A Python-based web application firewall for SQLi protection in heterogeneous web server environments
Abstract
Structured query language injection (SQLi) remains one of the most critical threats to web applications. Conventional web application firewall (WAF) such as ModSecurity provide protection but face limitations in heterogeneous environments and often require additional configurations on web servers. This issue is problematic because adding new configurations demands considerable effort and may disrupt stable services. To address this challenge, this research proposes PyWAF, a Python-based WAF developed as a reverse proxy that offers flexible protection across heterogeneous web servers against SQLi attacks. PyWAF employs a weighted core rule set (CRS) with a scoring mechanism and gate flags to detect various SQLi patterns. The proposed method was evaluated in compatibility testing and reliability testing across three popular web server environments namely Apache, Nginx, and OpenLiteSpeed. The reliability evaluation utilized 30 SQLi payloads across three different scenarios, namely GET, POST, and API payload. The results of compatibility test show that the proposed method achieved seamless integration with all web servers without requiring additional server configuration. In term of reliability, PyWAF successfully blocked 100% of SQLi attacks, while ModSecurity blocked 88.9%, demonstrating an improvement of 11.1% in SQLi detection capability.
Keywords
Structured query language injection; Web application firewall; Web environments; Web security; Web server
Full Text:
PDFDOI: https://doi.org/10.11591/eei.v15i5.11638
Refbacks
- There are currently no refbacks.

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Bulletin of Electrical Engineering and Informatics (BEEI)
ISSN: 2089-3191
,
e-ISSN: 2302-9285
This journal is published by the
Institute of Advanced Engineering and Science (IAES)
.