8.3 KiB
8.3 KiB
OWASP Top 10 ModSecurity Rules — Wazuh Active Response
Vue d'ensemble
Ce système détecte et répond aux attaques OWASP Top 10 via ModSecurity + Wazuh.
Deux couches de détection :
| Type | Trigger | Règle | Level | AR |
|---|---|---|---|---|
| Bloqué (403) | HTTP 403 | 100220-100281 | 12-15 | Fermer 4h-24h |
| Remontée (Warning) | Anomaly scoring | 100320-100381 | 6-11 | Fermer 30min-6h |
Correspondances CRS ModSecurity
941xxx — XSS (Cross-Site Scripting)
942xxx — SQL Injection, LDAP Injection, etc.
943xxx — XXE (XML External Entity)
930xxx — Path Traversal, RFI, RCE, LFI
932xxx — Remote Command Execution
933xxx — PHP Injection
934xxx — Java Injection
950xxx — Exploit attempts
951xxx — Regex DoS, Scanner detection
952xxx — Restricted File Access
953xxx — Insecure File Upload
954xxx — Proxy abuse, Scanner detection
955xxx — HTTP Response Splitting, Header Injection
970xxx — SSRF (Server-Side Request Forgery)
971xxx — SSRF (alternative patterns)
Règles par OWASP Category
OWASP #1 : Broken Access Control
Détecte : Path Traversal, File Inclusion, Unauthorized Access
| Rule ID | Type | Patterns | Level | Description |
|---|---|---|---|---|
| 100250 | Bloqué | 930xx (path|traversal|lfi) | 12 | LFI/Path Traversal bloquée |
| 100251 | Bloqué | 930xx (rfi|remote|include) | 13 | RFI bloquée |
| 100252 | Bloqué | 952xx | 11 | File Access bloquée |
| 100293 | Bloqué | Freq(100250)×4/180s | 12 | Path Traversal brute-force |
| 100350 | Remontée | 930xx (path|traversal|lfi) | 8 | LFI attempt (warning) |
| 100351 | Remontée | 930xx (rfi|remote|include) | 9 | RFI attempt (warning) |
| 100352 | Remontée | 952xx | 8 | File Access attempt (warning) |
Active Response :
- Bloqué :
firewall-drop 6h - Brute-force :
firewall-drop 24h - Remontée :
firewall-drop 2h-4h
OWASP #3 : Injection
Détecte : SQLi, LDAP, Command Injection, PHP/Java Injection
| Rule ID | Type | Patterns | Level | Description |
|---|---|---|---|---|
| 100220 | Bloqué | 942xx | 13 | SQL Injection bloquée |
| 100221 | Bloqué | 942xx (LDAP pattern) | 12 | LDAP Injection bloquée |
| 100222 | Bloqué | 932xx | 14 | Command Injection bloquée |
| 100223 | Bloqué | 933xx | 13 | PHP Injection bloquée |
| 100224 | Bloqué | 934xx | 13 | Java Injection bloquée |
| 100290 | Bloqué | Freq(100220)×3/60s | 14 | SQLi brute-force |
| 100292 | Bloqué | Freq(100222)×2/60s | 15 | Command Injection CRITICAL |
| 100320 | Remontée | 942xx | 9 | SQLi attempt (warning) |
| 100321 | Remontée | 932xx | 10 | Command Injection attempt |
| 100322 | Remontée | 942xx (LDAP) | 9 | LDAP Injection attempt |
| 100323 | Remontée | 933xx|934xx | 9 | PHP/Java Injection attempt |
| 100394 | Remontée | Freq(100320)×5/300s | 10 | SQLi anomaly scoring |
| 100396 | Remontée | Freq(100321)×2/60s | 12 | Command Injection CRITICAL |
Active Response :
- SQLi Bloquée :
firewall-drop 6h - SQLi Brute-force :
firewall-drop 24h + host-deny permanent - Command Injection :
firewall-drop 24h + host-deny - Command Injection CRITICAL :
firewall-drop permanent + host-deny permanent - SQLi Remontée :
firewall-drop 2h - SQLi Anomaly :
firewall-drop 4h - Command Injection Remontée :
firewall-drop 4h
OWASP #6 : Vulnerable & Outdated Components
Détecte : RCE, Exploit attempts, known vulnerabilities
| Rule ID | Type | Patterns | Level | Description |
|---|---|---|---|---|
| 100230 | Bloqué | 930xx|950xx | 14 | RCE/Exploit bloquée |
| 100330 | Remontée | 930xx|950xx | 11 | RCE/Exploit attempt (warning) |
Active Response :
- Bloqué :
firewall-drop 24h - Remontée :
firewall-drop 6h
OWASP #7 : Authentication & Session Management
Détecte : XSS, Header Injection, Session hijacking attempts
| Rule ID | Type | Patterns | Level | Description |
|---|---|---|---|---|
| 100240 | Bloqué | 941xx | 12 | XSS bloquée |
| 100241 | Bloqué | 955xx | 12 | Header Injection bloquée |
