TWO-LAYER WEB APPLICATION SECURITY MODEL BASED ON OWASP TOP 10:2025 AND ARTIFICIAL INTELLIGENCE METHODS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1230Keywords:
web application security, OWASP Top 10, artificial intelligence, anomaly detection, graph neural networks, intrusion detection, two-layer security model, cyber threat protectionAbstract
Web applications continue to be the primary target for cyberattacks such as SQL injection (SQLi), cross-site scripting (XSS), cross-site request forgery (CSRF), and distributed denial-of-service (DDoS). The traditional methods of defense - signature matching, static rule sets, and perimeter control - can no longer keep up with the dynamic threats that modern cloud-based and API-driven systems face on a daily basis. In this paper, we propose a two-layer security model framework designed to bridge this gap. The framework is organized into two complementary layers. The first layer uses deterministic security controls aligned with the OWASP Top 10:2025 standard, providing a stable and auditable baseline of protection. The second layer integrates three complementary AI techniques: HTTP request embeddings (HTTP2vec) for semantic representation of traffic, Graph Neural Networks (GNNs) for modeling relational patterns between users, sessions, and endpoints, and an autoencoder-based online anomaly detector called Kitsune, which adapts to evolving traffic in real time. We use a structured analytical approach in this study. First, we review recent research papers and real-world incident reports from industry, and then we systematically compare different detection methods across accuracy, latency, and operational cost. The results show that traditional controls remain effective against known attack signatures, while AI-driven methods are far better at uncovering zero-day exploits and coordinated, low-and-slow campaigns that rule-based systems typically miss. Industry reports indicate that integrating AI into SIEM and SOAR platforms can reduce false-positive alerts by approximately 60% and accelerate incident investigation by about 40%, freeing analysts to focus on higher-value tasks. We also argue that Precision–Recall curves and the Numenta Anomaly Benchmark (NAB) are more appropriate evaluation tools than ROC-AUC for security data, where malicious traffic often represents less than 0.1% of total volume and class imbalance distorts conventional metrics. The main conclusion is simple but important: AI performs best not as a replacement for traditional controls, but as a force multiplier that strengthens them, producing a layered defense that is both resilient and adaptive.
Downloads
References
International Telecommunication Union. (2024). Facts and figures 2024: Internet use. ITU. https://www.itu.int/itu-d/reports/statistics/2024/11/10/ff24-internet-use/
OWASP Foundation. (2025). OWASP Top 10:2025. https://owasp.org/Top10/2025/
Verizon Business. (2024). 2024 data breach investigations report. https://www.verizon.com/business/resources/reports/dbir.html
Tolkachov, M. Yu. (2024). Mechanisms of traffic protection in cyberspace. Suchasnyi Zakhyst Informatsii, 4(60), 85-99. https://doi.org/10.31673/2409-7292.2024.040009
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
IBM Security. (2023). Cost of a data breach report 2023. IBM. https://d110erj175o600.cloudfront.net/wp-content/uploads/2023/07/25111651/Cost-of-a-Data-Breach-Report-2023.pdf
Dilmegani, C. (2025). Top 13 AI cybersecurity use cases with real examples in 2025. AIMultiple Research. https://research.aimultiple.com/ai-cybersecurity-use-cases/
Gniewkowski, M., Maciejewski, H., Surmacz, T., & Walentynowicz, W. (2021). HTTP2vec: Embedding of HTTP requests for detection of anomalous traffic (arXiv:2108.01763). arXiv. https://doi.org/10.48550/arXiv.2108.01763
Bilot, T., Legay, A., & Rønne, P. B. (2023). Graph neural networks for intrusion detection: A survey. IEEE Access, 11, 45589-45612. https://doi.org/10.1109/ACCESS.2023.3275789
Mirsky, Y., Doitshman, T., Elovici, Y., & Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. In Proceedings of the Network and Distributed System Security Symposium (NDSS 2018). Internet Society. https://doi.org/10.14722/ndss.2018.23204
Razzaq, A., Hur, A., Ahmad, H. F., & Masood, M. (2013). Cyber security: Threats, reasons, challenges, methodologies and state-of-the-art solutions for industrial applications. In 2013 IEEE 11th International Symposium on Autonomous Decentralized Systems (ISADS) (pp. 1–6). IEEE. https://doi.org/10.1109/ISADS.2013.6513420
