Bot Detection
-
Java Script must be enabled in the client browser.
-
Does not work for XML responses.
How to upgrade your appliance to NetScaler CLI-based bot management configuration
-
After upgrading to the latest version connect to the upgrade tool "upgrade_bot_config.py" by using the following commandAt the command prompt, type:
shell "/var/python/bin/python /netscaler/upgrade_bot_config.py > /var/bot_upgrade_commands.txt" -
Run the configuration using the following command.At the command prompt, type:
batch -f /var/bot_upgrade_commands.txt -
Save the upgraded configuration.
save ns config
Configure NetScaler CLI-based bot management
-
Enable bot management
-
Import bot signature
-
Add bot profile
-
Bind bot profile
-
Add bot policy
-
Bind bot policy
-
Configure bot settings
Enable bot management
enable ns feature Bot
Import bot signature
import bot signature [<src>] <name> [-comment <string>] [-overwrite]
src - Local path name, or URL (protocol, host, path, and file name). Maximum Length: 2047.
name - Name of the bot signature file object. This is a mandatory argument. Maximum Length: 31.
comment - Description about the signature file object. Maximum Length: 255.
overwrite - Action that overwrites the existing file.
overwrite option to update the content in the signature file. Alternately, use the update bot signature <name> command to update the signature file on the NetScaler appliance.
Example
import bot signature http://www.example.com/signature.json signaturefile -comment commentsforbot –overwrite
update bot signature <name> command to update the signature file in the NetScaler appliance.
Add bot profile
addCookieFlags is added to the add bot profile and set bot profile commands.
add bot profile <name> [-signature <string>] [-errorURL <string>] [-trapURL <string>] [-whiteList ( ON | OFF )] [-blackList ( ON | OFF )] [-rateLimit ( ON | OFF )] [-deviceFingerprint ( ON | OFF )] [-deviceFingerprintAction ( none | log | drop | redirect | reset | mitigation )] [-ipReputation ( ON | OFF )] [-trap ( ON | OFF )] [-addCookieFlags ([**none**] | [**httpOnly**] | [**secure**] | [**all**])]
addCookieFlags - Add flags to cookies during transformation. Specify any one of the following:
-
None - Do not add flags to cookies.
-
HTTP only - Add the HttpOnly flag to all cookies. With this flag set, browsers that support the HttpOnly flag prevent scripts from accessing cookies. The default.
-
Secure - Add the Secure flag to cookies that are to be sent only over an SSL connection. Browsers that support the secure flag do not send the flagged cookies over an insecure connection.
-
All - Add the HttpOnly flag to all cookies, and the Secure flag to cookies that are to be sent only over an SSL connection.
add bot profile profile1 -signature signature -errorURL http://www.example.com/error.html -trapURL /trap.html -whitelist ON -blacklist ON -ratelimit ON -deviceFingerprint ON -deviceFingerprintAction drop -ipReputation ON -trap ON -addCookieFlags secure
Bind bot profile
bind bot profile <name> | (-ipReputation [-category <ipReputationCategory>] [-enabled ( ON | OFF )] [-action ( none | log | drop | redirect | reset | mitigation )] [-logMessage <string>]
bind bot profile profile5 -ipReputation -category BOTNET -enabled ON -action drop -logMessage message
Add bot policy
add bot policy <name> -rule <expression> -profileName <string> [-undefAction <string>] [-comment <string>] [-logAction <string>]
Name- Name for the bot policy. Must begin with a letter, number, or the underscore character (\_), and must contain only letters, numbers, and the hyphen (-), period (.) pound (#), space ( ), at (@), equals (=), colon (:), and underscore characters. Can be changed after the bot policy is added.
