Evaluation Framework for False Positives in Open-Source WAFs Based on OWASP CRS Paranoia Levels: A Systematic Approach for Comparative Measurement †


Abstract:

This work presents a systematic and modular framework to evaluate the detection of false positives (FPs) in open-source Web Application Firewalls (WAFs), implementing the OWASP Core Rule Set (CRS) and considering four different paranoia levels (PL1–PL4). The experimental design includes controlled generation of legitimate traffic, sequential application of sensitivity levels, monitoring of WAF behavior, and statistical analysis of FP rates. As a proof of concept, a virtualized laboratory environment is implemented using ModSecurity 2.9 and OWASP CRS 3.3.7 as a reverse proxy, applying 30 groups of progressively increasing legitimate requests, each carried out 20 times per paranoia level. The results show that PL1 does not generate FPs, while PL2, PL3, and PL4 progressively increase the FP rate, although no statistically significant differences are found among them. The proposed framework provides a foundation for comparative quantitative evaluations across multiple WAF solutions and deployment scenarios, supporting informed decisions prior to production environment implementation.

Año de publicación:

2025

Keywords:

  • False positives
  • ModSecurity
  • OWASP CRS
  • paranoia levels
  • WAF

Fuente:

scopusscopus

Tipo de documento:

Article

Estado:

Acceso restringido

Áreas de conocimiento:

  • Software de código abierto
  • Software
  • Tecnologías de la información y la comunicación

Áreas temáticas de Dewey:

  • Programación informática, programas, datos, seguridad
  • Ciencias de la computación
  • Métodos informáticos especiales
Procesado con IAProcesado con IA

Objetivos de Desarrollo Sostenible:

  • ODS 12: Producción y consumo responsables
  • ODS 7: Energía asequible y no contaminante
  • ODS 9: Industria, innovación e infraestructura
Procesado con IAProcesado con IA