# Understanding Application Schema Profiles: A Positive Security Approach for Web Applications
## Introduction
Modern web applications face an increasingly sophisticated threat landscape. Attackers now leverage large language models to craft intelligent, adaptive payloads that can probe applications, mutate attack techniques based on feedback, and automate exploitation at scale. Traditional detection methods—while still essential—rely on identifying known attack patterns, leaving gaps for novel or obfuscated threats.
A new paradigm is emerging: **positive security**. Instead of trying to recognize what an attack looks like, positive security defines what legitimate traffic should look like and blocks anything that deviates from that baseline. Application Schema Profiles represent a significant advancement in this approach, enabling teams to learn the expected structure of their HTTP requests and automatically validate every interaction against that learned baseline.
## How Application Schema Profiles Work
At its core, this technology works by continuously analyzing the structure and format of incoming HTTP requests to understand what “normal” looks like for a given application. The process unfolds in several stages:
### Learning Phase
The system ingests live traffic and builds a model of expected request patterns for each configured operation—defined by its HTTP method, hostname pattern, and path pattern. During this phase, it examines path variables, query parameters, headers, cookies, and request body structures (both JSON and form-encoded). For each field, it learns the expected data type (integer, string, boolean, array, UUID, or enum), acceptable value ranges, string length constraints, and character classes.
A minimum threshold of 1,000 successful requests within the preceding seven days is required to identify field structures, while 10,000 requests are needed to establish data boundaries accurately. The learning process runs automatically on a weekly basis, ensuring profiles evolve alongside the application.
### Validation Phase
Once a profile is established, an always-on validation layer is deployed on live traffic. Every incoming request is evaluated against the learned schema, and results are attached as metadata without taking action by default. This allows teams to observe the impact of validation before implementing any blocking rules.
### Enforcement Phase
When a team is ready to enforce the policy, they can create security rules that act on the validation signal. Rules can be scoped to entire applications, specific paths, individual operations, or even particular fields. The system provides detailed metadata—including exactly where a violation occurred and which parameters failed validation—enabling precise, targeted enforcement.
## Key Features and Capabilities
### Comprehensive Field Coverage
Schema Profiles support validation across multiple request components:
– Path variables
– Query parameters
– Headers and cookies
– JSON request bodies
– Form-encoded request bodies
The system recognizes and validates integers, strings, UUIDs, arrays, and enums with up to three values.
### Detailed Violation Classification
When a request fails validation, it is classified according to one of ten distinct reasons, including type mismatches, values outside a learned range, invalid formats, and unexpected characters. This granularity helps teams quickly understand whether a violation represents a legitimate change or a potential attack.
### Continuous Learning
Profiles are not static. They update weekly as application traffic patterns evolve, adding new fields that appear and removing fields that are no longer observed. Teams can also pin and export learned schemas in OpenAPI v3 format for use in other validation systems.
### Analytics and Visibility
A dedicated Profile Analysis section within security analytics dashboards provides visibility into conforming and non-conforming traffic trends. Teams can drill into individual violations, review sampled logs, and understand which fields were affected and why validation failed—all without impacting live traffic.
### LLM-Powered Contextualization
Beyond structural validation, intelligent analysis can be applied to learned profiles to extract semantic meaning from field names and operation paths. This capability identifies relationships between fields across different parts of an application, highlights business-critical operations, and surfaces risk indicators such as unusual data transfer patterns or reconnaissance behavior. These insights help security teams prioritize where to deploy enforcement first.
## Getting Started
The feature is available through a closed beta program for enterprise customers. Those with existing API security tooling have immediate access as this technology extends their schema learning and validation capabilities to web applications.
New adopters should begin by deploying profiles in observation mode, reviewing validation results in analytics dashboards, and gradually introducing enforcement rules starting with the highest-risk operations and fields.
## Frequently Asked Questions
**What is the difference between positive security and traditional threat detection?**
Traditional threat detection works by identifying requests that match known attack signatures or anomalous behavior patterns. Positive security, by contrast, builds a model of what legitimate requests should look like and blocks anything that falls outside that model. This approach is proactive rather than reactive, preventing attacks that have never been seen before simply because they don’t conform to expected patterns.
**What happens if a legitimate request doesn’t conform to the learned profile?**
Not all non-conforming requests are malicious. Application releases, new client implementations, or unusual but valid requests can introduce differences. The recommended approach is to start in observation mode, review violations in the analytics dashboard, and only enable enforcement once the team is confident in the profile’s accuracy. The system also supports uploading manually defined schemas alongside learned ones for fine-grained control.
**Can I exclude certain fields or parameters from enforcement?**
Yes. The validation metadata includes detailed fields that identify exactly which parameters violated the profile and which are undeclared (new parameters not present in the learned schema). This allows teams to create rules that target specific fields for enforcement while leaving others untouched.
**What request formats are currently supported?**
Schema Profiles support paths, query parameters, headers, cookies, JSON request bodies, and form-encoded request bodies. Currently unsupported formats include multipart forms, GraphQL, and XML.
**How does the system handle repeated parameter names?**
The validator checks every individual value when a parameter name appears multiple times in a request. However, it does not enforce parameter uniqueness—multiple values for the same parameter are allowed if they conform to the expected type and format.
**Does the system learn required parameters or block requests with new parameters?**
By default, the system does not learn or enforce required parameters, nor does it block requests solely because they include a new parameter. This design choice ensures that legitimate traffic introducing new fields isn’t inadvertently blocked. Teams can use the undeclared parameters metadata to create custom rules if they wish to adopt a stricter posture.
**Is this feature available for all customers?**
Currently, the feature is available through a closed beta by invitation. Enterprise customers with API Security have immediate access, while other customers can request access through their account team. Availability in production environments is subject to invitation and feedback cycles.
## Conclusion
Application Schema Profiles represent a meaningful evolution in web application security. By shifting from reactive detection to proactive, structure-based validation, teams can dramatically reduce their attack surface without relying on constant signature updates or patch cycles. The combination of automated learning, continuous validation, detailed analytics, and intelligent contextualization provides a comprehensive framework for deploying positive security in real-world environments.
As threat actors increasingly weaponize AI to craft sophisticated attacks, approaches that define and enforce what “good” traffic looks like will become essential components of any robust security posture. This technology lays the foundation for that future, empowering teams to stay ahead of emerging threats—including zero-day exploits—by focusing on the integrity of their applications’ expected behavior.
Thank you for reading



