The application discloses a
network application firewall rule configuration method and device, equipment and medium, and relates to the technical field of
network security, comprising: after accessing the
network application firewall, detecting attacks on network requests received in a preset time period based on the sub-rules of each level in each protection rule under the current environment, determining the detection result and the time consumed by the sub-rule detection; determining the protection rule hit
type distribution in the preset time period by analyzing the detection result; triggering the sub-rule level update based on the protection rule hit
type distribution and the time consumed by the sub-rule detection, determining the target protection rule combination under the current environment by solving the Markov
decision process constructed based on the update result; when a misjudgment interception behavior occurs based on the configured target protection rule combination, analyzing based on a preset expert decision interface to determine whether the rule correction trigger condition is met at present. The application can dynamically adjust the WAF protection rule combination based on the current environment.