[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122052-en":3,"doc-seo-122052-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122052,8796095462418,"Noah","https://ap-avatar.wpscdn.com/avatar/80000253c1241d02b47?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778826106357471780",6,"Technology","ModSec-Learn - Boosting ModSecurity with Machine Learning","ModSec-Learn addresses limitations of ModSecurity’s signature-weighting strategy for detecting SQL injection and other web attacks. ModSecurity matches requests against the OWASP Core Rule Set (CRS) and blocks when summed heuristic rule severities exceed a threshold, without adapting to application-specific traffic. ModSec-Learn replaces fixed severities with machine-learned rule weights using CRS rules as input features, tuning contributions to improve detection versus false positives. Experiments show a substantially better detection trade-off, and sparse regularization removes over 30% of CRS rules at inference.","arXiv :2406 . 13547v1 [ cs .LG] 19 Jun 2024  \nModSec-Learn: Boosting ModSecurity with Machine Learning  \nChristian Scano 1 ,2, Giuseppe Floris2, Biagio Montaruli3 ,6, Luca Demetrio4, Andrea Valenza5, Luca Compagna3, Davide Ariu2,  \nLuca Piras2, Davide Balzarotti6, and Battista Biggio 1 ,2  \n1 University of Cagliari, Cagliari, Italy  \n{battista.biggio,[giuseppe.floris}@unica.it](giuseppe.floris}@unica.it)  \n2 Pluribus One, Cagliari, Italy  \n{davide.ariu,[luca.piras}@pluribus-one.it](luca.piras}@pluribus-one.it)  \n3 SAP Security Research, Mougins, France  \n{biagio.montaruli,luca .compagna}@sap.com  \n4 University of Genova, Genova, Italy  \n[luca.demetrio@unige.it](luca.demetrio@unige.it)  \n5 Prima Assicurazioni, Milano, Italy  \n[andrea.valenza@prima.it](andrea.valenza@prima.it)  \n6 EURECOM, Biot, France  \n[davide.balzarotti@eurecom.fr](davide.balzarotti@eurecom.fr)  \nAbstract. ModSecurity is widely recognized as the standard open-source Web Application Firewall (WAF), maintained by the OWASP Foundation. It detects malicious requests by matching them against the Core Rule Set (CRS), identifying well-known attack patterns. Each rule is manually assigned a weight based on the severity of the corresponding attack, and a request is blocked if the sum of the weights of matched rules exceeds a given threshold. However, we argue that this strategy is largely ineffective against web attacks, as detection is only based on heuristics and not customized on the application to protect. In this work, we overcome this issue by proposing a machine-learning model that uses the CRS rules as input features. Through training, ModSec-Learn is able to tune the contribution of each CRS rule to predictions, thus adapting the severity level to the web applications to protect. Our experiments show that ModSec-Learn achieves a significantly better trade-off between detection and false positive rates. Finally, we analyze how sparse regularization can reduce the number of rules that are relevant at inference time, by discarding more than 30% of the CRS rules. We release our open-source code and the dataset at [https://github.com/pralab/modsec-learn](https://github.com/pralab/modsec-learn) and  \n[https://github.com/pralab/http-traffic-dataset](https://github.com/pralab/http-traffic-dataset), respectively.  \nKeywords: Web Application Firewalls · Machine Learning · Web Security · SQL injection · OWASP ModSecurity Core Rule Set  \n2 C. Scano et al.  \n1 Introduction  \nWeb applications are constantly evolving and deployed at a broad scale to offera plethora or variegated services, imposing serious challenges in securing them against an increasing number of attacks [12]. Among these, SQL injection (SQLi) consists of injecting a malicious SQL code payload inside regular queries, causing the target web application to either behave in an unintended way or expose sensitive data. Even if countermeasures to this attack are well known [1, 13 , 14], the Open Web Application Security Project (OWASP) Foundation still classifies SQLi as one of the top-10 most dangerous web threats [16] . Thus, Web Application Firewalls (WAFs) are commonly used as a defense tool in enterprise systems [3, 1] to counter such attacks and protect web applications. They work by filtering the incoming requests directed towards the web applications and blocking suspicious connections. In this work, we focus on ModSecurity [11], an established open-source WAF solution that builds its defense on top of signatures of well-known attacks, collected by the OWASP Foundation and known asthe Core Rule Set (CRS) . The CRS version used in this work (4.0.0) includes 319 rules, out of which 170 target critical injection attacks [17] . Specifically, SQLiis the most represented class of injection attack counting 60 rules. All rules areassigned with an heuristic severity level used to evaluate whether an [HTTP re](HTTP re)quest is malicious or not. Thus, detection is achieved through the summation of the scores of mat","cbCairp1SPKkMNvs","https://ap.wps.com/l/cbCairp1SPKkMNvs","pdf",530906,1,11,"English","en",105,"# Abstract\n# Introduction\n# Background","[{\"question\":\"How does ModSecurity determine whether a request is malicious?\",\"answer\":\"ModSecurity matches each request against the OWASP CRS and assigns an (heuristic) severity to each rule. It blocks the request when the sum of severities of matched rules exceeds a threshold.\"},{\"question\":\"What problem does the paper identify with ModSecurity’s CRS-based detection?\",\"answer\":\"The paper argues the heuristic severities are not tailored to the specific application traffic, leading to weak effectiveness and high false-positive rates. It also notes possible rule redundancy and interference.\"},{\"question\":\"What is ModSec-Learn and how does it improve detection?\",\"answer\":\"ModSec-Learn is a machine-learning WAF that uses CRS rules as input features to learn rule weights. This adapts the effective severity of each CRS rule to the protected web application and improves the detection/false-positive trade-off.\"}]","ModSec-Learn - Boosting ModSecurity with Machine Learning | PDF",1785808577,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"modsec-learn-boosting-modsecurity-with-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/modsec-learn-boosting-modsecurity-with-machine-learning/122052/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"How does ModSecurity determine whether a request is malicious?","Question",{"text":75,"@type":76},"ModSecurity matches each request against the OWASP CRS and assigns an (heuristic) severity to each rule. It blocks the request when the sum of severities of matched rules exceeds a threshold.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What problem does the paper identify with ModSecurity’s CRS-based detection?",{"text":80,"@type":76},"The paper argues the heuristic severities are not tailored to the specific application traffic, leading to weak effectiveness and high false-positive rates. It also notes possible rule redundancy and interference.",{"name":82,"@type":73,"acceptedAnswer":83},"What is ModSec-Learn and how does it improve detection?",{"text":84,"@type":76},"ModSec-Learn is a machine-learning WAF that uses CRS rules as input features to learn rule weights. This adapts the effective severity of each CRS rule to the protected web application and improves the detection/false-positive trade-off.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,113,118,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":111,"slug":112},50,"technology",{"id":114,"doc_module":4,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},7,"Healthcare",40,"healthcare",{"id":119,"doc_module":4,"doc_module_name":46,"category_name":120,"show_sort_weight":121,"slug":122},8,"Research & Report",30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]