A Thirty-Day Dataset of Malicious HTTP Requests Blocked by OWASP ModSecurity on a Production Web Server

We present a real-world dataset capturing thirty consecutive days of malicious HTTP traffic filtered and blocked by the OWASP ModSecurity Web Application Firewall (WAF) on a live production server. Each entry corresponds to a request that triggered one or more rules in the OWASP Core Rule Set (CRS),...

Celý popis

Uloženo v:
Podrobná bibliografie
Vydáno v:Data (Basel) Ročník 10; číslo 11; s. 186
Hlavní autoři: Lucz, Geza, Forstner, Bertalan
Médium: Journal Article
Jazyk:angličtina
Vydáno: Basel MDPI AG 01.11.2025
Témata:
ISSN:2306-5729, 2306-5729
On-line přístup:Získat plný text
Tagy: Přidat tag
Žádné tagy, Buďte první, kdo vytvoří štítek k tomuto záznamu!
Abstract We present a real-world dataset capturing thirty consecutive days of malicious HTTP traffic filtered and blocked by the OWASP ModSecurity Web Application Firewall (WAF) on a live production server. Each entry corresponds to a request that triggered one or more rules in the OWASP Core Rule Set (CRS), resulting in its inclusion in the audit log due to suspected exploitation attempts. The dataset includes attack categories such as SQL injection, cross-site scripting (XSS), local file inclusion, scanner probes, and various malformed or evasive input forms. The data has been carefully anonymized to protect sensitive information while preserving critical structural tags, including request method, URI, triggered rule IDs, request headers, and user-agent strings. This dataset provides a real-world resource for cybersecurity researchers, particularly those developing or evaluating intrusion detection systems (IDSs), WAF rule tuning strategies, anomaly detection algorithms, and adversarial machine learning models. The dataset also allows performance testing of threat prevention pipelines. By making this dataset publicly available, we aim to support reproducible research in web security, encourage benchmarking of detection techniques under real-world conditions, and contribute insight into the nature of contemporary web-based threats observed in an uncontrolled environment.
AbstractList We present a real-world dataset capturing thirty consecutive days of malicious HTTP traffic filtered and blocked by the OWASP ModSecurity Web Application Firewall (WAF) on a live production server. Each entry corresponds to a request that triggered one or more rules in the OWASP Core Rule Set (CRS), resulting in its inclusion in the audit log due to suspected exploitation attempts. The dataset includes attack categories such as SQL injection, cross-site scripting (XSS), local file inclusion, scanner probes, and various malformed or evasive input forms. The data has been carefully anonymized to protect sensitive information while preserving critical structural tags, including request method, URI, triggered rule IDs, request headers, and user-agent strings. This dataset provides a real-world resource for cybersecurity researchers, particularly those developing or evaluating intrusion detection systems (IDSs), WAF rule tuning strategies, anomaly detection algorithms, and adversarial machine learning models. The dataset also allows performance testing of threat prevention pipelines. By making this dataset publicly available, we aim to support reproducible research in web security, encourage benchmarking of detection techniques under real-world conditions, and contribute insight into the nature of contemporary web-based threats observed in an uncontrolled environment.
