cs.LGJun 19, 2024

ModSec-Learn: Boosting ModSecurity with Machine Learning

Authors: Christian Scano, Giuseppe Floris, Biagio Montaruli, Luca Demetrio, Andrea Valenza, Luca Compagna, Davide Ariu, Luca Piras, +2 more

Organizations: University of Cagliari, Cagliari, Italy · Pluribus One, Cagliari, Italy · SAP Security Research, Mougins, France · EURECOM, Biot, France · University of Genova, Genova, Italy · Prima Assicurazioni, Milano, Italy

Abstract

ModSecurity is widely recognized as the standard open-source Web Application Firewall (WAF), maintained by the OWASP Foundation. It detects malicious requests by matching them against the Core Rule Set (CRS), identifying well-known attack patterns. Each rule is manually assigned a weight based on the severity of the corresponding attack, and a request is blocked if the sum of the weights of matched rules exceeds a given threshold. However, we argue that this strategy is largely ineffective against web attacks, as detection is only based on heuristics and not customized on the application to protect. In this work, we overcome this issue by proposing a machine-learning model that uses the CRS rules as input features. Through training, ModSec-Learn is able to tune the contribution of each CRS rule to predictions, thus adapting the severity level to the web applications to protect. Our experiments show that ModSec-Learn achieves a significantly better trade-off between detection and false positive rates. Finally, we analyze how sparse regularization can reduce the number of rules that are relevant at inference time, by discarding more than 30% of the CRS rules. We release our open-source code and the dataset at https://github.com/pralab/modsec-learn and https://github.com/pralab/http-traffic-dataset, respectively.

Figures & tables

Explore similar work

CardsList
  1. Context-Aware Web Attack Detection in Open-Source SIEM Systems via MITRE ATT&CK-Enriched Behavioral Profiling

    May 13, 2026Badr Alboushy, Assef Jafar, Mohamad Aljnidi +2Threat DetectionIncident Response

  2. Robust and Explainable Divide-and-Conquer Learning for Intrusion Detection

    May 3, 2026Yan Zhou, Kevin Hamlen, Michael De Lucia +5Intrusion DetectionUnsupervised Detection

  3. Evaluating LLMs for Real-World Web Vulnerability Detection

    Jun 19, 2026Sebastian Neef, Luca Jungnickel, Antonio Benjamin Buchholz +2Model VulnerabilitiesAttacker Large Language Model