Dual-Stream Detection of HTTP Injection Attacks: A Hybrid Architecture Combining ModernBERT and Character-Level CNNs
- 1 School of Computational and Communication Science and Engineering, Nelson Mandela African Institution of Science and Technology (NM-AIST), Arusha, Tanzania
- 2 School of Computational and Communication Science and Engineering, Nelson Mandela African Institution of Science and Technology (NM-AIST), Arusha, Tanzania
- 3 School of Computational and Communication Science and Engineering, Nelson Mandela African Institution of Science and Technology (NM-AIST), Arusha, Tanzania
Abstract
Web applications remain critically vulnerable to injection attacks, including SQL Injection (SQLi), OS Command Injection, and Cross-Site Scripting (XSS) among others, which exploit the semantic gap between user-supplied input and executable code. Traditional Web Application Firewalls (WAFs) rely on signature-based pattern matching, rendering them susceptible to evasion through payload obfuscation. While Transformer-based language models excel at capturing long-range contextual dependencies and have demonstrated promise in detecting malicious intent, they alone may not fully exploit the fine-grained character-level patterns that distinguish obfuscated attack payloads. This paper proposes a Dual-Stream Hybrid Architecture that combines the contextual reasoning capabilities of Modern Bidirectional Encoder Representations from Transformers (ModernBERT), a state-of-the-art encoder supporting 8192 token sequences, with a Character-Level 1D Convolutional Neural Network (CNN) optimized for morphological pattern recognition. The semantic stream captures high-level payload intent, while the syntactic stream detects low-level structural signatures of obfuscation techniques (e.g., URL encoding, hexadecimal evasion, comment injection). Experiments on a composite dataset of ~93,500 HTTP requests, aggregated from public payload repositories, synthetic attack campaigns generated with SQLMap and XSStrike on vulnerable web applications, live honeypot traffic captured via T-Pot (SNARE/Tanner), and benign browsing sessions simulated with Playwright, demonstrate that our hybrid approach achieves 98.7% accuracy and 98.3% F1-score, outperforming standalone ModernBERT and CNN baselines by 2.4% and 8.6% respectively.
- OWASP Foundation (2025) Introduction-OWASP Top 10. https://owasp.org/Top10/2025/0x00_2025-Introduction
- Demetrio, L., Valenza, A., Costa, G. and Lagorio, G. (2020) WAF-A-MoLE: Evading Web Application Firewalls through Adversarial Machine Learning. Proceedings of the 35 th Annual ACM Symposium on Applied Computing , Brno, 30 March-3 April 2020, 1745-1752. https://doi.org/10.1145/3341105.3373962
- Seyyar, Y.E., Yavuz, A.G. and Unver, H.M. (2022) An Attack Detection Framework Based on BERT and Deep Learning. IEEE Access , 10, 68633-68644. https://doi.org/10.1109/access.2022.3185748
- Thakur, J. and Rane, K. (2023) Using Deep Learning to Perform Payload Classification. In: Saini, H.S., Sayal, R., Govardhan, A. and Buyya, R., Eds., Innovations in Computer Science and Engineering , Springer, 183-199. https://doi.org/10.1007/978-981-19-7455-7_14
- Schuster, M. and Nakajima, K. (2012) Japanese and Korean Voice Search. 2012 IEEE International Conference on Acoustics , Speech and Signal Processing ( ICASSP ), Kyoto, 25-30 March 2012, 5149-5152. https://doi.org/10.1109/icassp.2012.6289079
- Sennrich, R., Haddow, B. and Birch, A. (2016) Neural Machine Translation of Rare Words with Subword Units. Proceedings of the 54 th Annual Meeting of the Association for Computational Linguistics ( Volume 1: Long Papers ), Berlin, 7-12 August 2016, 1715-1725. https://doi.org/10.18653/v1/p16-1162
- Warner, B., Chaffin, A., Clavié, B., Weller, O., Hallström, O., Taghadouini, S., et al. (2025) Smarter, Better, Faster, Longer: A Modern Bidirectional Encoder for Fast, Memory Efficient, and Long Context Finetuning and Inference. Proceedings of the 63 rd Annual Meeting of the Association for Computational Linguistics ( Volume 1: Long Papers ), Vienna, 27 July-1 August 2025, 2526–2547. https://doi.org/10.18653/v1/2025.acl-long.127
- Guimaraes, B.D.C. and Stampar, M. (2026) Sqlmap. https://sqlmap.org/
- Bijjou, K. (2026) WAFNinja. https://github.com/khalilbijjou/WAFNinja
- Saleem Raja, A., Vinodini, R. and Kavitha, A. (2021) Lexical Features Based Malicious URL Detection Using Machine Learning Techniques. Materials Today : Proceedings , 47, 163-166. https://doi.org/10.1016/j.matpr.2021.04.041
- Sahoo, D., Liu, C. and Hoi, S.C.H. (2017) Malicious URL Detection Using Machine Learning: A Survey. arXiv: 1701.07179. https://arxiv.org/abs/1701.07179
- Liu, Y. and Dai, Y. (2024) Deep Learning in Cybersecurity: A Hybrid BERT-LSTM Network for SQL Injection Attack Detection. IET Information Security , 2024, Article ID: 5565950. https://doi.org/10.1049/2024/5565950