LLM-WAF: An Intelligent Web Application Firewall Powered by Large Language Models for Advanced Threat Detection

PDF (393KB), PP.317-327

Views: 0 Downloads: 0

Author(s)

Yousef Khalaf 1

1. Zarqa University, College of Cyber Security, Zarqa, 13112, Jordan

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.04.18

Received: 25 Feb. 2026 / Revised: 1 Apr. 2026 / Accepted: 15 Jul. 2026 / Published: 8 Aug. 2026

Index Terms

Web Application Firewall, Large Language Models, Cybersecurity, SQL Injection, Cross-Site Scripting, Natural Language Processing, Machine Learning, Threat Detection

Abstract

Traditional signature-based Web Application Firewalls (WAFs) have difficulty detecting increasingly complex assaults that target web applications, such as SQL injections, Cross-Site Scripting (XSS), and API misuse. In this study, we introduce LLM-WAF, a new intelligent firewall architecture that uses Large Language Models (LLMs) to analyze HTTP traffic contextually and semantically. Our framework integrates pre-trained language models with realtime traffic monitoring pipelines to identify malicious payloads through natural language processing capabilities rather than static rule matching. The system incorporates a continuous learning mechanism using reinforcement signals from detected attacks to adapt to emerging threat vectors automatically. In comparison to conventional WAF systems, experimental evaluation on benchmark datasets such as the CSIC 2010 HTTP Dataset and real-world traffic scenarios shows that LLM-WAF achieves 96.8% detection accuracy with an F1=0.95cand dramatically lowers false positives.

Cite This Paper

Yousef Khalaf, "LLM-WAF: An Intelligent Web Application Firewall Powered by Large Language Models for Advanced Threat Detection", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.4, pp. 317-327, 2026. DOI:10.5815/ijwmt.2026.04.18

Reference

[1]Khalaf, Y., Aljaidi, M., Laila, D.A., Alsarhan, A., Alkhawaldeh, A.K., Alsuwaylimi, A.A. and Kharabsheh, M., 2025. An Effective Encryption Algorithm Based on RSA and DES. International Journal of Communication Networks and Information Security, 17(4), pp.10-19.
[2]Laila, D. A., Aljaidi, M., Almaiah, M. A., AlBourini, M., Al-Na’amneh, Q., Samara, G., and Momani, K., 2025. A Novel Scheme to Optimize LSB Steganography Based on a Logistic Chaotic Map and Genetic Algorithm. Iraqi Journal for Computer Science and Mathematics, 6(2), p.24.
[3]A l-Mousa, M., Amer, W., Abualhaj, M., Albilasi, S., Nasir, O. and Samara, G., “Agile Proactive Cybercrime Evidence Analysis Model for Digital Forensics,” The International Arab Journal of Information Technology (IAJIT), vol. 22, no. 3, pp. 627–636, 2025, doi: 10.34028/iajit/22/3/15.
[4]Alazaidah, R., Al-Shaikh, A., Al-Mousa, R., Khafajah, H., Samara, G., and Alzyoud, M., 2024. Website Phishing Detection Using Machine Learning Techniques. Journal of Statistics Applications & Probability, 13(1), Article 8.
[5]Król, M., Janiszewski, P., & Mazurczyk, W., "Dynamic Web Application Firewall Detection Supported by Cyber Mimic Defense Approach", Journal of Network and Computer Applications, Vol. 213, Article 103596, 2023. DOI: 10.1016/j.jnca.2023.103596
[6]Kakisim, A. G.,"A Deep Learning Approach Based on Multi-View Consensus for SQL Injection Detection", International Journal of Information Security, Vol. 23, pp. 1541–1556, 2024.DOI: 10.1007/s10207-023-00791-y 
[7]Husari, G., Al-Shaer, E., Ahmed, M., & Chu, B., "Natural Language Processing for Cybersecurity: A Survey", ACM Computing Surveys, Vol. 56, No. 2, pp. 1-38,2023. DOI: 10.1145/3597303
[8]Zhu, X., Zhou, W., Han, Q.-L., Ma, W., Wen, S., & Xiang, Y., "When Software Security Meets Large Language Models: A Survey", IEEE/CAA Journal of Automatica Sinica, Vol. 12, No. 2, pp. 317-334, 2025. DOI: 10.1109/JAS.2024.124971
[9]Apruzzese, G., Andreolini, M., Marchetti, M., Colajanni, M., & Ferretti, L.,"Deep Learning for Cybersecurity: The Adversarial Case", IEEE Transactions on Artificial Intelligence, Vol. 4, No. 1, pp. 21-35,2023. DOI: 10.1109/TAI.2022.3141259
[10]Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H.,"Deep Learning and Transformer-Based Approaches for Cyber Threat Detection", IEEE Communications Surveys & Tutorials, Vol. 25, No. 2, pp. 1024-1062, 2023. DOI: 10.1109/COMST.2023.3241234
[11]Jaffal, N. O., Alkhanafseh, M., & Mohaisen, D., "Large Language Models in Cybersecurity: Applications and Challenges", AI, Vol. 6, No. 9, Article 216, 2025. DOI: 10.3390/ai6090216
[12]Alzahrani, N., Alenazi, M., & Alshammari, R., "Web Application Security: Threats, Vulnerabilities and Defense Mechanisms", Computer Networks, Vol. 235, Article 109957 ,2024. DOI: 10.1016/j.comnet.2023.109957
[13]Dawadi, B. R., Adhikari, B., & Srivastava, D. K., "Deep Learning Technique-Enabled Web Application Firewall for the Detection of Web Attacks”, Sensors, Vol. 23, No. 4, Article 2073, 2023.DOI: 10.3390/s23042073
[14]Kim, J., Lee, H., & Park, Y., "Adaptive Learning Frameworks for Cybersecurity Systems: Challenges and Opportunities", IEEE Security & Privacy, Vol. 21, No. 3, pp. 45-53, 2023. DOI: 10.1109/MSEC.2023.3254478
[15]Ferrag, M. A., Alwahedi, F., Battah, A., Cherif, B., Mechri, A., & Tihanyi, N., "Generative AI in Cybersecurity: A Comprehensive Review of Large Language Models Applications and Vulnerabilities", Internet of Things and Cyber-Physical Systems, Vol. 5, pp. 1–46, 2025. DOI: 10.1016/j.iotcps.2025.01.001