UGC Approved Journal no 63975(19)
New UGC Peer-Reviewed Rules

ISSN: 2349-5162 | ESTD Year : 2014
Volume 13 | Issue 9 | September 2026

JETIREXPLORE- Search Thousands of research papers



WhatsApp Contact
Click Here

Published in:

Volume 13 Issue 9
September-2026
eISSN: 2349-5162

UGC and ISSN approved 7.95 impact factor UGC Approved Journal no 63975

7.95 impact factor calculated by Google scholar

Unique Identifier

Published Paper ID:
JETIR2609289


Registration ID:
586311

Page Number

c812-c817

Share This Article


Jetir RMS

Title

WAF Rule Development and Experimental Evaluation for Detecting and Blocking Web- Based Attacks

Abstract

Web applications are frequently exposed to security threats such as SQL injection, Cross-Site Scripting (XSS), command injection, path traversal, iframe injection, and other malicious HTTP requests. Web Application Firewalls (WAFs) provide an additional security layer by inspecting incoming requests and identifying patterns associated with known web-based attacks. However, effective WAF protection depends significantly on the quality and coverage of its security rules. This research presents the development and experimental evaluation of a rule-based Web Application Firewall using Mod Security integrated with the OWASP Core Rule Set (CRS) and a set of customized security rules. The proposed system is designed to inspect HTTP requests, detect predefined attack patterns, block malicious requests, and record security events for further analysis. Custom rules were developed to detect specific attack categories, including JavaScript protocol attacks, iframe injection, command injection, path traversal, and sensitive file access, while OWASP CRS rules were used to identify common attacks such as SQL injection and Cross-Site Scripting. An experimental web application was developed to generate both legitimate and malicious requests for evaluating the behaviour of the implemented rules. The detected events were logged and processed to provide information such as attack type, rule identifier, severity, attack category, request URL, payload, and blocking status. The experimental evaluation demonstrates how customized rule development can complement standard WAF rules and provide a practical approach for detecting and blocking different web-based attacks. The study also highlights the importance of rule testing, logging, and analysis in improving the effectiveness of WAF-based web application protection.

Key Words

Web Application Firewall, ModSecurity, OWASP Core Rule Set, WAF Rule Development, Web Attack Detection, SQL Injection, Cross-Site Scripting, Command Injection, WAF Evasion, Web Application Security.

Cite This Article

"WAF Rule Development and Experimental Evaluation for Detecting and Blocking Web- Based Attacks", International Journal of Emerging Technologies and Innovative Research (www.jetir.org), ISSN:2349-5162, Vol.13, Issue 9, page no.c812-c817, September-2026, Available :http://www.jetir.org/papers/JETIR2609289.pdf

ISSN


2349-5162 | Impact Factor 7.95 Calculate by Google Scholar

An International Scholarly Open Access Journal, Peer-Reviewed, Refereed Journal Impact Factor 7.95 Calculate by Google Scholar and Semantic Scholar | AI-Powered Research Tool, Multidisciplinary, Monthly, Multilanguage Journal Indexing in All Major Database & Metadata, Citation Generator

Cite This Article

"WAF Rule Development and Experimental Evaluation for Detecting and Blocking Web- Based Attacks", International Journal of Emerging Technologies and Innovative Research (www.jetir.org | UGC and issn Approved), ISSN:2349-5162, Vol.13, Issue 9, page no. ppc812-c817, September-2026, Available at : http://www.jetir.org/papers/JETIR2609289.pdf

Publication Details

Published Paper ID: JETIR2609289
Registration ID: 586311
Published In: Volume 13 | Issue 9 | Year September-2026
DOI (Digital Object Identifier):
Page No: c812-c817
Country: Mumbai, Maharashtra, India .
Area: Science & Technology
ISSN Number: 2349-5162
Publisher: IJ Publication


Preview This Article


Downlaod

Click here for Article Preview

Download PDF

Downloads

0005

Print This Page

Current Call For Paper

Jetir RMS