An empirical study on the evaluation and enhancement of OWASP CRS (Core Rule Set) in ModSecurity

M K Anuvarshini, Kommuri Sai Suhitha Bala, Sri Sai Tanvi Sonti, K. P. Jevitha · Computers & Security · 2025

The effectiveness of a Web Application Firewall is determined by their ability to accurately detect and block malicious payloads while allowing legitimate traffic without any interference. This research evaluates the effectiveness of the popular open-source OWASP CRS (Core Rule Set) with the ModSecurity web application firewall. The study analyzes the impact on performance metrics under different configurations of the OWASP CRS. This study also aims to evaluate the detection capabilities of the WAF in its strict configuration to uncover gaps in the existing rule coverage. The identified gaps were then improved through the creation of 146 new custom rules that were designed to recognize attack payloads that managed to evade all rules in the OWASP CRS. The implemented custom rules, which were developed in accordance with the gaps identified during the test, improved the detection precision from 60.54% to 97.46% with no increase in false positives within our controlled test environment, thereby incrementally strengthening the security of the rule set by detecting threats that had previously escaped notice.

Read the paper · More papers on PaperTik