Problem
Web application firewall rule laboratory that runs attack payloads and legitimate traffic through three rule generations, showing how literal keyword matching is defeated by inline comments and why parameter context is what finally removes the false positives.