Web Application Firewalls: A Comprehensive Bibliometric Review
Authors
Raghvendra Singh
Department of Computer Science & Engineering, Sharda University, Greater Noida, India (IN)
Aditya Kaushik
Department of Computer Science & Engineering, Sharda University, Greater Noida, India (IN)
Jatin Kumar
Department of Computer Science & Engineering, Sharda University, Greater Noida, India (IN)
Keshav Kaushik
Center for Cyber Security and Cryptology, Sharda School of Computer Science & Engineering, Sharda University, Greater Noida, India (IN)
Article Information
DOI: 10.51583/IJLTEMAS.2025.1409000092
Subject Category: Computer Science
Volume/Issue: 14/9 | Page No: 780-790
Publication Timeline
Submitted: 2025-10-17
Published: 2025-10-17
Abstract
Abstract-Web Application Firewalls (WAFs) have been characterized as essential in defending web-based systems against standard attacks of the application-layer (SQL injection and cross-site scripting). In order to consider the progress and current research tendencies in this area, this paper provides a broad bibliometric search through the literature on the topic of WAF articles during the 2010-2025 period. On 6 August 2025, the query (Web Application Firewall) OR (WAF) AND (cybersecurity OR web security OR web application security) was selected, and bibliographic data were fetched in the Scopus database. A hit list of 100 publications was eventually processed after screening 412 retrieved records at metadata level using the following filter terms; authorship, citations, keywords, abstracts, titles, year of publication, language of publication, DOI, and institution or organization of publication. Keywords co-occurrence and network effect Co-occurrence statistical analysis was done with using VOSviewer v1.6.20 and R Bibliometrix package to analyze networks and patterns of collaboration between authors and countries and citation. The findings demystify that WAF research has been continuously growing since 2016, and it becomes apparent that lack of interest in the traditional signature-based models has shifted to the machine-learning and cloud-native methods. India, China, and United States are the major contributors. Continuing gaps in research were found in encrypted-traffic inspection, real-time adaptive defence and lack of standard benchmark databases. Reproducibility resources are also given such as exported metadata, keyword mappings, and analysis scripts in the paper to assist other bibliometric research to come, and encourage the openness of future research activity.
Keywords
Web Application Firewall, Bibliometric Analysis, Intrusion Detection, Threat Intelligence, HTTP Security
Downloads
References
1. A. Shaheed and M. H. D. B. Kurdy, “Web Application Firewall Using Machine Learning and Features Engineering,” Security and Communication Networks, vol. 2022, Art. no. 5280158, 2022, doi: 10.1155/2022/5280158. [Google Scholar] [Crossref]
2. S. Applebaum, T. Gaber, and A. Ahmed, “Signature-based and Machine-Learning-based Web Application Firewalls: A Short Survey,” Procedia Computer Science, vol. 189, pp. 359–367, 2021, doi: 10.1016/j.procs.2021.05.105. [Google Scholar] [Crossref]
3. S. Toprak and A. G. Yavuz, “Web Application Firewall Based on Anomaly Detection using Deep Learning,” Acta Infologica, vol. 6, no. 2, pp. 219–244, 2022, doi: 10.26650/acin.1039042. [Google Scholar] [Crossref]
4. M. S. Aliero et al., “Web Application Firewall: Review,” Int. J. Comput. Inf. Res. Adv. Stud., vol. 3, no. 4, pp. 26–43, 2020. [Google Scholar] [Crossref]
5. L. Demetrio et al., “WAF-A-MOLE: Evading Web Application Firewalls through Adversarial Machine Learning,” arXiv preprint arXiv:2001.01952, 2020. [Google Scholar] [Crossref]
