SPEC and README: rule set changes, error bursts, admin bans, GeoJS answers (closes #6)
Address the second review of the spec update. The Core Rule Set allows PUT, PATCH and DELETE and the headers git and curl send, inspects only bodies it can read, leaves responses alone, and by default switches off the rules that refuse a code forge's ordinary files, uploads and git traffic. The error burst counts only the sidecar's own refusals. Bans an admin made are never dropped. A limit ban resets the client's counters. GeoJS answers move to their own `lookups.json`. The spec now says which address is the client when every forwarded address is trusted, that the exclusive country list refuses private addresses, which are never sent to GeoJS, what `close` gives behind traefik, and Spamhaus's terms for DROP. Model: opus-5-5
This commit is contained in:
@@ -79,7 +79,8 @@ goes through the candidates one by one.
|
||||
running;
|
||||
- the OWASP Core Rule Set, run by the Coraza engine, refusing the requests
|
||||
it flags;
|
||||
- trap paths and bursts of error responses.
|
||||
- trap paths, and a ban for a client that the rule files or the Core Rule
|
||||
Set refuse again and again.
|
||||
- Bans:
|
||||
- a clear sign of attack, such as a probe for a `.env` file or a scanner's
|
||||
user agent, bans for seven days on the first request, and any further
|
||||
@@ -102,8 +103,8 @@ goes through the candidates one by one.
|
||||
fields, the decision taken and why, AS number and country, and timings.
|
||||
Optionally also sent to a remote syslog server.
|
||||
- Prometheus metrics on their own port.
|
||||
- State (bans with their notes, each client's counters, history and lookup
|
||||
answer, the reputation cache, the alerting state) held in memory and kept in
|
||||
- State (bans with their notes, each client's counters and history, the GeoJS
|
||||
answers, the reputation cache, the alerting state) held in memory and kept in
|
||||
readable JSON files, written regularly and at every stop, so a restart loses
|
||||
nothing. Edit a file, or add a rule file, and the running `smallwebwaf` picks
|
||||
up the change. Nothing is read from disk while serving a request.
|
||||
@@ -131,8 +132,9 @@ For each request `smallwebwaf`:
|
||||
client at once for a clear sign of attack;
|
||||
- forwards it to the app and streams the response back, within the size and time
|
||||
limits;
|
||||
- counts the bytes and any error response, bans the client if it broke a limit,
|
||||
updates its history, sends any alerts that are due, and writes the log line.
|
||||
- counts the bytes and any refusal by the rule files or the Core Rule Set, bans
|
||||
the client if it broke a limit, updates its history, sends any alerts that are
|
||||
due, and writes the log line.
|
||||
|
||||
A minimal deployment beside an app in docker-compose. `UPSTREAM_URL` is the only
|
||||
setting:
|
||||
@@ -204,6 +206,11 @@ request. GeoJS publishes no rate limit but may block a caller it thinks asks too
|
||||
much; while it is not answering, new visitors count as coming from an unknown
|
||||
country, which `EXCLUSIVELY_ALLOWED_COUNTRIES` refuses.
|
||||
|
||||
Neither source can place a private address, so a client on one, such as a
|
||||
visitor on your local network, another container or your monitoring, has no
|
||||
country: `EXCLUSIVELY_ALLOWED_COUNTRIES` refuses it unless you list it in
|
||||
`ALLOW_NETS`. Such addresses are never sent to GeoJS.
|
||||
|
||||
## Documents
|
||||
|
||||
- [`SPEC.md`](SPEC.md): the design.
|
||||
|
||||
Reference in New Issue
Block a user