Rule- An expression that the policy uses to determine whether to apply the bot profile on the specified request. This is a mandatory argument. Maximum Length: 1499
profileName- Name of the bot profile to apply if the request matches this bot policy. This is a mandatory argument. Maximum Length: 127
undefAction- Action to perform if the result of policy evaluation is undefined (UNDEF). An UNDEF event indicates an internal error condition. Maximum Length: 127
Comment- Description about this bot policy. Maximum Length: 255
logAction - Name of the log action to use for requests that match this policy. Maximum Length: 127
add bot policy pol1 –rule "HTTP.REQ.HEADER(\"header\").CONTAINS(\"custom\")" - profileName profile1 -undefAction drop –comment commentforbotpolicy –logAction log1
Bind bot policy global
bind bot global -policyName <string> -priority <positive_integer> [-gotoPriorityExpression <expression>][-type ( REQ_OVERRIDE | REQ_DEFAULT )] [-invoke (-labelType ( vserver | policylabel ) -labelName <string>) ]
bind bot global –policyName pol1 –priority 100 –gotoPriorityExpression NEXT -type REQ_OVERRIDE
Bind bot policy to a virtual server
bind lb vserver <name>@ ((<serviceName>@ [-weight <positive_integer>] ) | <serviceGroupName>@ | (-policyName <string>@ [-priority <positive_integer>] [-gotoPriorityExpression <expression>]
bind lb vserver lb-server1 –policyName pol1 –priority 100 –gotoPriorityExpression NEXT -type REQ_OVERRIDE
Configure bot settings
set bot settings [-defaultProfile <string>] [-javaScriptName <string>] [-sessionTimeout <positive_integer>] [-sessionCookieName <string>] [-dfpRequestLimit <positive_integer>] [-signatureAutoUpdate ( ON | OFF )] [-signatureUrl <URL>] [-proxyServer <ip_addr|ipv6_addr|*>] [-proxyPort <port|*>]
defaultProfile - Profile to use when a connection does not match any policy. Default setting is " ", which sends unmatched connections back to the NetScaler without attempting to filter them further. Maximum Length: 31
javaScriptName - Name of the JavaScript that the BotNet feature uses in response. Must begin with a letter or number, and can consist of from 1 to 31 letters, numbers, and the hyphen (-) and underscore (\_) symbols. The following requirement applies only to the NetScaler CLI: If the name includes one or more spaces, enclose the name in double or single quotation marks (for example, "my cookie name" or 'my cookie name'). Maximum Length: 31
sessionTimeout - Session times out, in seconds, after which a user session is terminated.
Minimum value - 1, Maximum value: 65535
sessionCookieName - Name of the SessionCookie that the BotNet feature uses it for tracking. Must begin with a letter or number, and can consist of from 1 to 31 letters, numbers, and the hyphen (-) and underscore (_) symbols. The following requirement applies only to the NetScaler CLI: If the name includes one or more spaces, enclose the name in double or single quotation marks (for example, "my cookie name" or 'my cookie name'). Maximum Length: 31
dfpRequestLimit - Number of requests to allow without bot session cookie if device fingerprint is enabled. Minimum value: 1, Maximum Value: 4294967295
signatureAutoUpdate - Flag used to enable/disable bot auto update signatures. Possible values: ON, OFF. Default value: OFF
signatureUrl - URL to download the bot signature mapping file from the server. Default value: https://nsbotsignatures.s3.amazonaws.com/BotSignatureMapping.json. Maximum Length: 2047
proxyServer - Proxy Server IP to get updated signatures from AWS.
proxyPort - Proxy Server Port to get updated signatures from AWS. Default value: 8080
proxyUsername - User name to authenticate to the proxy server for downloading signature updates.
proxyPassword – Password to authenticate to the proxy server for downloading signature updates.
set bot settings –defaultProfile profile1 –javaScriptName json.js –sessionTimeout 1000 –sessionCookieName session -proxyServer 10.102.30.112 -proxyPort 3128 -proxyUsername defaultuser -proxyPassword defaultPassword
Configuring bot management by using NetScaler GUI
-
Enable bot management feature
-
Configure bot management settings
-
Clone NetScaler® bot default signature
-
Import NetScaler bot signature
-
Configure bot profile and signature settings
-
Create bot profile
-
Create bot policy
Enable bot management feature
-
On the navigation pane, expand System and then click Settings > Configure Advanced Features.
-
On the Configure Advanced Features page, select the NetScaler Bot Management checkbox.
-
Click OK.
Configure bot management settings
-
Navigate to Security > NetScaler bot Management.
-
In the details pane, under Settings click Change NetScaler bot Management Settings.
-
In the Configure NetScaler bot Management Settings, set the following parameters.
-
Default Profile. Select a bot profile.