Audience Academic
Author Forstner, Bertalan
Lucz, Geza
Author_xml – sequence: 1
  givenname: Geza
  orcidid: 0000-0003-1760-468X
  surname: Lucz
  fullname: Lucz, Geza
– sequence: 2
  givenname: Bertalan
  orcidid: 0009-0003-6669-2660
  surname: Forstner
  fullname: Forstner, Bertalan
BookMark eNptkV9rFDEUxYNUsNa--QECvjo1_yfzuLZqCy1d3JU-hkxys2bdndRkRphvb9otWkESyM3l3F9yOK_R0ZAGQOgtJWecd-SDt6OlhNat1Qt0zDhRjWxZd_SsfoVOS9kSQhgTUjF9jDYLvP4e8zg3F3bGF5VRYMQp4Bu7iy6mqeDL9XqJv8LPCcpY8Mddcj_A437Gt3eL1RLfJL8CN-U4zjgN2OJlTn5yY6yXO-jxCvIvyG_Qy2B3BU6fzhP07fOn9fllc3375ep8cd04xpVqhPMyOKKJoyH0gvfCSio72inOOg_AwOlOBeV7L22rW956K3qorpVyUnh-gq4OXJ_s1tznuLd5NslG89hIeWNsHqPbgfGceRa0ZlJo4V2noSeiY7oXQddnZWW9O7Duc3p0b7ZpykP9vuGslZJ0XLG_qo2t0DiENGbr9rE4s9BKKkqYpFV19h9VXR720dUkQ6z9fwbeHwZcTqVkCH_MUGIeAjfPA-e_ATaQm9s
Cites_doi 10.1007/s10207-025-01072-6
10.1109/MilCIS.2015.7348942
10.1109/ACCESS.2023.3320928
10.1016/j.cose.2025.104510
10.1007/s10207-024-00914-z
10.2507/35th.daaam.proceedings.042
10.1145/3404868.3406664
10.3390/fi16070256
10.3390/info12070259
10.13052/jsn2445-9739.2017.009
10.1109/ISGTEUROPE56780.2023.10407262
ContentType Journal Article
Copyright COPYRIGHT 2025 MDPI AG
2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Copyright_xml – notice: COPYRIGHT 2025 MDPI AG
– notice: 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
DBID AAYXX
CITATION
8FE
8FG
ABUWG
AFKRA
ARAPS
AZQEC
BENPR
BGLVJ
CCPQU
DWQXO
HCIFZ
P5Z
P62
PHGZM
PHGZT
PIMPY
PKEHL
PQEST
PQGLB
PQQKQ
PQUKI
PRINS
DOA
DOI 10.3390/data10110186
DatabaseName CrossRef
ProQuest SciTech Collection
ProQuest Technology Collection
ProQuest Central (Alumni)
ProQuest Central UK/Ireland
Advanced Technologies & Computer Science Collection
ProQuest Central Essentials
ProQuest Central Database Suite (ProQuest)
ProQuest Technology Collection
ProQuest One
ProQuest Central Korea
SciTech Collection (ProQuest)
Advanced Technologies & Aerospace Database
ProQuest Advanced Technologies & Aerospace Collection
Proquest Central Premium
ProQuest One Academic (New)
Publicly Available Content Database
ProQuest One Academic Middle East (New)
ProQuest One Academic Eastern Edition (DO NOT USE)
ProQuest One Applied & Life Sciences
ProQuest One Academic (retired)
ProQuest One Academic UKI Edition
ProQuest Central China
DOAJ Directory of Open Access Journals
DatabaseTitle CrossRef
Publicly Available Content Database
Advanced Technologies & Aerospace Collection
Technology Collection
ProQuest One Academic Middle East (New)
ProQuest Advanced Technologies & Aerospace Collection
ProQuest Central Essentials
ProQuest One Academic Eastern Edition
ProQuest Central (Alumni Edition)
SciTech Premium Collection
ProQuest One Community College
ProQuest Technology Collection
ProQuest SciTech Collection
ProQuest Central China
ProQuest Central
Advanced Technologies & Aerospace Database
