Journal "Software Engineering"
a journal on theoretical and applied science and technology
ISSN 2220-3397

Issue N8 2026 year

DOI: 10.17587/prin.17.415-425
Web Application Attack Detection Methodology Based on a Combination of Gradient Boosting, Transformers, and Neural Networks
P. S. Sobolev, Postgraduate Student, pavels21@bk.ru, Saint Petersburg National Research University of Information Technologies, Mechanics, and Optics, Saint Petersburg, 197101, Russian Federation, I. V. Kotenko, D. Sc. (Eng.), Professor, Honored Scientist of the Russian Federation, Chief Researcher, ivkote@comsec.spb.ru, Saint Petersburg Federal Research Center of the Russian Academy of Sciences, Saint Petersburg, 199178, Russian Federation
Corresponding author: Pavel S. Sobolev, Postgraduate Student, Saint Petersburg National Research University of Information Technologies, Mechanics, and Optics, Saint Petersburg, 197101, Russian Federation, E-mail: pavels21@bk.ru
Received on May 21, 2026
Accepted on June 02, 2026

The growing number of attacks on web applications and the increasing volume of HTTP traffic strengthen the requirements for automatic malware detection systems. The aim of the research is to develop a technique for detecting attacks on web applications based on a cascade approach, which allows combining a quick initial analysis of incoming requests with a more detailed classification of potentially dangerous traffic. The proposed methodology is based on the sequential (step-by-step) application of two models that differ in purpose and computational complexity. The first stage performs binary filtering of HTTP requests and is designed to promptly exclude legitimate traffic from further processing. The second stage applies only to requests deemed suspicious and solves the task of multiclass classification by identifying the type of attack. Due to this separation, resource-intensive processing is not used for the entire data stream, but only for its most significant part, which reduces the computational load of the system. The paper also presents a technique for detecting attacks on web applications, describing the full cycle of building and applying the proposed cascade model. It allows us to consider the model not only as an experimental solution, but also as a consistent procedure suitable for practical implementation. Experimental verification of the proposed approach demonstrates that the cascading organization of the analysis makes it possible to reduce the number of requests submitted for in-depth verification without significantly reducing the ability of the model to detect malicious requests. The proposed approach is aimed at eliminating one of the significant limitations of existing solutions, which is the gap between the high quality of classification and the practical applicability of the model when processing an intensive stream of HTTP requests.