-
JavaScript Name. Name of the JavaScript file that bot management uses in its response to the client.
-
Session Timeout. Timeout in seconds after which the user session is terminated.
-
Session Cookie. Name of the session cookie that the bot management system uses for tracking.
-
Device Fingerprint Request Limit. Number of requests to allow without a bot session cookie, if device fingerprint is enabled.
-
Proxy Server - Proxy server IP address from where the latest signatures are uploaded.
-
Proxy Port – Port number of machine from where the latest signatures are uploaded.
-
Proxy Username – User name for the authentication of the proxy server
-
Proxy Password - Password for the authentication of the proxy server.
Note:Proxy User name and the Proxy Password fields are enabled if the Proxy Server and the Proxy Port fields are configured. -
-
Click OK.
Clone bot signature file
-
Navigate to Security > NetScaler Bot Management and Signatures.
-
In the NetScaler Bot Management Signatures page, select the default bot signatures record and click Clone.
-
In the Clone Bot Signature page, enter a name and edit the signature data.
-
Click Create.
Import bot signature file
-
Navigate to Security > NetScaler Bot Management and Signatures.
-
On the NetScaler Bot Management Signatures page, import the file as URL, File, or text.
-
Click Continue.
-
On the Import NetScaler Bot Management Signature page, set the following parameters.
-
Name - Name of the bot signature file.
-
Comment - Brief description about the imported file.
-
Overwrite - Select the checkbox to allow overwriting of data during file update.
-
Signature Data - Modify signature parameters
-
-
Click Done.
Configure IP reputation
-
Navigate to Security > NetScaler bot Management and Profiles.
-
On the NetScaler bot Management Profiles page, select a profile and click Edit.
-
On the NetScaler bot Management Profile page, go to the Profile Settings section and click IP Reputation.
-
On the IP Reputation section, set the following parameters:
-
Enabled. Select the checkbox to validate incoming bot traffic as part of the detection process.
-
Configure Categories. You can use the IP reputation technique for incoming bot traffic under different categories. Based on the configured category, you can drop or redirect the bot traffic. Click Add to configure a malicious bot category.
-
In the Configure NetScaler bot Management Profile IP Reputation Binding page, set the following parameters:
-
Category. Select a Webroot IP reputation bot category to validate a client request as a malicious IP address.
-
IP_BASED - This category checks whether the client IP address (IPv4 and IPv6) is malicious or not.
-
BOTNET - This category includes Botnet C&C channels, and infected zombie machines controlled by Bot master.
-
SPAM_SOURCES - This category includes tunneling spam messages through a proxy, anomalous SMTP activities, and forum spam activities.
-
SCANNERS - This category includes all reconnaissance such as probes, host scan, domain scan, and password brute force attack.
-
DOS - This category includes DOS, DDOS, anomalous sync flood, and anomalous traffic detection.
-
REPUTATION - This category denies access from IP addresses (IPv4 and IPv6) currently known to be infected with malware. This category also includes IP addresses with average low Webroot Reputation Index score. Enabling this category prevents access from sources identified to contact malware distribution points.
-
PHISHING - This category includes IP addresses (IPv4 and IPv6) hosting phishing sites and other kinds of fraud activities such as ad click fraud or gaming fraud.
-
PROXY - This category includes IP addresses (IPv4 and IPv6) providing proxy services.
-
NETWORK - IPs providing proxy and anonymization services including The Onion Router aka TOR or dark net.
-
MOBILE_THREATS - This category checks the client IP address (IPv4 and IPv6) with the list of addresses harmful for mobile devices.
-
-
Category. Select a Webroot public cloud service provider category to validate a client request is a public cloud IP address.
-
AWS - This category checks client IP address with list of public cloud addresses from AWS.
-
GCP - This category checks client IP address with list of public cloud addresses from the Google Cloud Platform.
-
AZURE - This category checks client address with list of public cloud addresses from Azure.
-
ORACLE - This category checks client IP address with list of public cloud addresses from Oracle
-
IBM - This category checks client IP address with list of public cloud addresses from IBM.
-
SALESFORCE - This category checks client IP address with list of public cloud addresses from Salesforce.
