arrow
Return

ModSec-AdvLearn: Countering Adversarial SQL Injections With Robust Machine Learning

delete2025-01-01
delete0
PRE
AI
G
Giuseppe Floris
C
Christian Scano
B
Biagio Montaruli
L
Luca Demetrio
A
Andrea Valenza
L
Luca Compagna
D
Davide Ariu
L
Luca Piras
D
Davide Balzarotti
B
Battista Biggio
DOI:10.1109/TIFS.2025.3583234delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Many Web Application Firewalls (WAFs) leverage the OWASP Core Rule Set (CRS) to block incoming malicious requests. The CRS consists of different sets of rules designed by domain experts to detect well-known web attack patterns. Both the set of rules and the weights used to combine them are manually defined, yielding four different default configurations of the CRS. In this work, we focus on the detection of SQL injection (SQLi) attacks, and show that the manual configurations of the CRS typically yield a suboptimal trade-off between detection and false alarm rates. Furthermore, we show that these configurations are not robust to adversarial SQLi attacks, i.e., carefully-crafted attacks that iteratively refine the malicious SQLi payload by querying the target WAF to bypass detection. To overcome these limitations, we propose (i) using machine learning to automate the selection of the set of rules to be combined along with their weights, i.e., customizing the CRS configuration based on the monitored web services; and (ii) leveraging adversarial training to significantly improve its robustness to adversarial SQLi manipulations. Our experiments, conducted using the well-known open-source ModSecurity WAF equipped with the CRS rules, show that our approach, named ModSec-AdvLearn, can (i) increase the detection rate up to 30%, while retaining negligible false alarm rates and discarding up to 50% of the CRS rules; and (ii) improve robustness against adversarial SQLi attacks up to 85%, marking a significant stride toward designing more effective and robust WAFs. We release our open-source code at <uri xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">https://github.com/pralab/modsec-advlearn</uri>
Keywords:
Web application firewalls
machine learning
SQL injection
adversarial training

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

D
department of digital security
Scholars:
2
Papers: 1
Citations: 0
P
pluribus one, cagliari, italy
Scholars:
2
Papers: 1
Citations: 0
P
prima assicurazioni, milano, italy
Scholars:
1
Papers: 1
Citations: 0
U
University of Genova
Scholars:
580
Papers: 256
Citations: 0
E
endor labs
Scholars:
1
Papers: 1
Citations: 0
U
university of cagliari
Scholars:
1.2W
Papers: 9.7K
Citations: 9
researcher View more organizations