ProQuest One Applied & Life Sciences
ProQuest One Academic UKI Edition
ProQuest Central Korea
ProQuest Central (New)
ProQuest One Academic
ProQuest One Academic (New)
DatabaseTitleList

Publicly Available Content Database
CrossRef
Database_xml – sequence: 1
  dbid: DOA
  name: DOAJ Directory of Open Access Journals
  url: https://www.doaj.org/
  sourceTypes: Open Website
– sequence: 2
  dbid: PIMPY
  name: Publicly Available Content Database
  url: http://search.proquest.com/publiccontent
  sourceTypes: Aggregation Database
DeliveryMethod fulltext_linktorsrc
Discipline Sciences (General)
EISSN 2306-5729
ExternalDocumentID oai_doaj_org_article_d32d2f8825484dc98eb04928b4f84a55
A865610251
10_3390_data10110186
GroupedDBID 8FE
8FG
AADQD
AAYXX
ADBBV
ADMLS
AFFHD
AFKRA
AFZYC
ALMA_UNASSIGNED_HOLDINGS
ARAPS
ARCSS
BCNDV
BENPR
BGLVJ
CCPQU
CITATION
GROUPED_DOAJ
HCIFZ
IAO
ICD
ITC
MODMG
M~E
P62
PHGZM
PHGZT
PIMPY
PQGLB
PROAC
AGGLG
ABUWG
AZQEC
DWQXO
PKEHL
PQEST
PQQKQ
PQUKI
PRINS
ID FETCH-LOGICAL-c2366-4cd5fc080c1ffb43b4a5159196329dee2ec896f6dbd5a78737da4be11066c54d3
IEDL.DBID P5Z
ISSN 2306-5729
IngestDate Mon Dec 01 19:28:35 EST 2025
Thu Nov 27 00:14:15 EST 2025
Wed Dec 10 10:22:52 EST 2025
Tue Dec 02 03:53:28 EST 2025
Thu Nov 13 04:23:02 EST 2025
IsDoiOpenAccess true
IsOpenAccess true
IsPeerReviewed true
IsScholarly true
Issue 11
Language English
LinkModel DirectLink
MergedId FETCHMERGED-LOGICAL-c2366-4cd5fc080c1ffb43b4a5159196329dee2ec896f6dbd5a78737da4be11066c54d3
Notes ObjectType-Article-1
SourceType-Scholarly Journals-1
ObjectType-Feature-2
content type line 14
ORCID 0000-0003-1760-468X
0009-0003-6669-2660
OpenAccessLink https://www.proquest.com/docview/3275509362?pq-origsite=%requestingapplication%
PQID 3275509362
PQPubID 2055419
ParticipantIDs doaj_primary_oai_doaj_org_article_d32d2f8825484dc98eb04928b4f84a55
proquest_journals_3275509362
gale_infotracmisc_A865610251
gale_infotracacademiconefile_A865610251
crossref_primary_10_3390_data10110186
PublicationCentury 2000
PublicationDate 20251101
PublicationDateYYYYMMDD 2025-11-01
PublicationDate_xml – month: 11
  year: 2025
  text: 20251101
  day: 01
PublicationDecade 2020
PublicationPlace Basel
PublicationPlace_xml – name: Basel
PublicationTitle Data (Basel)
PublicationYear 2025
Publisher MDPI AG
Publisher_xml – name: MDPI AG
References ref_14
ref_13
ref_12
ref_11
ref_10
ref_20
Prates (ref_3) 2025; 24
ref_1
ref_2
ref_19
ref_18
ref_17
ref_16
ref_15
ref_9
ref_8
ref_5
ref_4
ref_7
ref_6
References_xml – ident: ref_6
– ident: ref_9
– ident: ref_18
  doi: 10.1007/s10207-025-01072-6
– ident: ref_7
  doi: 10.1109/MilCIS.2015.7348942
– ident: ref_4
  doi: 10.1109/ACCESS.2023.3320928
– ident: ref_5
  doi: 10.1016/j.cose.2025.104510
– volume: 24
  start-page: 11
  year: 2025
  ident: ref_3
  article-title: DevSecOps practices and tools
  publication-title: Int. J. Inf. Secur.
