Stopping web attacks inline
CSIC 2010. 91.69% of attacking sources blocked by their third request; no genuine source blocked.
Evidence
Every security experiment, with its datasheet and its data. Each pass mark was set before the run.
CSIC 2010. 91.69% of attacking sources blocked by their third request; no genuine source blocked.
OWASP Core Rule Set. Level untuned; 2.4 times its blocking after learning.
ADFA-LD. Attacks ranked above normal operation at AUC 0.9246, learned from normal behaviour only.
AIT Log Data Set. AUC 0.9604 across four mail servers, each above 0.95 on its own.
Server Machine Dataset. AUC 0.7747; 23 of 28 machines at 0.70 or better.
Replica portal. An agent blocked by its third request; no normal session affected.
More on the second datasheet page, and live on the showcases.