inklap

HYBRID CYBERSECURITY STRATEGIES FOR WEB APPLICATIONS USING ARTIFICIAL INTELLIGENCE

Kostiantyn Savchuk · Cybersecurity: Education, Science, Technique · 2025

Web applications form the foundation of most digital services and remain primary targets for SQLi, XSS, CSRF, IDOR, SSRF, and DDoS attacks. The expansion of cloud technologies and API-driven architectures increases risk, while artificial intelligence (AI) offers new opportunities for detection and response. This article examines a reproducible security framework that maps the OWASP Top 10 risks to protocol-dependent control measures and supplementary AI signals, clarifying where AI adds the greatest value without incurring excessive operational costs. The study presents a structured review of OWASP recommendations, industry reports, and academic research (including HTTP request embeddings, online anomaly detection, and graph neural networks). It defines comparative criteria emphasizing attack coverage, precision-recall for imbalanced data, false positive rate, and detection latency—illustrated through practical examples of “baseline controls + AI monitoring.” The paper aligns common web threats with fundamental protection elements (validation, CSP, parameterized queries, MFA, SameSite and short-lived tokens, WAF, TLS/HSTS, and egress restrictions) and AI applications (HTTP embeddin

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً