[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120456-en":3,"doc-seo-120456-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120456,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",6,"Technology","Web application firewall based on machine learning models","Web application security is increasingly critical as web applications store sensitive data and support financial transactions. The study designs a machine learning-based web application firewall to mitigate injection vulnerabilities, using a hybrid dataset that combines CISC 2010, HTTPParams 2015, and real-time HTTP requests. Five classifiers—k-nearest neighbors, logistic regression, naïve Bayes, support vector machine, and decision tree—are assessed for XSS, SQL Injection, OS Command Injection, and Local File Inclusion. The decision tree achieves the strongest precision, recall, F1-score, ROC, and AUC. Real-time testing yields an F1 score of 93.13% and accuracy of 93.27%. Future work expands coverage to additional attack types and evaluates on new datasets.","Submitted 6 December 2024 Accepted 29 May 2025  \nPublished 16 July 2025  \nCorresponding author Muhammed Ersin Durmus􀀋 kaya, [m.durmuskaya@iku.edu.tr](m.durmuskaya@iku.edu.tr)  \nAcademic editor Davide Chicco  \nAdditional Information and Declarations can be found on page 27  \nDOI 10.7717/peerj-cs.2975  \n Copyright  \n2025 Durmus􀀋 kaya and Bayrakl􀀙  \nDistributed under  \nCreative Commons CC-BY 4.0  \nOPEN ACCESS  \nWeb application firewall based on machine learning models  \nMuhammed Ersin Durmus􀀋 kaya1 and Selim Bayrakl􀀙2  \n1 Department of Computer Engineering, Istanbul Kultur University, Istanbul, Turkey  \n2 Department of Computer Engineering, Turkish Air Force Academy, National Defence University, Istanbul, Turkey  \nABSTRACT  \nThe increasing reliance on web applications for storing sensitive data and financial transactions has elevated the importance of web application security. A machine learning-based web application firewall was designed to protect web applications against injection vulnerabilities. A hybrid dataset, including CISC 2010, [HTTPParams](HTTPParams) 2015, and real-time Hypertext Transfer Protocol ([HTTP](HTTP)) requests, was employed. The study evaluated five classification algorithms􀀖K-nearest neighbors, logistic regression, naïve Bayes, support vector machine, and decision tree􀀖for detecting cross site scripting (XSS), Structured Query Language (SQL) Injection, Operating System Command Injection, and Local File Inclusion attacks. Decision tree was identified as the algorithm with the highest precision, accuracy, recall, F1-score, receiver operating characteristic (ROC), and area under the curve (AUC) values. According to the confusion matrix analysis, the real-time tested web application firewalls (WAF) achieved a remarkably high F1 score of 93.13% and accuracy of 93.27% . The findings indicate that machine learning-based WAFs effectively protect web applications against injection threats. Future work includes expanding the WAF to cover other attack types and testing it on different datasets.  \nSubjects Algorithms and Analysis of Algorithms, Data Mining and Machine Learning, Security and Privacy, Neural Networks  \nKeywords Web application firewall, Machine learning, Classification, Web security, WAF, Injection  \nINTRODUCTION  \nIn the field of cybersecurity, intrusion detection systems (IDS) and intrusion prevention systems (IPS) function as critical safeguards against unauthorized network traffic. These systems, implemented as hardware or software, continuously monitor network traffic. Upon detecting potential security threats, they promptly notify the network administrator, enabling timely intervention (Hock & Kortis, 2015) . Web application firewalls (WAFs) emerged as a specialized form of IDS/IPS designed to address the specificities of the Hypertext Transfer Protocol ([HTTP](HTTP)) and the associated attack landscape. Typically, WAFs rely on intricate rule sets, often employing regular expressions, to identify and mitigate a wide range of known input and output validation attacks targeting web applications (Luptk, 2011) .  \nThe Open Worldwide Application Security Project (OWASP) Top 10 is a widely recognized reference in web application security. It is a collaborative effort that identifies  \nHow to cite this article Durmus􀀋 kaya ME, Bayrakl􀀙 S. 2025. Web application firewall based on machine learning models. PeerJ Comput. Sci. 11:e2975 [http://doi.org/10.7717/peerj-cs.2975](http://doi.org/10.7717/peerj-cs.2975)  \nthe most significant security weaknesses impacting web applications, offering a consensusdriven compilation aimed at enhancing awareness among professionals in the field. Organizations are strongly encouraged to adopt the OWASP Top 10 and initiate a process of mitigating these risks within their web applications. Implementing OWASP Top 10 recommendations helps establish a security-focused software development culture, resulting in more secure code (Ghanbari et al., 2015) .  \nCross-site scripting (XSS","cbCaii14Uwv4snEB","https://ap.wps.com/l/cbCaii14Uwv4snEB","pdf",6172743,1,30,"English","en",105,"# Abstract\n# Introduction\n## IDS/IPS and the role of WAF\n## OWASP Top 10 and injection categories\n## Attack types addressed (XSS, SQLi, OS Command, LFI)\n## WAF detection approaches and deployment strategies","[{\"question\":\"What problem does the proposed system address?\",\"answer\":\"It addresses web application injection vulnerabilities that can arise from threats such as XSS, SQL injection, OS command injection, and local file inclusion, by using a machine learning-based web application firewall.\"},{\"question\":\"Which dataset and evaluation approach are used?\",\"answer\":\"The system uses a hybrid dataset combining CISC 2010, HTTPParams 2015, and real-time HTTP requests, and evaluates five classification algorithms using detection metrics including F1-score and ROC/AUC.\"},{\"question\":\"Why does the decision tree model perform best in the study?\",\"answer\":\"The decision tree is identified as the top performer, achieving the highest precision, accuracy, recall, F1-score, ROC, and AUC, and it produces strong confusion-matrix results in real-time testing.\"}]","Web application firewall based on machine learning models | PDF",1785730200,76,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"web-application-firewall-based-on-machine-learning-models","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/technology/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/web-application-firewall-based-on-machine-learning-models/120456/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04","2026-08-03",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the proposed system address?","Question",{"text":76,"@type":77},"It addresses web application injection vulnerabilities that can arise from threats such as XSS, SQL injection, OS command injection, and local file inclusion, by using a machine learning-based web application firewall.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"Which dataset and evaluation approach are used?",{"text":81,"@type":77},"The system uses a hybrid dataset combining CISC 2010, HTTPParams 2015, and real-time HTTP requests, and evaluates five classification algorithms using detection metrics including F1-score and ROC/AUC.",{"name":83,"@type":74,"acceptedAnswer":84},"Why does the decision tree model perform best in the study?",{"text":85,"@type":77},"The decision tree is identified as the top performer, achieving the highest precision, accuracy, recall, F1-score, ROC, and AUC, and it produces strong confusion-matrix results in real-time testing.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,114,119,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":112,"slug":113},50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":21,"slug":122},8,"Research & Report","research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]