6. I. Jemal et al., “SWAF: A Smart Web Application Firewall Based on Convolutional Neural Network,” in Proc. Int. Conf. Security Inf. Technol. (SIN 2022), doi: 10.1109/SIN58406.2022.9970545. [Google Scholar] [Crossref]
7. A. Coscia et al., “PROGESI: A Proxy Grammar to Enhance Web Application Firewall for SQL Injection Prevention,” IEEE Access, vol. 12, 2024, doi: 10.1109/ACCESS.2024.3438092. [Google Scholar] [Crossref]
8. X. Wang and H. Hu, “Evading Web Application Firewalls with Reinforcement Learning,” 2021. [Google Scholar] [Crossref]
9. V. Babaey and A. Ravindran, “GenSQLi: A Generative Artificial Intelligence Framework for Automatically Securing Web Application Firewalls Against SQL Injection Attacks,” Future Internet, vol. 17, no. 1, Jan. 2025, doi: 10.3390/FI17010008. [Google Scholar] [Crossref]
10. J. Á. Román-Gallego et al., “Artificial Intelligence Web Application Firewall for Advanced Detection of Web Injection Attacks,” Expert Systems, vol. 42, no. 1, Jan. 2025, doi: 10.1111/EXSY.13505. [Google Scholar] [Crossref]
11. R. A. Muzaki et al., “Improving Security of Web-Based Application Using ModSecurity and Reverse Proxy in Web Application Firewall,” Preprint, 2020. [Google Scholar] [Crossref]
12. N. O. Maslova et al., “Multi-agent WAF Pentesting on the JADE Platform,” CEUR Workshop Proc., vol. 3988, pp. 282–295, 2025. [Google Scholar] [Crossref]
13. M. Amouei et al., “RAT: Reinforcement-Learning-Driven and Adaptive Testing for Vulnerability Discovery in Web Application Firewalls,” IEEE Trans. Dependable Secure Comput., 2023. [Google Scholar] [Crossref]
14. F. M. Alotaibi and V. G. Vassilakis, “Toward an SDN-based Web Application Firewall: Defending Against SQL Injection Attacks,” Future Internet, vol. 15, no. 5, p. 170, 2023. [Google Scholar] [Crossref]
15. Z. Qu et al., “AdvSQLi: Generating Adversarial SQL Injections Against Real-World WAF-as-a-Service,” IEEE Trans. Inf. Forensics Security, vol. 19, pp. 2623–2638, 2024. [Google Scholar] [Crossref]
16. H. Liang et al., “Generative Pre-Trained Transformer-Based Reinforcement Learning for Testing Web Application Firewalls,” IEEE Trans. Dependable Secure Comput., vol. 21, no. 1, pp. 309–324, 2024. [Google Scholar] [Crossref]
17. G. Floris et al., “ModSec-AdvLearn: Countering Adversarial SQL Injections with Robust Machine Learning,” IEEE Trans. Inf. Forensics Security, vol. 20, pp. 6693–6705, 2025. [Google Scholar] [Crossref]
18. N. W. C. Lasantha et al., “Validating IP Reputation in Cloud Firewall Systems Using Machine Learning Driven Signature Generation and Detection Techniques,” in IEEE IEACon 2024. [Google Scholar] [Crossref]
19. H. Do Hoang et al., “WebGuardRL: A Reinforcement Learning-Based Approach for Advanced Web Attack Detection,” in Proc. ACM SOICT 2023, pp. 761–768. [Google Scholar] [Crossref]
20. J. Yang et al., “LLM-AE-MP: Web Attack Detection Using a Large Language Model with Autoencoder and Multilayer Perceptron,” Expert Systems with Applications, vol. 274, May 2025. [Google Scholar] [Crossref]
21. A. Mycek et al., “Multi-layered Security of Web Applications in Cloud Environments Using WAF, Zero Trust, AI-driven Threat Detection, and RASP,” in Proc. Eur. Council Model. Simul., 2025. [Google Scholar] [Crossref]
22. E. Fakhfakh et al., “Combining TF-IDF, V-GAN, and XGB to Improve Next-Generation Web Application Firewalls,” in IEEE/ACS Int. Conf. Comput. Syst. Appl., 2024. [Google Scholar] [Crossref]
23. K. Gupta et al., “Smart Defense: Machine Learning-Based Web Application Firewall,” in IEEE PuneCon, Dec. 2024. [Google Scholar] [Crossref]
24. S. Dhote et al., “ML-Based Web Application Firewall for Signature and Anomaly Detection Using Feature Extraction,” in IEEE ICCCNT 2024. [Google Scholar] [Crossref]
25. P. Kalariya et al., “ML Assisted Web Application Firewall,” in IEEE ISDFS 2024. [Google Scholar] [Crossref]