Liao, H. J., Lin, C. H. R., Lin, Y. C., & Tung, K. Y. (2013). Intrusion detection system: A comprehensive review. Journal of Network and Computer Applications, 36(1), 16–24. https://doi.org/10.1016/j.jnca.2012.09.004
Clincy, V., & Shahriar, H. (2018). Web application firewall: Network security models and configuration. In 2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC) (pp. 835–836). IEEE. https://doi.org/10.1109/COMPSAC.2018.00144
OWASP Foundation. (2025). OWASP Top 10:2025-Introduction. https://owasp.org/Top10/2025/0x00_2025-Introduction/
Park, S., Kim, M., & Lee, S. (2018). Anomaly detection for HTTP using convolutional autoencoders. IEEE Access, 6, 70884-70901. https://doi.org/10.1109/ACCESS.2018.2881003
Davis, J., & Goadrich, M. (2006). The relationship between precision-recall and ROC curves. In Proceedings of the 23rd International Conference on Machine Learning (ICML '06) (pp. 233-240). https://ftp.cs.wisc.edu/machine-learning/shavlik-group/davis.icml06.pdf
Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153-1176. https://doi.org/10.1109/COMST.2015.2494502
Saito, T., & Rehmsmeier, M. (2015). The precision-recall plot is more informative than the ROC plot when evaluating binary classifiers on imbalanced datasets. PLOS ONE, 10(3), e0118432. https://doi.org/10.1371/journal.pone.0118432
Lavin, A., & Ahmad, S. (2015). Evaluating real-time anomaly detection algorithms: The Numenta Anomaly Benchmark. In 2015 14th IEEE International Conference on Machine Learning and Applications (ICMLA) (pp. 38-44). IEEE. https://doi.org/10.48550/arXiv.1510.03336
Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the International Conference on Information Systems Security and Privacy (ICISSP 2018) (pp. 108–116). https://www.scitepress.org/papers/2018/66398/66398.pdf
National Institute of Standards and Technology. (2022). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53, Rev. 4). https://doi.org/10.6028/NIST.SP.800-53r4
Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In 2010 IEEE Symposium on Security and Privacy (pp. 305–316). IEEE. https://doi.org/10.1109/SP.2010.25
Ahmad, Z., Shahid Khan, A., Wai Shiang, C., Abdullah, J., & Ahmad, F. (2021). Network intrusion detection system: A systematic study of machine learning and deep learning approaches. Transactions on Emerging Telecommunications Technologies, 32(1), e4150. https://doi.org/10.1002/ett.4150
Li, J., Zhang, H., & Wei, Z. (2020). The weighted Word2Vec paragraph vectors for anomaly detection over HTTP traffic. IEEE Access, 8, 141787-141798. https://doi.org/10.1109/ACCESS.2020.3013849
Vartouni, A. M., Kashi, S. S., & Teshnehlab, M. (2018). An anomaly detection method to detect web attacks using stacked auto-encoder. In 2018 6th Iranian Joint Congress on Fuzzy and Intelligent Systems (CFIS) (pp. 131-134). IEEE. https://doi.org/10.1109/CFIS.2018.8336654
Tolkachov, M. Yu., Dzheniuk, N. V., Zakharzhevskyi, A. H., Pohasii, S. S., & Hlukhov, S. I. (2024). Method of protecting information resources based on a semiotic model of cyberspace. Suchasnyi Zakhyst Informatsii, 1(57), 57-68. https://doi.org/10.31673/2409-7292.2024.010007
Tolkachov, M., Dzheniuk, N., Yevseiev, S., et al. (2024). Development of a method for protecting information resources in a corporate network by segmenting traffic. Eastern-European Journal of Enterprise Technologies, 5(9(131)), 63-78. https://doi.org/10.15587/1729-4061.2024.313158
OWASP Foundation. (2021). OWASP Top 10:2021. https://owasp.org/Top10/2021/
Cisco. (2020). Cisco annual Internet report (2018-2023). https://www.deeprogram.org/library-v2/cisco-annual-internet-report-2018-2023-/5H7BUBW2
Sandvine. (2024). The global Internet phenomena report 2024. https://www.sandvine.com
International Organization for Standardization. (2023). ISO/IEC 27032:2023. Information technology-Cybersecurity-Guidelines for Internet security. ISO. https://cdn.standards.iteh.ai/sist-preview/76070/be57667fdd0b432490c253ca538c9938/ISO-IEC-27032-2023.pdf
Milevskyi, S. V., Kostiak, M. Yu., Milov, O. V., & Pohasii, S. S. (2019). Means of modeling agent behavior in information and communication systems. Systems of Navigation, Management, Communication and Control, 6(58), 63-70. https://doi.org/10.26906/SUNZ.2019.6.063
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Костянтин Савчук, Олена Нємкова

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.