| 100291 | Bloqué | Freq(100240)×5/120s | 13 | XSS anomaly scoring |
| 100340 | Remontée | 941xx | 8 | XSS attempt (warning) |
| 100341 | Remontée | 955xx | 8 | Header Injection attempt |
| 100395 | Remontée | Freq(100340)×8/300s | 10 | XSS anomaly scoring |
Active Response :
- XSS Bloquée :
firewall-drop 4h - XSS Anomaly :
firewall-drop 6h - Header Injection :
firewall-drop 6h - XSS Remontée :
firewall-drop 1h - Header Remontée :
firewall-drop 2h
OWASP #8 : Software & Data Integrity Failures
Détecte : XXE, Deserialization attacks
| Rule ID | Type | Patterns | Level | Description |
|---|---|---|---|---|
| 100260 | Bloqué | 943xx | 13 | XXE bloquée |
| 100360 | Remontée | 943xx | 9 | XXE attempt (warning) |
Active Response :
- Bloqué :
firewall-drop 12h - Remontée :
firewall-drop 4h
OWASP #9 : Logging & Monitoring Failures
Détecte : Web scanners, bot activity, reconnaissance
| Rule ID | Type | Patterns | Level | Description |
|---|---|---|---|---|
| 100270 | Bloqué | 951xx|954xx | 10 | Scanner detection (bloquée) |
| 100370 | Remontée | 951xx|954xx | 6 | Scanner detection (warning) |
Active Response :
- Bloqué :
firewall-drop 2h - Remontée :
firewall-drop 30min
Autres : SSRF & File Upload
| Rule ID | Type | Patterns | Level | Description |
|---|---|---|---|---|
| 100280 | Bloqué | 970xx|971xx | 13 | SSRF bloquée |
| 100281 | Bloqué | 953xx | 12 | File Upload bloquée |
| 100380 | Remontée | 970xx|971xx | 9 | SSRF attempt |
| 100381 | Remontée | 953xx | 8 | File Upload attempt |
Active Response :
- SSRF Bloquée :
firewall-drop 12h - File Upload Bloquée :
firewall-drop 6h - SSRF Remontée :
firewall-drop 4h - File Upload Remontée :
firewall-drop 2h
Timeline des Active Responses
Bloquées (HTTP 403)
| Durée | Règles | Motif |
|---|---|---|
| Permanent | 100292 | Command Injection CRITICAL (2+ tentatives / 60s) |
| 24h | 100290 | SQLi brute-force (3+ / 60s) |
| 24h | 100230 | RCE/Exploit |
| 12h | 100251, 100260, 100280 | RFI, XXE, SSRF |
| 6h | 100220, 100221, 100250, 100252, 100281, 100330 | SQLi, LDAP, Path Traversal, File Access, Upload, RCE |
| 4h | 100240 | XSS |
| 2h | 100270 | Scanner |
Remontées (Anomaly Scoring)
| Durée | Règles | Motif |
|---|---|---|
| Permanent | 100396 | Command Injection (2+ / 60s) |
| 6h | 100395, 100330, 100351 | XSS anomaly, RCE, RFI |
| 4h | 100394, 100321, 100323, 100360, 100380 | SQLi anomaly, Cmd Inj, PHP/Java, XXE, SSRF |
| 2h | 100320, 100322, 100341, 100350, 100352, 100381 | SQLi, LDAP, Header Inj, Path Traversal, File Access, Upload |
| 30min | 100370 | Scanner |
Files
modsecurity_owasp_rules.xml— Définition des règles (100220-100396)ossec.conf— Active-response configs (firewall-drop, durées)firewall-monitoring-uber.sh— iptables pour autoriser trafic ModSec
Monitoring
Dashboard Wazuh :
- Alerts → Security Events → OWASP
- Visualization:
- Blocking rate (HTTP 403)
- Anomaly scoring trends
- Top attackers (srcip)
- Attack distribution by category
Logs:
# On monitoring-uber
tail -f /var/ossec/logs/alerts/alerts.json | grep -i "owasp\|100[23][0-9][0-9]"
Tuning
Les seuils de fréquence peuvent être ajustés :
- SQLi anomaly:
frequency="5" timeframe="300"→ Réduire pour être plus agressif - XSS anomaly:
frequency="8" timeframe="300"→ Augmenter pour réduire false positives - Command Injection:
frequency="2" timeframe="60"→ Critique, ne pas modifier
Notes
- First-match semantics: Wazuh évalue les règles par ID croissant → les règles bloquées (100220+) ont priorité sur les remontées (100320+)
- Field matching: Les patterns utilisent
<field name="transaction.messages.message">pour matcher les CRS rule IDs dans les logs ModSecurity - SCA suppressed: Les alertes SCA (CIS benchmark) sont à level 0 (voir
local_sca_noise.xml) - Persistence: Tous les AR sont sauvegardés dans
iptables-save→ survient les reboots