AutoEx: A Log-Driven Framework for Automated Exception Rule Generation in OWASP CRS-Based Web Application Firewalls

Aldrin Reyes Narváez, Michael Curipallo Martínez, Hernán Barba Molina · Electronics · 2026

Web Application Firewalls (WAFs) based on the OWASP Core Rule Set (CRS) are widely utilized to protect web applications; however, higher CRS paranoia levels, while improving attack coverage, often lead to a significant increase in false positives, thus creating substantial operational challenges. To address this issue, this article proposes AutoEx, a systematic framework for the automated generation of secure exclusion rules in CRS-based, rule-driven WAFs. The framework analyzes WAF audit logs and traces of legitimate traffic to identify recurring false-positive patterns and derive exception rules without disabling core detection mechanisms. AutoEx is evaluated across multiple CRS paranoia levels using controlled traffic scenarios, enabling a comparative assessment of its impact on false-positive reduction and detection effectiveness. The results demonstrate that false-positive rates decrease from 100% to mean residual values between 32% and 46% under scenarios involving simple input datasets and to below 2% when sufficiently representative datasets are utilized for exception generation. Additionally, the detection effectiveness remains at 100% when all intentionally introduced attack payloads are correctly identified and blocked, regardless of input dataset complexity or configured paranoia level. Furthermore, the processing latency before and after applying AutoEx is discussed. These findings show that log-driven automated exception rule generation can substantially improve the operational usability of CRS-based WAFs. The proposed framework provides a practical and scalable solution to support secure WAF tuning in complex web applications, reducing manual effort, and minimizing the risk of security degradation caused by overly permissive configurations.

Read the paper · More papers on PaperTik