Yousef Khalaf

Work place: Zarqa University, College of Cyber Security, Zarqa, 13112, Jordan

E-mail: yousefmohammadkhalaf@gmail.com

Website: https://orcid.org/0009-0006-4536-0781

Research Interests: Artificial Intelligence, Network Architecture, Digital Forensics

Biography

Yousef Khalaf received his B.Sc. degree in Cyber Security from Zarqa University, Zarqa, Jordan. His academic interests include cybersecurity, web application security, penetration testing, network security, digital forensics, cryptography, artificial intelligence in cybersecurity, and security automation.
He is currently a researcher. His research focuses on intelligent security systems, Web Application Firewalls (WAFs), Large Language Models (LLMs) for threat detection, malware analysis, and secure software development. He is the author of several scientific publications in the fields of cybersecurity and information security.
Mr. Khalaf is a member of various academic and cybersecurity communities. His achievements include publishing peer-reviewed research papers in international journals and actively participating in cybersecurity training programs and technical research activities. His current research interests include AI-driven cybersecurity, threat intelligence, digital forensics, and secure network architectures.

Author Articles
LLM-WAF: An Intelligent Web Application Firewall Powered by Large Language Models for Advanced Threat Detection

By Yousef Khalaf

DOI: https://doi.org/10.5815/ijwmt.2026.04.18, Pub. Date: 8 Aug. 2026

Traditional signature-based Web Application Firewalls (WAFs) have difficulty detecting increasingly complex assaults that target web applications, such as SQL injections, Cross-Site Scripting (XSS), and API misuse. In this study, we introduce LLM-WAF, a new intelligent firewall architecture that uses Large Language Models (LLMs) to analyze HTTP traffic contextually and semantically. Our framework integrates pre-trained language models with realtime traffic monitoring pipelines to identify malicious payloads through natural language processing capabilities rather than static rule matching. The system incorporates a continuous learning mechanism using reinforcement signals from detected attacks to adapt to emerging threat vectors automatically. In comparison to conventional WAF systems, experimental evaluation on benchmark datasets such as the CSIC 2010 HTTP Dataset and real-world traffic scenarios shows that LLM-WAF achieves 96.8% detection accuracy with an F1=0.95cand dramatically lowers false positives.

[...] Read more.
Other Articles