Evaluation Framework for False Positives in Open-Source WAFs Based on OWASP CRS Paranoia Levels: A Systematic Approach for Comparative Measurement †
Abstract:
This work presents a systematic and modular framework to evaluate the detection of false positives (FPs) in open-source Web Application Firewalls (WAFs), implementing the OWASP Core Rule Set (CRS) and considering four different paranoia levels (PL1–PL4). The experimental design includes controlled generation of legitimate traffic, sequential application of sensitivity levels, monitoring of WAF behavior, and statistical analysis of FP rates. As a proof of concept, a virtualized laboratory environment is implemented using ModSecurity 2.9 and OWASP CRS 3.3.7 as a reverse proxy, applying 30 groups of progressively increasing legitimate requests, each carried out 20 times per paranoia level. The results show that PL1 does not generate FPs, while PL2, PL3, and PL4 progressively increase the FP rate, although no statistically significant differences are found among them. The proposed framework provides a foundation for comparative quantitative evaluations across multiple WAF solutions and deployment scenarios, supporting informed decisions prior to production environment implementation.
Año de publicación:
2025
Keywords:
- False positives
- ModSecurity
- OWASP CRS
- paranoia levels
- WAF
Fuente:
scopusTipo de documento:
Article
Estado:
Acceso restringido
Áreas de conocimiento:
- Software de código abierto
- Software
- Tecnologías de la información y la comunicación
Áreas temáticas de Dewey:
- Programación informática, programas, datos, seguridad
- Ciencias de la computación
- Métodos informáticos especiales
Objetivos de Desarrollo Sostenible:
- ODS 12: Producción y consumo responsables
- ODS 7: Energía asequible y no contaminante
- ODS 9: Industria, innovación e infraestructura