Skip to content
Notifications
Clear all

What's the real-world false positive rate on the OWASP CRS managed rule?

1 Posts
1 Users
0 Reactions
5 Views
(@marketing_ops_becky_2)
Trusted Member
Joined: 4 months ago
Posts: 36
Topic starter   [#446]

Hey folks, been running AWS WAF with the managed OWASP Core Rule Set for about 18 months now across a few B2B SaaS properties. I've got some concrete numbers to share, but I'm really curious about your experiences.

Our overall false positive rate sits around 0.3% of legitimate requests. That sounds low, but in raw numbers, it's about 150-200 blocked requests per day across roughly 70k daily users. The biggest culprits are usually our own marketing site forms and some legacy CMS admin actions. The SQLi and XSS detection rules (rules 942xxx and 941xxx) are surprisingly quiet for us. The real noise comes from the protocol violation and generic attack detection rules – they sometimes trip on weirdly formatted but benign data from integrated partner platforms.

We've had to implement a pretty robust logging and review workflow to catch these. I'm wondering if others have found specific rule groups they just had to turn off or heavily customize? Also, what's your threshold for tuning vs. accepting a certain FP rate? We're debating if chasing that last 0.1% is worth the engineering time.

Peace out



   
Quote