การพัฒนาระบบ Web Application Firewall (WAF) อัจฉริยะที่ใช้ Machine Learning ในการตรวจจับและป้องกันการโจมตี
Main Article Content
บทคัดย่อ
การวิจัยนี้มีวัตถุประสงค์เพื่อพัฒนาระบบ Web Application Firewall (WAF) อัจฉริยะ โดยประยุกต์ใช้เทคนิค Machine Learning และ Deep Learning เพื่อเพิ่มประสิทธิภาพในการตรวจจับและป้องกันการโจมตีทางเว็บ โดยโมเดลที่ใช้ในการวิจัยประกอบด้วยเทคนิคในกลุ่ม Machine Learning ได้แก่ Random Forest และ Support Vector Machine (SVM) และเทคนิคในกลุ่ม Deep Learning ได้แก่ Deep Neural Network (DNN) ระบบที่พัฒนาขึ้นใช้ข้อมูลจากชุด CIC-IDS2017 Dataset และ OWASP Benchmark Dataset สำหรับการฝึกสอบและทดสอบโมเดลการเรียนรู้ ผลการทดลองพบว่า โมเดล Deep Neural Network (DNN) ซึ่งเป็นเทคนิคในกลุ่ม Deep Learning มีประสิทธิภาพสูงสุด โดยให้ค่าความแม่นยำเฉลี่ย 97.60% และค่า F1-Score ที่ 96.65% สูงกว่าโมเดลในกลุ่ม Machine Learning ได้แก่ Random Forest และ SVM ระบบ WAF ที่พัฒนาเชื่อมต่อกับโมเดลผ่าน RESTful API และสามารถตรวจจับการโจมตีแบบเรียลไทม์ได้ โดยมีเวลาเฉลี่ยในการตอบสนองเพียง 120 มิลลิวินาที ผลการทดสอบการทำงานของระบบพบว่า ระบบมีความแม่นยำในการตรวจจับการโจมตีเฉลี่ย 96.10% และผู้ใช้งานมีระดับความพึงพอใจต่อระบบอยู่ในระดับ “มากที่สุด” (ค่าเฉลี่ย 4.53 จาก 5) โดยเฉพาะด้านความถูกต้องของการตรวจจับและความรวดเร็วในการตอบสนอง ผลการวิจัยแสดงให้เห็นว่า การประยุกต์ใช้เทคนิค Deep Learning โดยเฉพาะโมเดล Deep Neural Network (DNN) สามารถช่วยเพิ่มประสิทธาภพในการตรวจจับการโจมตีทางเว็บได้สูงกว่าเทคนิคในกลุ่ม Machine Learning และมีศักยภาพในการนำไปพัฒนาเป็นเครื่องมือด้านความปลอดภัยไซเบอร์ที่สามารถตรวจจับการโจมตีทั้งแบบที่เคยรู้จักและไม่เคยรู้จักมาก่อนได้อย่างมีประสิทธิภาพ
Downloads
Article Details

อนุญาตภายใต้เงื่อนไข Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Journal of TCI is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International (CC BY-NC-ND 4.0) licence, unless otherwise stated. Please read our Policies page for more information...
เอกสารอ้างอิง
The Open Web Application Security Project, “OWASP Top 10 - 2021,” 2021. [Online]. Available: https://owasp.org/Top10/. [Accessed: Mar. 11, 2026].
M. E. Durmuşkaya and S. Bayraklı, “Web application firewall based on machine learning models,” PeerJ Computer Science, vol. 11, Art. no. e2975, 2025, doi: 10.7717/ peerj-cs.2975.
M. Ito and H. Iyatomi, “Web application firewall using character-level convolutional neural network,” in Proc. IEEE 14th Int. Colloquium on Signal Processing and Its Applications (CSPA), Kuala Lumpur, Malaysia, Mar. 9-10, 2018, pp. 103-106, doi: 10.1109/ CSPA.2018.8368694.
B. Işık and I. Sogukpinar, “Machine learning based web application firewall,” Expert Systems, vol. 42, Art. no. e13467, 2025, doi: 10.1111/exsy.13467.
G. Betarte, Á. Pardo, and R. Martínez, “Web application attacks detection using machine learning techniques,” in Proc. IEEE 17th Int. Conf. Machine Learning and Applications (ICMLA), Orlando, FL, USA, Dec. 16-19, 2018, pp. 1065-1072, doi: 10.1109/ICMLA. 2018.00167.
B. R. Dawadi, B. Adhikari, and D. K. Srivastava, “Deep learning technique-enabled web application firewall for the detection of web attacks,” Sensors, vol. 23, no. 4, p. 2073, Feb. 2023, doi: 10.3390/s23042073.
A. Moradi Vartouni, M. Teshnehlab, and S. Sedighian Kashi, “Leveraging deep neural networks for anomaly-based web application firewall,” IET Information Security, vol. 13, no. 4, pp. 352-361, Jul. 2019, doi: 10.1049/iet-ifs.2018.5212.
M. Krishnan, Y. Lim, S. Perumal, and G. Palanisamy, “Detection and defending the XSS attack using novel hybrid stacking ensemble learning-based DNN approach,” Digital Communications and Networks, vol. 8, no. 1, pp. 49-60, Feb. 2022, doi: 10.1016/j.dcan.2021.06.004.
R. Vinayakumar et al., “Deep learning approach for intelligent intrusion detection system,” IEEE Access, vol. 7, pp. 41525- 41550, 2019, doi: 10.1109/ACCESS. 2019.2895334.
D. S. Berman, A. L. Buczak, J. S. Chavis, and C. L. Corbett, “A survey of deep learning methods for cyber security,” Information, vol. 10, no. 4, p. 122, Apr. 2019, doi: 10.3390/ info10040122.
D. Chen and D. Zhang, “Deep learning for vulnerability and attack detection on web applications: A systematic literature review,” Sensors, vol. 22, no. 4, Art. no. 118, Mar. 2022, doi: 10.3390/s22010118.
A. S. Alnami and T. B. Kim, “Adaptive web application firewall using risk-based adaptation,” Computers & Security, vol. 101, Art. no. 102120, Feb. 2021, doi: 10.1016/j.cose.2020.102120.
I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. 4th Int. Conf. Information Systems Security and Privacy (ICISSP), Funchal, Madeira, Portugal, Jan. 2018, pp. 108-116, doi: 10.5220/0006639801080116.