Signatures
-
Default Signatures: This template contains a preconfigured list of over 1,300 signatures, in addition to a complete list of SQL injection keywords, SQL special strings, SQL transform rules, and SQL wildchar characters. It also contains denied patterns for cross-site scripting, and allowed attributes and tags for cross-site scripting. This is a read-only template. You can view the contents, but you cannot add, edit, or delete anything in this template. To use it, you must make a copy. In your own copy, you can enable the signature rules that you want to apply to your traffic, and specify the actions to be taken when the signature rules match the traffic.
-
*Xpath Injection Patterns: This template contains a preconfigured set of literal and PCRE keywords and special strings that are used to detect XPath (XML Path Language) injection attacks.
-
Cenzic
-
Deep Security for Web Apps
-
IBM AppScan Enterprise
-
IBM AppScan Standard.
-
Qualys
-
Qualys Cloud
-
Whitehat
-
Hewlett Packard Enterprise WebInspect
-
Rapid7 Appspider
-
Acunetix
Security protection for your application
-
Negative Security Model: With the negative security model, you use a rich set of preconfigured signature rules to apply the power of pattern matching to detect attacks and protect against application vulnerabilities. You block only what you don’t want and allow the rest. You can add your own signature rules, based on the specific security needs of your applications, to design your own customized security solutions.
-
Hybrid security Model: In addition to using signatures, you can use positive security checks to create a configuration ideally suited for your applications. Use signatures to block what you don’t want, and use positive security checks to enforce what is allowed.
<not blocked>, although the request is blocked by the SQL injection check.
Getting started
-
Add a signature object.
-
You can use the Wizard that prompts you to create the entire Web App Firewall configuration, including adding the profile and policy, selecting and enabling signatures, and specifying actions for signatures and positive security checks. The signatures object is created automatically.
-
You can create a copy of the signatures object from the *Default Signatures template, use a blank template to create a signature with your own customized rules, or add an external format signature. Enable the rules and configure the actions that you want to apply.
-
Configure the target Web App Firewall profile to use this signatures object.
-
Send traffic to validate the functionality
Highlights
-
The Default signatures object is a template. It cannot be edited or deleted. To use it, you must create a copy. In your own copy, you can enable the rules and the desired action for each rule as required for your application. To protect the application, you must configure the target profile to use this signature.
-
Processing signature patterns has overhead. Try to enable only those signatures that are applicable for protecting your application, rather than enabling all signature rules.
-
Every pattern in the rule must match to trigger a signature match.
-
You can add your own customized rules to inspect incoming requests to detect various types of attacks, such as SQL injection or cross-site scripting attacks. You can also add rules to inspect the responses to detect and block leakage of sensitive information such as credit card numbers.
-
You can make a copy of an existing signature object and tweak it, by adding or editing rules and SQL/cross-site scripting patterns, to protect another application.
-
You can use auto-update to download the latest version of the Web App Firewall default rules without need for ongoing monitoring to check for the availability of the new update.
-
A signature object can be used by more than one profile. Even after you have configured one or more profiles to use a signature object, you can still enable or disable signatures or change the action settings. You can manually create and modify your own custom signature rules. The changes apply to all the profiles that are currently configured to use this signature object.
-
You can configure signatures to detect violations in various types of payloads, such as HTML, XML, JSON, and GWT.
-
You can export a configured signatures object and import it to another NetScaler appliance for easy replication of your customized signature rules.