26. A. Kumar et al., “Machine Learning-Based Web Application Firewall for Real-Time Threat Detection,” in IEEE ICEI 2024. [Google Scholar] [Crossref]
27. M. Maheshwari et al., “Adaptive Web Application Firewall for Multi-Threat Detection,” in IEEE ICICNIS 2024. [Google Scholar] [Crossref]
28. I. Darmawan et al., “Real-Time Web Application Firewall Monitoring Using the OWASP CRS Framework,” in IEEE ICIC 2024. [Google Scholar] [Crossref]
29. Q. Wang et al., “Automated Discovery of Protocol-Level Evasion Vulnerabilities in WAFs,” in Proc. IEEE SP 2024, pp. 185–202. [Google Scholar] [Crossref]
30. V. Nayar et al., “Optimizing Real-Time Performance in ML-Based Application Layer Firewalls,” Lecture Notes in Networks and Systems, vol. 991, pp. 947–959, 2024. [Google Scholar] [Crossref]
31. E. Tuyishime et al., “Enhancing Cloud Security: Proactive Threat Monitoring Using a SIEM-Based Approach,” Applied Sciences, vol. 13, no. 22, Nov. 2023. [Google Scholar] [Crossref]
32. M. Sepczuk, “Dynamic Web Application Firewall Detection Supported by Cyber Mimic Defense Approach,” J. Netw. Comput. Appl., vol. 213, 2023. [Google Scholar] [Crossref]
33. B. R. Dawadi et al., “Deep Learning Technique-Enabled Web Application Firewall for the Detection of Web Attacks,” Sensors, vol. 23, no. 4, 2023. [Google Scholar] [Crossref]
34. H. Xu et al., “Accelerating Deep Packet Inspection with SIMD-Based Multi-Literal Matching Engine,” IEEE Trans. Netw. Serv. Manag., 2024. [Google Scholar] [Crossref]
35. Y. Guan et al., “SSQLi: A Black-Box Adversarial Attack Method for SQL Injection Based on Reinforcement Learning,” Future Internet, vol. 15, no. 4, 2023. [Google Scholar] [Crossref]
36. B. Shobiri et al., “CDNs’ Dark Side: Security Problems in CDN-to-Origin Connections,” Digital Threats: Research and Practice, vol. 4, no. 1, 2023. [Google Scholar] [Crossref]
37. A. Chowdhary et al., “Generative Adversarial Network (GAN)-Based Autonomous Penetration Testing for Web Applications,” Sensors, vol. 23, no. 18, 2023. [Google Scholar] [Crossref]
38. J. Harish Kumar and J. Godwin Ponsam, “Securing Web Application Using Web Application Firewall (WAF) and Machine Learning,” in Proc. ICAEECI 2023. [Google Scholar] [Crossref]
39. C.-V. Trinh et al., “An Efficient Machine Learning-Based Web Application Firewall with Deep Automated Pattern Categorization,” in Proc. FDSE 2023, pp. 212–225. [Google Scholar] [Crossref]
40. A. Kozhevnikov and Y. Chernyshov, “Implementing Machine Learning in the Context of Web Application Firewalls,” in Proc. IEEE USBEREIT 2024, pp. 237–240. [Google Scholar] [Crossref]
41. G. E. Cárdenas Rosero et al., “Website Protection: An Evaluation of the Web Application Firewall,” Data Metadata, vol. 4, Jan. 2025. [Google Scholar] [Crossref]
42. N. Hubballi et al., “WebScreen+: Web Traffic Screening Performance Enhancement with eBPF Filtering,” in Proc. IEEE ICNC 2025. [Google Scholar] [Crossref]
43. S. Ye et al., “Network Attack Monitoring Based on HTTP Traffic Parameter Analysis,” in Proc. IEEE ITOEC 2025. [Google Scholar] [Crossref]
44. M. Fatima et al., “Enhancing the Resilience of IoT Networks: Strategies for Mitigating DDoS Attacks,” J. Mech. Continua Math. Sci., vol. 19, no. 10, 2024. [Google Scholar] [Crossref]
45. H. Pardamean et al., “Enterprise Architecture Using the Open Group Architecture Framework (TOGAF) in Container Depot Companies,” in Proc. ICE3IS 2024. [Google Scholar] [Crossref]
46. S. P. Singh and N. Afzal, “Effective Bot Management Strategies for Web Applications,” in Proc. ISoIRS 2024. [Google Scholar] [Crossref]
47. H. Verma et al., “A Comprehensive Analysis of Cross-Site Scripting Vulnerabilities,” Comput. Methods Sci. Technol., vol. 2, 2025. [Google Scholar] [Crossref]
