Real-time Web Application Firewall Monitoring uses the OWASP CRS Framework
Irfan Darmawan, Afan Nuridwan, Alam Rahmatulloh, Rohmat Gunawan, Randi Rizal · 2024
Security of communication between users and web applications is critical due to the confidential nature of the data involved. This research implements a Web Application Firewall (WAF) using ModSecurity, enhanced with ModSecurity Log Collector (mloge), to improve application-layer security. The primary contribution of this study is the development of an integrated real-time monitoring system that streamlines the process for security administrators by allowing them to easily monitor and respond to security events as they occur. Through penetration testing with SQL Injection, Cross-Site Scripting (XSS), Unlimited File Uploads, Remote File Inclusions, and Denial of Service (DoS) attacks, the WAF's effectiveness was evaluated. The system successfully blocked these attacks while logging each event in detail. The real-time monitoring system provided instant alerts and detailed reports, enabling administrators to track and respond to intrusion attempts with greater efficiency. This research distinguishes itself by integrating a real-time monitoring solution that not only visualizes WAF logs but also provides a complete record of attack patterns and vulnerabilities. This advancement significantly enhances the ability of administrators to detect, analyze, and mitigate security threats in real-time, offering a practical solution for strengthening web application security management.