ML WAF
[!NOTE] The ML WAF needs a valid license. Without one, the Machine Learning pages are hidden. The ML WAF adds a machine-learning model next to the rule-based WAF. It scores every request from 0.0 (benign) to 1.0 (malicious) and learns what normal traffic looks like for each of your services, so it can catch attacks the rules don't recognise. It runs after the rule-based WAF. Turn it on for a service Open the service and go to ML Security. Choose a mode: Training (default): observe and learn. Detections are logged but nothing is blocked. Enforcement: block requests that score above the threshold, once the service has learned enough. Blocking is phased in as the model learns a service's traffic. A service starts with detection only, then blocks only very high scores (above 0.95), then high scores (above 0.85), and finally applies full blocking. Each level needs a minimum number of requests and a minimum time. The ML Dashboard shows each service's learning level. Per-service options include a Score Threshold Override, ML Bypass IPs / CIDRs, ML Bypass Paths, and Trusted Training IPs / CIDRs: sources whose traffic is trusted for learning. Global settings Under Settings > ML Security: Global Score Threshold (default 0.642): requests scoring above this are flagged or blocked. Tuning Zone Lower Bound and Upper Bound (defaults 0.35 and 0.65): requests scoring in this range are grouped for human review. Max Body Inspect Size: request bodies larger than this skip ML scoring. The rule-based WAF still inspects them. Pages Page Use Machine Learning > ML Dashboard Model information and performance, and each service's ML status and learning level. Security Events > ML Events Requests the model flagged, with score, confidence and verdict. Machine Learning > ML Tuning Classify ambiguous request groups as benign or malicious to improve the model. Groups expire after 72 hours. Machine Learning > ML Whitelist Exempt a service path and method from ML scoring.
NullWard documentation