  doi: 10.1007/s10207-024-00914-z
– ident: ref_12
– ident: ref_11
– ident: ref_2
  doi: 10.2507/35th.daaam.proceedings.042
– ident: ref_19
  doi: 10.1145/3404868.3406664
– ident: ref_13
  doi: 10.3390/fi16070256
– ident: ref_16
– ident: ref_15
– ident: ref_20
  doi: 10.3390/info12070259
– ident: ref_8
  doi: 10.13052/jsn2445-9739.2017.009
– ident: ref_14
– ident: ref_17
– ident: ref_1
– ident: ref_10
  doi: 10.1109/ISGTEUROPE56780.2023.10407262
SSID ssj0002245628
Score 2.3078656
Snippet We present a real-world dataset capturing thirty consecutive days of malicious HTTP traffic filtered and blocked by the OWASP ModSecurity Web Application...
SourceID doaj
proquest
gale
crossref
SourceType Open Website
Aggregation Database
Index Database
StartPage 186
SubjectTerms Anomalies
Applications programs
Archives & records
Audits
Customer feedback
Cybersecurity
Data collection
Data security
Datasets
Headers
HTTP request filtering
Internet software
intrusion detection dataset
Intrusion detection systems
Machine learning
Metadata
ModSecurity
OWASP Core Rule Set (CRS)
Payloads
real-world dataset
Servers
Web Application Firewall (WAF)
Web applications
SummonAdditionalLinks – databaseName: DOAJ Directory of Open Access Journals
  dbid: DOA
  link: http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwrV1Nb9QwELVQxYELonyIhYLmAAIOUVPbcezjllL10rKii9qb5U8oSLsoSSvtv2fGSdH2gLhwTSzZeuPnmZFm3jD2JkeVXeCm0kL7SoZAnGtMRRUKpm1KB00ZNtGenenLS7PYGvVFNWGjPPAI3H4UPPKsKZHRMgajk8eglmsvs5auKeqldWu2kqkfRdSFIns9VroLzOv3S8ElObsDapve8kFFqv9vD3LxMseP2MMpPIT5eKxddi-tHrPdiYA9vJ9Uoj88Yd_msPx-1Q2b6sht4Aj37dMA6wynGFkHqmyFk-VyAV9S2aiHQ3RbP1MEv4HPF_PzBZyu4_k0vQ7WK3CwGNVf0VJwkTzQM5K6p-zr8aflx5NqmppQBS6UQrxjk0k_PBzk7KXwiBLGLMQ0bmJKPAVtVFbRx8YhXUUbnfQJkVEqNDKKZ2xntV6l5wxkTpFHneo61NKl2ivlG17nFrM0kZSesbe3ONpfoziGxaSC8LbbeM_YIYH8Zw1JWpcPaGg7Gdr-y9Az9o5MZIl4Q-eCm_oH8KgkYWXnWlEsiPHajO3dWYmECXd_3xrZToTtreAt5moG3fmL_3HYl-wBp0HBpWlxj-0M3XV6xe6Hm-Gq716Xu_obsx_rMQ
  priority: 102
  providerName: Directory of Open Access Journals
Title A Thirty-Day Dataset of Malicious HTTP Requests Blocked by OWASP ModSecurity on a Production Web Server
URI https://www.proquest.com/docview/3275509362
https://doaj.org/article/d32d2f8825484dc98eb04928b4f84a55
Volume 10
hasFullText 1
inHoldings 1
isFullTextHit
isPrint
journalDatabaseRights – providerCode: PRVAON
  databaseName: DOAJ Directory of Open Access Journals
