Patent attributes
A method and system for configuring a web application firewall (WAF) device. The system includes continuously receiving events of an event log associated with a first web based application; generating for each event a signature using a local sensitive hash function; populating a Markov model based on signatures generated for the events, wherein each node in the Markov model corresponds to a generated signature; generating a first new signature for a first new received event, and a second new signature for a second new received event, wherein the second event is subsequent to the first event; determining a probability based on the Markov model that the second event is subsequent to the first event, by locating a first node corresponding to the first new signature and a second node corresponding to the second new signature; and authorizing a request associated with the second event, in response to determining that the determined probability exceeds a predefined threshold.