Electronics· 2026Q2
Character-Level NLP and 1D-CNN-Based Decision Support for Web Application Firewalls
- 0citations
- Q2SCImago
- 2026year
Short summary
A new Web Application Firewall (WAF) decision-support framework uses character-level HTTP request representation and a 1D-CNN to generate an uncalibrated attack score, allowing flexible threshold adjustment without retraining.
AI-generated from the title and abstract; the full text is not read.
Key points
- A WAF decision-support framework combines character-level HTTP request representation with a 1D-CNN.
- The model produces an uncalibrated attack score, allowing threshold adjustment without retraining.
- Group-disjoint F1-scores achieved were 0.8590 ± 0.1079 on CSIC 2010 and 0.9912 ± 0.0005 on SR-BH 2020.
- The framework prioritizes reproducible evaluation and operational threshold analysis over substantial accuracy improvements.
AI-generated from the title and abstract; the full text is not read.
Abstract
Rule- and signature-based Web Application Firewalls (WAFs) may struggle with evolving malicious requests. This study presents a WAF decision-support framework that combines character-level HTTP request representation with a one-dimensional convolutional neural network (1D-CNN). The sigmoid output is treated as an uncalibrated attack score, which allows threshold adjustment without retraining. Across five seeds, each run evaluates 999 validation thresholds ranging from 0.001 to 0.999. The threshold that maximizes validation F1-score is locked before the corresponding held-out test evaluation. Cross-seed one-standard-error analysis is used only to characterize threshold stability. It is not interpreted as a confidence interval for the optimal threshold. Evaluation on CSIC 2010 and SR-BH 2020 includes baseline comparisons, request-length sensitivity analysis, model-only CPU runtime characterization, and normalized-prefix group-disjoint testing. Group-disjoint F1-scores were 0.8590 ± 0.1079 and 0.9912 ± 0.0005, respectively. CSIC 2010 showed greater variability and performance degradation relative to random splitting, indicating sensitivity to group composition. Under matched random splits, the 1D-CNN achieved higher mean F1-scores than Character-MLP and Char TF-IDF + LR. However, the improvement over the competitive TF-IDF baseline was modest. The baseline models were not evaluated under group-disjoint partitions. The principal contribution is therefore a reproducible evaluation framework and operational threshold analysis rather than substantial gains in detection accuracy.
The authors' abstract, as published at the source. Electronics, 2026 · DOI ↗
Continue with a free account
Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.
Continue free on the webSign in with Google or Apple; no card needed. You come back to this paper.
On your phone:
Field: Hardware and Architecture
Hardware and ArchitectureComputer Science