The Core Rule Set, run by Coraza, on each request's method, URL and headers (closes #25)
check / check (push) Waiting to run
check / check (push) Waiting to run
Coraza v3.8.1 runs the Core Rule Set 4.25.0 (coraza-coreruleset v4.25.0) after the rule files, with the six changes and the default SWWAF_WAF_DISABLED_RULES that SPEC.md gives; no body, no response. The parameter names in the third and fourth changes are matched in any case, as Coraza does. SWWAF_WAF_DISABLED_RULES refuses 900000 to 900999, smallwebwaf's own rules. A request with more than 1000 query parameters adds 5 (rule 900300). In block mode a match is refused with 403, an offence counted toward the error burst; in detect mode it is let through. Both log waf_rule_ids, waf_score and duration_waf, raise waf_block, and count smallwebwaf_waf_matches_total. Judgement call: waf_block is raised in block mode too. Deviation: no engine-error path; with no body read, Coraza cannot fail. Model: opus-5-5
This commit was merged in pull request #121.
This commit is contained in:
@@ -124,11 +124,12 @@ type Offences struct {
|
||||
// Limit is its requests that broke a rate limit, a byte limit or the
|
||||
// error burst, Attack those that were a clear sign of attack, a match
|
||||
// of a ban rule or a request for a trap path, RuleBlocked those a block
|
||||
// rule refused, and TokenRefused those refused for a missing or wrong
|
||||
// token.
|
||||
// rule refused, WAFBlocked those the Core Rule Set refused, and
|
||||
// TokenRefused those refused for a missing or wrong token.
|
||||
Limit int64 `json:"limit"`
|
||||
Attack int64 `json:"attack"`
|
||||
RuleBlocked int64 `json:"rule_blocked"`
|
||||
WAFBlocked int64 `json:"waf_blocked"`
|
||||
TokenRefused int64 `json:"token_refused"`
|
||||
}
|
||||
|
||||
@@ -148,11 +149,13 @@ type Request struct {
|
||||
ResponseBytes int64
|
||||
// BrokeLimit is true for a request that broke a rate limit, a byte
|
||||
// limit or the error burst, Attack for one that matched a ban rule or
|
||||
// asked for a trap path, RuleBlocked for one a block rule refused, and
|
||||
// TokenRefused for one refused for a missing or wrong token.
|
||||
// asked for a trap path, RuleBlocked for one a block rule refused,
|
||||
// WAFBlocked for one the Core Rule Set refused, and TokenRefused for
|
||||
// one refused for a missing or wrong token.
|
||||
BrokeLimit bool
|
||||
Attack bool
|
||||
RuleBlocked bool
|
||||
WAFBlocked bool
|
||||
TokenRefused bool
|
||||
}
|
||||
|
||||
@@ -236,10 +239,10 @@ func (l *Limiter) CountBytes(
|
||||
}
|
||||
|
||||
// CountRefusal counts a request from client at now that smallwebwaf
|
||||
// refused after a rule file match or for a missing or wrong token, and
|
||||
// reports whether the client's refusals in the minute that ends at now,
|
||||
// this one included, are more than threshold, which breaks the error
|
||||
// burst, and the hit.
|
||||
// refused after a rule file or Core Rule Set match or for a missing or
|
||||
// wrong token, and reports whether the client's refusals in the minute
|
||||
// that ends at now, this one included, are more than threshold, which
|
||||
// breaks the error burst, and the hit.
|
||||
func (l *Limiter) CountRefusal(
|
||||
client netip.Prefix, now time.Time, threshold int64,
|
||||
) (Hit, bool) {
|
||||
@@ -304,6 +307,10 @@ func (l *Limiter) AddToHistory(client netip.Prefix, now time.Time, r Request) {
|
||||
h.Offences.RuleBlocked++
|
||||
}
|
||||
|
||||
if r.WAFBlocked {
|
||||
h.Offences.WAFBlocked++
|
||||
}
|
||||
|
||||
if r.TokenRefused {
|
||||
h.Offences.TokenRefused++
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user