  customDbUrl:
  eissn: 2306-5729
  dateEnd: 99991231
  omitProxy: false
  ssIdentifier: ssj0002245628
  issn: 2306-5729
  databaseCode: DOA
  dateStart: 20160101
  isFulltext: true
  titleUrlDefault: https://www.doaj.org/
  providerName: Directory of Open Access Journals
– providerCode: PRVHPJ
  databaseName: ROAD: Directory of Open Access Scholarly Resources
  customDbUrl:
  eissn: 2306-5729
  dateEnd: 99991231
  omitProxy: false
  ssIdentifier: ssj0002245628
  issn: 2306-5729
  databaseCode: M~E
  dateStart: 20160101
  isFulltext: true
  titleUrlDefault: https://road.issn.org
  providerName: ISSN International Centre
– providerCode: PRVPQU
  databaseName: Advanced Technologies & Aerospace Database
  customDbUrl:
  eissn: 2306-5729
  dateEnd: 99991231
  omitProxy: false
  ssIdentifier: ssj0002245628
  issn: 2306-5729
  databaseCode: P5Z
  dateStart: 20160601
  isFulltext: true
  titleUrlDefault: https://search.proquest.com/hightechjournals
  providerName: ProQuest
– providerCode: PRVPQU
  databaseName: ProQuest Central
  customDbUrl:
  eissn: 2306-5729
  dateEnd: 99991231
  omitProxy: false
  ssIdentifier: ssj0002245628
  issn: 2306-5729
  databaseCode: BENPR
  dateStart: 20160601
  isFulltext: true
  titleUrlDefault: https://www.proquest.com/central
  providerName: ProQuest
– providerCode: PRVPQU
  databaseName: Publicly Available Content Database
  customDbUrl:
  eissn: 2306-5729
  dateEnd: 99991231
  omitProxy: false
  ssIdentifier: ssj0002245628
  issn: 2306-5729
  databaseCode: PIMPY
  dateStart: 20160601
  isFulltext: true
  titleUrlDefault: http://search.proquest.com/publiccontent
  providerName: ProQuest
link http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwpV3LTxQxGG8UPHhR8BEWcdODRj1MGNpOp3MyuzyCh10nsAb00vSJhGQHZ0aS_e_p1-0iHPTite3hm_n1e_Z7IPTOW-6VIVUmqNAZMwZ4rqgyyFCoyiJW0MRhE-V0Ks7PqzoF3LqUVrmSiVFQ28ZAjHyXkjIY01WQt5-vf2UwNQpeV9MIjcdoHbokwOiGuvhxF2Mh8KpHxDLfnQbvfjemXYLK24Pi6XuaKDbs_5tYjrrm6Pn_UrmBniUrE4-W12ITPXLzF2gz8XGHP6Zm059eoosRnv28bPtFdqAW-CAQ3rkeNx5PgoFuIEEWH89mNT5xkYwOj4P2u3IW6wX-ejY6rfGksadpCB5u5ljhetlENgCOz5zGII1c-wp9Ozqc7R9nafhCZgjlPMBmCw9tyM2e95pRzRSYPsCwpLLOEWdExT232hYqcD0trWLahV_LuSmYpa_R2ryZuy2EmXeWWOHy3ORMuVxzrguS-zI4e9RxMUDvV0DI62WPDRl8EwBM3gdsgMaA0t0Z6IwdF5r2QiZGk5YSS7wAx1cwayrhdHCCiNDMi_AJxQB9AIwl8G_fKqNSGUIgFTphyZHgYFIGs2-Adh6cDHxnHm6vroBMfN_JP_hv_3v7DXpKYJJwrGrcQWt9-9u9RU_MTX_ZtUO0Pj6c1ifDGCEYxksd1uovk_r7LU2i_hg
