[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124465-en":3,"doc-seo-124465-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124465,1099514068365,"Aurelia","https://ap-avatar.wpscdn.com/avatar/10000253d8d9f28188e?_k=1776742907772140068",8,"Research & Report","Improving WAF Detection Capabilities Through Machine Learning Algorithms in Open-Source Technologies","Web application security depends on reliable defenses as cyberattacks continue to grow in volume and sophistication. Web application firewalls (WAFs) provide an application-layer inspection of HTTP(S) traffic, but conventional regular-expression filtering struggles with zero-day vulnerabilities, replay attacks, payload variations, and ongoing maintenance as applications evolve. The work proposes an open-source Shadow Daemon approach that integrates a machine learning module to detect malicious requests. The solution enhances detection effectiveness while keeping latency within limits suitable for interactive user experiences.","Wiley  \nSecurity and Communication Networks Volume 2025, Article ID 6021296, 13 pages [https://doi.org/10.1155/sec/6021296](https://doi.org/10.1155/sec/6021296)  \nResearch Article  \nImproving WAF Detection Capabilities Through Machine Learning Algorithms in Open-Source Technologies  \nJavier Otero-Mosquera , 1 Cristina Lpez-Bravo , 1 Pedro Tub´ıo-Figueira ,2 and Alejandro Ignacio Garc´ıa de la Iglesia2  \n1 atlanTTic Research Center, Universidade de Vigo, Vigo, Spain  \n2 Information Technologies Group, Universidade de Vigo, Vigo, Spain  \nCorrespondence should be addressed to Cristina Lo´pez-Bravo; [clbravo@gti.uvigo.es](clbravo@gti.uvigo.es)  \nReceived 2 October 2023; Revised 24 October 2023; Accepted 1 November 2025  \nAcademic Editor: Arnab Biswas  \nCopyright © 2025 Javier Otero-Mosquera et al. Security and Communication Networks published by John Wiley & Sons Ltd. 2isis an open access article under the terms of the Creative Commons Attribution License, which permits use, distribution and reproduction in any medium, provided the original work is properly cited.  \n2e number of companies oﬀering their services online has grown enormously in recent years. Customer conﬁdence in these web applications is, therefore, vital. However, the number of attacks on these sites has also multiplied exponentially, requiring the use of new tools to prevent and defend against them. In this scenario, web application ﬁrewalls (WAFs) are emerging as one of the main defenses against website attacks. 2eir goal is to block those requests that could be considered malicious. Most WAFs are based on ﬁltering requests using regular expressions; nevertheless, this approach has many diﬃculties in dealing with issues such as detecting zero-day vulnerabilities or replay attacks and requires frequent and exhaustive updates. 2anks to advances in machine learning techniques, it is now possible to simplify the update process and combine manually conﬁgured rules with learned rules. In this work, we present a solution for the open-source WAF Shadow Daemon that incorporates a machine learning module for attack detection. 2e proposed solution improves the detection capability of Shadow Daemon while keeping the latency of the detection process within limits that allow for pleasant interaction with users.  \nKeywords: machine learning; MLP; n-grams; OWASP; Shadow Daemon cybersecurity; SVM; WAF  \n1. Introduction  \nOver the last decade, an increasing number of businesses (clothing stores, banking, ticketing, vacation booking, social networking, etc.) have used their websites as the main channel of interaction with their customers. Asa result, trust in these sites has become critical to maintaining customer privacy and satisfaction, as well as company proﬁts. However, web applications are not always as reliable and secure as expected, for various reasons. To name a few, these can be led by bugs in the application’s code, poor input data validation, insecure session management, lack of software updates in legacy applications, or the use of vulnerable third-party libraries [1, 2], among others. In either case, attackers can exploit these vulnerabilities to obtain sensitive data (such as  \ncredentials that provide access to bank accounts), to sell conﬁdential information, or simply to trigger a denial-ofservice attack that might quickly cause ﬁnancial and reputational losses. As an example, according to the 2022 Verizon Data Breach Investigations Report [3], web application hacking is the most prevalent attack vector, accounting for nearly 47% of enterprise attacks.  \nWeb application ﬁrewalls (WAFs) have been designed to add an extra layer of security in these scenarios, becoming one of the primary defense mechanisms for protecting web applications [4, 5] . WAFs perform an application-layer inspection of [HTTP](HTTP)(S) traﬃc between clients and servers, blocking requests if they are found to be malicious. By analyzing transmitted data, WAFs can identify potential attacks, even","cbCaifRCqAT4MvCk","https://ap.wps.com/l/cbCaifRCqAT4MvCk","pdf",1297929,1,13,"English","en",105,"# Introduction\n# Web Application Firewalls and Limitations\n# Proposed Solution: Machine Learning for Shadow Daemon\n# Methodology and Evaluation\n# Results and Discussion\n# Conclusion","[{\"question\":\"Why do traditional WAFs based on regular expressions struggle to detect modern attacks?\",\"answer\":\"They struggle with zero-day vulnerabilities, replay attacks across multiple requests, payload changes that bypass matching, and the constant need to update rules as applications evolve.\"},{\"question\":\"What open-source component does the paper improve using machine learning?\",\"answer\":\"The paper presents an approach for the open-source WAF Shadow Daemon by incorporating a machine learning module for attack detection.\"},{\"question\":\"How does the proposed solution balance detection quality and user experience?\",\"answer\":\"It improves Shadow Daemon’s detection capability while keeping detection latency within bounds that allow pleasant interaction for users.\"}]","Improving WAF Detection Capabilities Through Machine Learning Algorithms in Open-Source Technologies | PDF",1785822483,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"improving-waf-detection-capabilities-through-machine-learning-algorithms-in-open-source-technologies","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/improving-waf-detection-capabilities-through-machine-learning-algorithms-in-open-source-technologies/124465/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do traditional WAFs based on regular expressions struggle to detect modern attacks?","Question",{"text":75,"@type":76},"They struggle with zero-day vulnerabilities, replay attacks across multiple requests, payload changes that bypass matching, and the constant need to update rules as applications evolve.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What open-source component does the paper improve using machine learning?",{"text":80,"@type":76},"The paper presents an approach for the open-source WAF Shadow Daemon by incorporating a machine learning module for attack detection.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the proposed solution balance detection quality and user experience?",{"text":84,"@type":76},"It improves Shadow Daemon’s detection capability while keeping detection latency within bounds that allow pleasant interaction for users.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]