Advancing continuous integration for WAF engines by developing the ModSecurity Regression Test Set

(2025)

Files

Amelinckx_55691700_2025.pdf
  • Open access
  • Adobe PDF
  • 1.23 MB

Details

Supervisors
Faculty
Degree label
Abstract
Web application security is an increasingly critical concern for organizations relying on web technologies to support their operations. Web Application Firewalls (WAFs) serve as the first line of defense against attacks targeting web applications. ModSecurity, a popular open-source WAF engine, recently underwent a development transition from Trustwave to the OWASP community. During this transition, no automated testing infrastructure was transferred to the new developers. Motivated by the absence of testing within ModSecurity’s continuous integration and continuous delivery (CI/CD) pipelines, this work proposes a WAF engine testing methodology aimed at assisting developers in implementing a rigorous CI process. The work begins by evaluating the testing practices and tools of the OWASP Core Rule Set, followed by a description of the attempt of ModSecurity developers to adapt these tools into a utility known as the ModSecurity Regression Test Set (MRTS). To help advance MRTS to sufficient maturity for integration into ModSecurity’s CI/CD pipelines, this thesis contributes new features and test cases to the MRTS testing framework. Finally, the test set is evaluated on ModSecurity2 and libmodsecurity3 infrastructures, and the work concludes by outlining future directions for MRTS’s development.