Optimizing HTTP Traffic Classification in Web Application Firewalls: A Comparative Analysis of Random Forest and SVM
Cristian Chindruş, Constantin F. Caruntu · 2025
Web applications play a vital role in modern business but are increasingly exposed to cyber threats such as cross-site scripting (XSS), SQL injection, and distributed denial-of-service (DDoS) attacks, which can cause significant financial and reputational damage. As a response to these threats, Web Application Firewalls (WAFs) serve as a critical defense by filtering, monitoring, and blocking malicious HTTP traffic, though traditional, rule-based approaches struggle with novel or zero-day attacks. With the increasing complexity and volume of web-based threats, effective WAF solutions require more advanced techniques for anomaly detection. To address this, machine learning (ML) techniques are being adopted to enhance WAF capabilities by dynamically learning and adapting to evolving threats. Thus, this study explores the application of ML methods, specifically Random Forest (RF) and Support Vector Machine (SVM), to classify HTTP traffic for the detection of web-based attacks. Their performance was evaluated to provide valuable insights into the suitability of classical ML algorithms for WAF applications and to set the foundation for exploring more advanced models in future work regarding cybersecurity.