Possible values for Webroot IP reputation bot category: IP, BOTNETS, SPAM_SOURCES, SCANNERS, DOS, REPUTATION, PHISHING, PROXY, NETWORK, MOBILE_THREATS.Possible values for Webroot public cloud service provider category: AWS, GCP, AZURE, ORACLE, IBM, SALESFORCE. -
-
Enabled. Select the checkbox to validate the IP reputation signature detection.
-
Bot action. Based on the configured category, you can assign no action, drop, redirect, or mitigation action.
-
Log. Select the checkbox to store log entries.
-
Log Message. Brief description of the log.
-
Comments. Brief description about the bot category.
-
-
-
Click OK.
-
Click Update.
-
Click Done.

-
Navigate to Security > NetScaler bot Management > Change NetScaler bot Management Settings
-
Change the Default Nonintrusive Profile to BOT_BYPASS.
Configure bot static signatures
-
On the navigation pane, expand Security > NetScaler Bot Management > Signatures.
-
On the NetScaler Bot Management Signatures page, select a signature file and click Edit.
-
On the NetScaler Bot Management Signature page, go to the Signature Settings section and click Bot Signatures.
-
In the Bot Signatures section, set the following parameters:
-
Configure Static Signatures. This section has a list of bot static signature records. You can select a record and click Edit to assign a bot action to it.
-
Click OK.
-
-
Click Update Signature.
-
Click Done.
Bot static signature delineation
-
Enable Selected - Enable all the selected signature rules.
-
Disable Selected - Disable all the selected signatures rules.
-
Drop Selected - Select the "Drop" action to all the selected signature rules.
-
Redirect Selected - Apply the "Redirect" action to all the selected signature rules.
-
Reset Selected - Apply the "Reset" action to all the selected signature rules.
-
Log Selected - Apply the "Log" action to all the selected signature rules.
-
Remove Drop Selected - Unset the drop action to all the selected signature rules.
-
Remove Redirect Selected - Unset the redirect action to all the selected signature rules.
-
Remove Reset Selected - Unset the reset action to all the selected signature rules.
-
Remove Log Selected - Unset the log action to all the selected signature rules.
-
Action - Sort based on bot action.
-
Category - Sort based on bot category.
-
Developer - Sort based on the host company publisher.
-
Enabled - Sort based on signature rules that are enabled.
-
Id - Sort based on signature rule ID.
-
Log - Sort based on signature rules that have logging enabled.
-
Name - Sort based on signature rule name.
-
Type - Sort based on signature type.
-
Version - Sort based on signature rule version.
Search bot static signature rules based on action and category types by using the NetScaler GUI
-
Navigate to Security > NetScaler Bot Management > Signature.
-
In the details page, click Add.
-
In the NetScaler Bot Management Signatures page, click edit in the Static Signature section.
-
In the Configure Static Signature section, select a signature action from the drop-down list.
-
Use the search function to select a category and filter the rules accordingly.
-
Click Update.
Edit the bot static signature rule property by using the NetScaler GUI
-
Navigate to Security > NetScaler Bot Management > Signature.
-
In the details page, click Add.
-
In the NetScaler Bot Management Signatures page, click edit in the Static Signature section.
-
In the Configure Static Signature section, select an action from the drop-down list.
-
Use the search function to select a category and filter the rules accordingly.
-
From the static signature list, select a signature to modify its property.
-
Click OK to confirm.
Create bot management profile
-
Navigate to Security > NetScaler Bot Management > Profiles.
-
In the details pane, click Add.
-
In the Create NetScaler Bot Management Profile page, set the following parameters.
-
Name. Bot profile name.
-
Signature. Name of the bot signature file.
-
Error URL. URL for redirects.
-
Comment. Brief description about the profile.
-
-
Click Create and Close.
Create bot policy
-
Navigate to Security > NetScaler Bot Management > Bot Policies.
-
In the details pane, click Add.
-
In the Create NetScaler Bot Management Policy page, set the following parameters.
-
Name. Name of the Bot policy.
-
Expression. Type the policy expression or rule directly in the text area.
-
Bot Profile. Bot profile to apply the bot policy.
-
Undefined Action. Select an action that you prefer to assign.
-
Comment. Brief description about the policy.
-
Log Action. Audit log message action for logging bot traffic. For more information about audit log action, see Audit logging topic.
-
-
Click Create and Close.