linkProvider ProQuest
linkToHtml http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMw1V1Lb9QwEB6VLRJcgPIQCwV8oAIOUVPbcZwDQluWalftLhFd1HIK8atUSJuSBND-KX4jnjxKe4BbD1xjK_Lj8zcz9jwAnjsjXK5pEkgmVcC1xjMXJQF6KCRx1ETQNMUm4vlcHh8n6Rr86mNh0K2y58SGqE2h8Y58m9HYK9OJ59s3Z98CrBqFr6t9CY0WFvt29dObbNXr6djv7xale-8WbydBV1Ug0JQJ4cdjIof5tfWOc4ozxXOU6YhEmhhrqdUyEU4YZaLcw5nFJufKejEphI64Yf6_12CdI9gHsJ5OZ-mn81sdiu-IVLYe9owl4Xbj6IlCdgfDtS_IvqZEwN8EQSPd9m7_b-tyB251ejQZtcDfgDW7vAsbHVNV5GWXTvvVPTgZkcWX07JeBeN8RcZ-oSpbk8KRmTdBNLoAk8likZIPtpl2RXa9fP9qDVEr8v5odJiSWWEOuzJ_pFiSnKRtmlwPaXJkFUG-teV9-HglE34Ag2WxtA-BcGcNNdKGoQ55bkMlhIpo6GJvzjIr5BC2-o3PztosIpm3vhAg2UWADGEXUXHeB3N_Nx-K8iTrqCQzjBrqJJr2khudSKu8mUel4k76KURDeIGYypCh6jLXeRdo4YeKub6ykRSoNHvFdgibl3p6ZtGXm3vIZR2zVdkfvD36d_MzuDFZzA6yg-l8_zHcpFg3uYnh3IRBXX63T-C6_lGfVuXT7hAR-HzV-PwNOwJYaA
linkToPdf http://cvtisr.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMw1V1Lb9QwELZKQagXoDzEQgEfqIBDtKmdOM4BoS3LqlXpEtFFrbiY-NVWSJuSBND-NX4dM062tAe49cA1tiI_Pn8zY8-DkOfeCl8alkeSSx0lxuCZS_MIPRTyLA0RNKHYRDadyqOjvFghv5axMOhWueTEQNS2MnhHPuQsA2U6B74d-t4tohhP3px9i7CCFL60LstpdBDZc4ufYL41r3fHsNebjE3ezd7uRH2FgcgwLgSMzaYec22bLe91wnVSonxHVLLcOseckbnwwmqblgBtntky0Q5EphAmTSyH_14j1zOwMdGdsEg_n9_vMHxRZLLztec8j4fB5RPF7RYGbl-QgqFYwN9EQpBzk9v_8wrdIbd67ZqOuuOwTlbc_C5Z7_mroS_7JNuv7pHjEZ2dnNbtIhqXCzqGRWtcSytP98EwMegYTHdms4J-dGEJGroNUv-rs1Qv6IfD0UFB9yt70Bf_o9WclrTokucC0Omh0xRZ2NX3yacrmfADsjqv5u4hoYl3llnp4tjESeliLYROWewzMHK5E3JANpcgUGddbhEFNhmCRV0Ey4BsI0LO-2BG8PChqo9VTzDKcmaZl2jwy8SaXDoNxh-TOvESppAOyAvEl0LeauvSlH34BQwVM4CpkRSoSoO6OyAbl3oC35jLzUv4qZ7vGvUHe4_-3fyM3ARQqve7073HZI1hMeUQ2LlBVtv6u3tCbpgf7WlTPw2niZIvVw3O3yuYX8s
openUrl ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=A+Thirty-Day+Dataset+of+Malicious+HTTP+Requests+Blocked+by+OWASP+ModSecurity+on+a+Production+Web+Server&rft.jtitle=Data+%28Basel%29&rft.au=Lucz%2C+Geza&rft.au=Forstner%2C+Bertalan&rft.date=2025-11-01&rft.pub=MDPI+AG&rft.issn=2306-5729&rft.eissn=2306-5729&rft.volume=10&rft.issue=11&rft_id=info:doi/10.3390%2Fdata10110186&rft.externalDocID=A865610251
thumbnail_l http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/lc.gif&issn=2306-5729&client=summon
thumbnail_m http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/mc.gif&issn=2306-5729&client=summon
thumbnail_s http://covers-cdn.summon.serialssolutions.com/index.aspx?isbn=/sc.gif&issn=2306-5729&client=summon