Keywords: web application attack detection, machine learning, transformer, deep learning, convolutional neural networks, multilayer perceptron, cascade model, attack detection methodology, SQL injection, XSS attacks
pp. 415—425
For citation:
Sobolev P. S., Kotenko I. V. Web Application Attack Detection Methodology Based on a Combination of Gradient Boosting, Transformers, and Neural Networks, Programmnaya Ingeneria, 2026, vol. 17, no. 8, pp. 415—425. DOI: 10.17587/prin.17.415-425. (in Russian).
The work was carried out with partial financial support from budget topic FFZF-2025-0016
References:
  1. Kaur D., Kaur P. Empirical Analysis of Web Attacks, Procedia Computer Science, 2016, vol. 78, pp. 298—306. DOI: 10.1016/j.procs.2016.02.057.
  2. Kotenko I. V., Levshun D. A. Methods of Intelligent Analysis of System Events for Detecting Multi-Step Cyberattacks: Using Machine Learning Methods, Iskusstvennyj Intellekt i Prinjatie Reshenij, 2023, no. 3, pp. 3—15. DOI: 10.14357/20718594230301 (in Russian).
  3. Kotenko I. V., Levshun D. A. Methods of Intelligent Analysis of System Events for Detecting Multi-Step Cyberattacks: Using Knowledge Bases, Iskusstvennyj Intellekt i Prinjatie Reshenij, 2023, no. 2, pp. 3—14. DOI: 10.14357/20718594230201 (in Russian).
  4. Tekerek A. A Novel Architecture for Web-Based Attack Detection Using Convolution Neural Network, Computers & Security, 2021, vol. 100, article 102096. DOI: 10.1016/j.cose.2020.102096.
  5. Seyyar Y. E., Yavuz A. G., Unver H. M. An Attack Detection Framework Based on BERT and Deep Learning, IEEE Access, 2022, vol. 10, pp. 68633 — 68644. DOI: 10.1109/ACCESS.2022.3185748.
  6. Tadhani J. R., Vekariya V., Sorathiya V. et al. Securing Web Applications against XSS and SQLi Attacks Using a Novel Deep Learning Approach, Scientific Reports, 2024, vol. 14, article 1803. DOI: 10.1038/s41598-023-48845-4.
  7. Xie X., Ren C., Fu Y. et al. SQL Injection Detection for Web Applications Based on Elastic-Pooling CNN, IEEE Access, 2019, vol. 7, pp. 151475—151481. DOI: 10.1109/ACCESS.2019.2947527.
  8. Mokbal F. M. M., Wang D., Imran A. et al. MLPXSS: An Integrated XSS-Based Attack Detection Scheme in Web Applications Using Multilayer Perceptron Technique, IEEE Access, 2019, vol. 7, pp. 100567—100580. DOI: 10.1109/ACCESS.2019.2927417.
  9. Dong H., Kotenko I. Cybersecurity in the AI Era: Analyzing the Impact of Machine Learning on Intrusion Detection, Knowledge and Information Systems, 2025, vol. 67, no. 5, pp. 3915—3966. DOI: 10.1007/s10115-025-02366-w.
  10. Deshpande K. V., Singh J. Weighted Transformer Neural Network for Web Attack Detection Using Request URL, Multimedia Tools and Applications, 2024, vol. 83, no. 15, pp. 43983—44007. DOI: 10.1007/s11042-023-17356-9.
  11. Eremin E. O. A Review of Open Datasets for Detecting Attacks on Web Applications, Mezhdunarodnyj Zhurnal Otkrytyh Infor-macionnyh Tehnologij, 2024, vol. 12, no. 3, pp. 106—113 (in Russian).
  12. Toprak S., Yavuz A. G. Web Application Firewall Based on Anomaly Detection Using Deep Learning, Acta Infologica, 2022, vol. 6, no. 2, pp. 219—244. DOI: 10.26650/acin.1039042.
  13. Singh C., Vijayalakshmi V., Raj H. A Machine Learning Approach for Web Application Vulnerability Detection Using Random Forest, International Journal for Research in Applied Science and Engineering Technology, 2022, vol. 10, no. 12, pp. 2106—2112. DOI: 10.22214/ijraset.2022.48397.
  14. Rawat R., Chouhan M., Garg B. et al. Malware Inputs Detection Approach (Tool) Based on Machine Learning [MIDT-SVM], SSRN Electronic Journal, 2021. DOI: 10.2139/ssrn.3915404.
  15. Zhao C., Si S., Tu T. et al. Deep-Learning Based Injection Attacks Detection Method for HTTP, Mathematics, 2022, vol. 10, no. 16, article 2914. DOI: 10.3390/math10162914.
  16. Gong X., Lu J., Wang Y. et al. CECoR-Net: A Character-Level Neural Network Model for Web Attack Detection, Proceedings of the 2019 IEEE International Conference on Smart Cloud (Smart-Cloud), 2019, pp. 98—103. DOI: 10.1109/SmartCloud.2019.00027.
  17. Tang P., Qiu W., Huang Z. et al. Detection of SQL Injection Based on Artificial Neural Network, Knowledge-Based Systems, 2020, vol. 190, article 105528. DOI: 10.1016/j.knosys.2020. 105528.
  18. Tian Z., Luo C., Qiu J., et al. A Distributed Deep Learning System for Web Attack Detection on Edge Devices, IEEE Transactions on Industrial Informatics, 2020, vol. 16, no. 3, pp. 1963—1971. DOI: 10.1109/TII.2019.2938778.
  19. El Mahdaouy A., Lamsiyah S., Janati Idrissi M. et al. DomURLsBERT: Pre-trained BERT-based Model for Malicious Domains and URLs Detection and Classification, Journal of Network and Systems Management, 2026, vol. 34, no. 2, article 36. DOI: 10.1007/s10922-025-10010-9.
  20. Bacevicius M., Paulauskaite-Taraseviciene A., Zokaityte G. et al. Comparative Analysis of Perturbation Techniques in LIME for Intrusion Detection Enhancement, Machine Learning and Knowledge Extraction, 2025, vol. 7, no. 1, article 21. DOI: 10.3390/make7010021.
  21. Bacevicius M., Paulauskaite-Taraseviciene A. Machine Learning Algorithms for Raw and Unbalanced Intrusion Detection Data in a Multi-Class Classification Problem, Applied Sciences, 2023, vol. 13, no. 12, article 7328. DOI: 10.3390/app13127328.
  22. Kotenko I. V., Sobolev P. S. Detecting Attacks on Web Applications: Analyzing Current Approaches, Actual Problems of Infotelecommunications in Science and Education (APINO 2024): Collection of Scientific Articles of the XIII International Scientific-Technical and Scientific-Methodological Conference, St. Petersburg, 2024, vol. 1, pp. 497—501 (in Russian).
  23. Sureda Riera T., Bermejo Higuera J. R., Bermejo Higuera J. et al. A New Multi-Label Dataset for Web Attacks CAPEC Classification Using Machine Learning Techniques, Computers & Security, 2022, vol. 120, article 102788. DOI: 10.1016/j.cose.2022.102788.
  24. Karacan H., Sevri M. A Novel Data Augmentation Technique and Deep Learning Model for Web Application Security, IEEE Access, 2021, vol. 9, pp. 150781—150797. DOI: 10.1109/AC-CESS.2021.3125785.
  25. Mac H., Truong D., Nguyen L. et al. Detecting Attacks on Web Applications Using Autoencoder, Proceedings of the Ninth International Symposium on Information and Communication Tech- nology (SoICT 2018), Danang City, Viet Nam, 2018, pp. 416—421. DOI: 10.1145/3287921.3287946.