Trap paths, and the error burst banning a client refused too often (closes #115)
check / check (push) Waiting to run
check / check (push) Waiting to run
SWWAF_TRAP_PATHS: a request whose path, as a path rule sees it, is one of them is a clear sign of attack, banned as a ban rule's match is; the ban's notes give its trap_path. Checked after the rate limits, before the rule files. SWWAF_ERROR_BURST_THRESHOLD (default 30, or off): more refusals in a minute after a block or ban rule or a trap path, or for a missing or wrong token, ban the client as a broken limit does. Counted in clients.json's minute_refusals; limit_hit error_burst, notes kind refusals. A token refusal is now the offence token_refused, and smallwebwaf_offences_total counts every kind the history does. Judgement call: the threshold is not lowered by a client's limit percentage. Model: opus-5-5
This commit is contained in:
+18
-10
@@ -1,6 +1,7 @@
|
||||
// Package bans is the ban ledger: the bans smallwebwaf makes on the
|
||||
// netblocks of clients that break a rate limit or a byte limit, show a
|
||||
// clear sign of attack or are listed by the CrowdSec decision list, and
|
||||
// netblocks of clients that break a rate limit, a byte limit or the error
|
||||
// burst, show a clear sign of attack or are listed by the CrowdSec
|
||||
// decision list, and
|
||||
// those an admin makes, with their notes, as the "Bans" section of SPEC.md
|
||||
// describes. The bans are kept in memory, and written to bans.json and
|
||||
// read from it by the state package.
|
||||
@@ -103,10 +104,11 @@ type Notes struct {
|
||||
ASName string `json:"as_name"`
|
||||
Country string `json:"country"`
|
||||
// Kind, Limit, Window and Count are, for a ban for a broken limit,
|
||||
// what the limit was on, "requests" for a rate limit or "bytes" for a
|
||||
// byte limit, the limit that was broken, its window, "minute", "hour"
|
||||
// or "day", and the count reached: the client's requests, or bytes, in
|
||||
// the window, those of the request that broke the limit included.
|
||||
// what the limit was on, "requests" for a rate limit, "bytes" for a
|
||||
// byte limit or "refusals" for the error burst, the limit that was
|
||||
// broken, its window, "minute", "hour" or "day", and the count reached:
|
||||
// the client's requests, bytes or refusals in the window, those of the
|
||||
// request that broke the limit included.
|
||||
// These are what counted toward the ban, and the window is the time
|
||||
// over which they came.
|
||||
Kind string `json:"kind,omitempty"`
|
||||
@@ -120,9 +122,11 @@ type Notes struct {
|
||||
LimitPercent *int64 `json:"limit_percent,omitempty"`
|
||||
LimitPercentSetting string `json:"limit_percent_setting,omitempty"`
|
||||
// RuleID and Target are, for a ban for a clear sign of attack, the id
|
||||
// of the rule file rule that matched, and its target.
|
||||
RuleID string `json:"rule_id,omitempty"`
|
||||
Target string `json:"target,omitempty"`
|
||||
// of the rule file rule that matched, and its target; TrapPath is, for
|
||||
// one for a request for a path in SWWAF_TRAP_PATHS, that path.
|
||||
RuleID string `json:"rule_id,omitempty"`
|
||||
Target string `json:"target,omitempty"`
|
||||
TrapPath string `json:"trap_path,omitempty"`
|
||||
// Reputation is the reputation sources that listed the client when
|
||||
// the request that caused the ban was made, in the order the request
|
||||
// log's reputation names them. It is left out when none did.
|
||||
@@ -311,7 +315,7 @@ func (l *Ledger) WouldBanForLimit(
|
||||
// notes, and returns the ban, and whether it made it, as BanForLimit
|
||||
// does. A first ban lasts AttackBanDuration; once the netblock has had
|
||||
// one that was not lifted, the next is permanent. Its reason is "matched
|
||||
// the rule <RuleID>".
|
||||
// the rule <RuleID>", or "asked for the trap path <TrapPath>".
|
||||
func (l *Ledger) BanForAttack(
|
||||
netblock netip.Prefix, now time.Time, notes Notes,
|
||||
) (Ban, bool) {
|
||||
@@ -382,6 +386,10 @@ func limitReason(notes Notes) string {
|
||||
// attackReason is the reason of a ban for a clear sign of attack, with
|
||||
// notes.
|
||||
func attackReason(notes Notes) string {
|
||||
if notes.TrapPath != "" {
|
||||
return "asked for the trap path " + notes.TrapPath
|
||||
}
|
||||
|
||||
return "matched the rule " + notes.RuleID
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user