Web applications are normally written in scripting languages like JavaScript, PHP embedded in HTML allowing connectivity to the databases, retrieving data and putting them in the WWW site. A web application is vulnerable to many kinds of threats and attacks. In order to detect known attacks, some set of attack rules and detections are needed. In this paper, a negative
security model based on misuse of web applications is used.
This negative security model provides a Web Application
Firewall(WAF) engine with a rule set, to ensure critical
protection across every web architecture.