48. B. Hulloowan and G. Bekaroo, “Defending Against XML External Entity (XXE) Attacks,” in Proc. NextComp 2024. [Google Scholar] [Crossref]
49. I. F. Sabah, “Design and Implementation of a Web-Based Platform for Administering a Virtual University,” in Proc. HORA 2024. [Google Scholar] [Crossref]
50. E. Leka et al., “Web Application Firewall for Detecting and Mitigation of DDoS Attacks Using ML and Blockchain,” TEM Journal, vol. 13, no. 4, 2024. [Google Scholar] [Crossref]
51. A. Alquwayzani et al., “Mitigating Security Risks in Firewalls and Web Applications Using VAPT,” Int. J. Adv. Comput. Sci. Appl. (IJACSA), vol. 15, no. 5, 2024. [Google Scholar] [Crossref]
52. N. W. C. Lasantha et al., “Hybrid Supervised Machine Learning Driven IP Reputation Validation for Cloud Firewalls,” in Proc. IEEE ICATC 2024. [Google Scholar] [Crossref]
53. F. N. Nife and Z. Kotulski, “Application-Aware Firewall Mechanism for Software Defined Networks,” J. Netw. Syst. Manag., vol. 28, 2020. [Google Scholar] [Crossref]
54. T. D. Sobola et al., “Experimental Study of ModSecurity Web Application Firewalls,” Project Report, Concordia University Edmonton, 2020. [Google Scholar] [Crossref]
55. C. Scano et al., “ModSec-Learn: Boosting ModSecurity with Machine Learning,” Lecture Notes in Networks and Systems, vol. 1198, 2025. [Google Scholar] [Crossref]
56. A. Mycek et al., “Multi-layered Security of Web Applications in Cloud Environments Using WAF and Zero Trust,” in Proc. Eur. Council Model. Simul., 2025. [Google Scholar] [Crossref]
57. E. Tuyishime et al., “Enhancing Cloud Security—Proactive Threat Monitoring and Detection,” Applied Sciences, 2023. [Google Scholar] [Crossref]
58. M. S. Islam et al., “Analysis and Evaluation of Network and Application Security Based on Next Generation Firewall,” Int. J. Comput. Digit. Syst., vol. 13, no. 1, 2023. [Google Scholar] [Crossref]
59. H. Bahruddin et al., “Adversary Simulation of SQL Injection Attack Using Genetic Algorithm for WAF Bypass,” in Proc. IntelliSys 2023, vol. 823, pp. 656–669. [Google Scholar] [Crossref]
60. M. N. Zaidan et al., “Collaborative Detection of SQL Injection Attacks Using SIEM and WAFs,” in Proc. IEEE CIEES 2024. [Google Scholar] [Crossref]
61. Y. Nikam et al., “AI-Based Web Application Firewall,” in Proc. IEEE ICCCIT 2025. [Google Scholar] [Crossref]
62. J.-K. Lee et al., “AI-Based Approach to Firewall Rule Refinement on HPC Networks,” Applied Sciences, vol. 14, 2024. [Google Scholar] [Crossref]
63. A. Gzyl et al., “Understanding the Feature Space and Decision Boundaries of Commercial WAFs,” Entropy, vol. 25, no. 11, 2023. [Google Scholar] [Crossref]
64. H. Gzyl et al., “Maximum Entropy in Commercial WAFs,” Entropy, vol. 25, no. 11, 2023. [Google Scholar] [Crossref]
65. J. Carrillo-Mondejar et al., “Hardening IoT Devices Using Defensive Firmware Modifications,” IEEE Internet Things Journal, vol. 10, no. 10, 2023. [Google Scholar] [Crossref]
66. A. Shaheed et al., “AI-Based WAF Using Feature Engineering,” Security and Communication Networks, vol. 2022. [Google Scholar] [Crossref]
67. O. Chakir and Y. Sadqi, “Evaluation of Open-Source Web Application Firewalls for Cyber Threat Intelligence,” CRC Press, 2023. [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- Competency and Challenges of BTLED-ICT Students in 2D Animation: An Analytical Study
- Slope Stability Assessment: A Case Study of Embankments Along OMU-Aran-Ilorin Road, Nigeria
- Advancements in Precursors, Materials, Deposition Techniques for Thin Film Research in Electronic Devices: A Mini Review
- “Empowering Indian Women through Entrepreneurship: A Study on Kolkata”
- Impact of Mental Mathematics Proficiency on Job Performance Among Seconadry Schools Teachers in Emohua and Port Hacourt City