Context
Following automated research using CVE-derived payloads tested against CRS 4.x PL1 (methodology: https://wafplanet.com/blog/autoresearch-crs-regex/), we identified several false positive reductions and false negative improvements.
Per maintainer feedback on #4573 and #4574, we split the combined PRs into individual PRs for easier review.
False Positive Reductions
| # |
PR |
Rule |
Description |
Status |
| 1 |
#4585 |
933150 |
Remove is_int from PHP function list |
Merged |
| 2 |
#4586 |
LFI data |
.profile -> /.profile (require path prefix) |
Merged |
| 3 |
#4587 |
932370 |
Remove url from Windows LOLBIN list |
Merged |
| 4 |
#4588 |
942290 |
MongoDB operator word boundary |
Merged |
| 5 |
#4589 |
942550 |
JSON/PostgreSQL: restrict to single-quote and backtick |
Changes requested |
| 6 |
#4590 |
943110 |
Remove generic session-id/session_id from PL1 |
Open |
| 7 |
#4591 |
932xxx |
Remove \\{ from shell evasion prefix |
Open |
| 8 |
#4592 |
932xxx |
Remove w from no-arguments list |
Merged |
| 9 |
#4593 |
932xxx |
Require arguments for base64, lastlog, lastlogin |
Merged |
| 10 |
#4594 |
920420 |
Content-Type: split on comma |
Closed (superseded by #4365) |
| 11 |
#4595 |
932330 |
!-\d require non-alphanumeric prefix |
Open |
| 12 |
#4596 |
932270 |
Tilde expansion: require boundary |
Open |
False Negative Improvements
| # |
PR |
Rule |
Description |
Status |
| 1 |
#4597 |
942190/942230 |
SQLite ==, GLOB, PostgreSQL ARRAY @>, UNION newline evasion |
Open |
| 2 |
#4598 |
932130 |
ANSI-C hex quoting ($'\x69\x64') |
Open |
| 3 |
#4599 |
932xxx |
Backslash-prefix evasion (\id) |
Merged |
| 4 |
#4600 |
934175 |
New SSTI detection rule |
Merged |
| 5 |
#4601 |
LFI data |
.dockerenv, .DS_Store, META-INF/, WEB-INF/ |
Merged |
Dataset
- 95 malicious CVE-derived payloads
- 4500 legitimate request samples
- Combined balanced accuracy improvement: 0.630 -> 0.900
- FP reduction: 666 fewer false positives
- FN improvement: 37 more true detections
Superseded PRs
Blog post
https://wafplanet.com/blog/autoresearch-crs-regex/
Context
Following automated research using CVE-derived payloads tested against CRS 4.x PL1 (methodology: https://wafplanet.com/blog/autoresearch-crs-regex/), we identified several false positive reductions and false negative improvements.
Per maintainer feedback on #4573 and #4574, we split the combined PRs into individual PRs for easier review.
False Positive Reductions
is_intfrom PHP function list.profile->/.profile(require path prefix)urlfrom Windows LOLBIN listsession-id/session_idfrom PL1\\{from shell evasion prefixwfrom no-arguments listbase64,lastlog,lastlogin!-\drequire non-alphanumeric prefixFalse Negative Improvements
Dataset
Superseded PRs
Blog post
https://wafplanet.com/blog/autoresearch-crs-regex/