Web Application Protection Optimization Through Coraza WAF: Performance Assessment Against OWASP Risks in Reverse Proxy Configurations

Michael Curipallo Martínez, Alexander Guevara-Vega, Aldrin Reyes Narváez, Geovanny Raura, Hernán Barba Molina · 2025

This study presents an evaluation of Coraza Web Application Firewall (WAF) performance when integrated with two reverse proxy environments, Caddy and Envoy, which utilize the Open Web Application Security Project (OWASP) Core Rule Set version 4.15.0. This research is motivated by the increasing need for lightweight, open-source WAF solutions that offer reliable protection against OWASP Top-Ten vulnerabilities while maintaining low false positive rates. A virtual testing laboratory is implemented using vulnerable web servers and a secure HTTPS application to simulate both attack and legitimate traffic. The analysis is conducted in two phases: detection of attack vectors across the ten OWASP categories and measurement of false positives generated under legitimate traffic at four CRS-defined sensitivity levels (Paranoia Levels PL1–PL4). Results indicate that while both proxies successfully block malicious traffic, false positive rates vary significantly depending on the proxy and paranoia level. Envoy exhibited better precision at PL2 and PL3, whereas Caddy outperformed Envoy in maintaining stability at PL4. Statistical analysis using Levene’s test and Welch’s t-test confirmed these differences as significant. The findings highlight the importance of proxy-specific characteristics in WAF performance and provide guidance for selecting optimal deployment configurations for Coraza WAF in security-sensitive environments.

Read the paper · More papers on PaperTik