mechanism can be evaded by adversarial SQLi intentionally designed to bypass CRS detection.\"},{\"question\":\"What is AdvModSec and what inputs does it use?\",\"answer\":\"AdvModSec is a robust machine learning model that uses CRS rules as input features to detect adversarial SQLi attacks more effectively.\"},{\"question\":\"How does training on protected traffic affect detection and false positives?\",\"answer\":\"Training on the traffic directed to the protected web services yields a better trade-off, improving the detection rate of the vanilla ModSecurity CRS-based version by 21%.\"}]","Adversarial ModSecurity - Countering Adversarial SQL Injections with Robust Machine Learning | PDF",1785893514,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"adversarial-modsecurity-countering-adversarial-sql-injections-with-robust-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/adversarial-modsecurity-countering-adversarial-sql-injections-with-robust-machine-learning/124647/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why can ModSecurity’s CRS weight-summing strategy fail against SQL injection?","Question",{"text":75,"@type":76},"Because heuristic weights can create an unfavorable balance between detection and false alarms, and the same mechanism can be evaded by adversarial SQLi intentionally designed to bypass CRS detection.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is AdvModSec and what inputs does it use?",{"text":80,"@type":76},"AdvModSec is a robust machine learning model that uses CRS rules as input features to detect adversarial SQLi attacks more effectively.",{"name":82,"@type":73,"acceptedAnswer":83},"How does training on protected traffic affect detection and false positives?",{"text":84,"@type":76},"Training on the traffic directed to the protected web services yields a better trade-off, improving the detection rate of the vanilla ModSecurity CRS-based version by 21%.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,113,118,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":111,"slug":112},50,"technology",{"id":114,"doc_module":4,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},7,"Healthcare",40,"healthcare",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},8,"Research & Report",30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]