Files
ansible-mln/monitoring/security/OWASP_MODSECURITY_RULES.md
2026-08-08 12:04:57 +02:00

247 lines
8.3 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# OWASP Top 10 ModSecurity Rules — Wazuh Active Response
## Vue d'ensemble
Ce système détecte et répond aux attaques OWASP Top 10 via ModSecurity + Wazuh.
**Deux couches de détection :**
| Type | Trigger | Règle | Level | AR |
|------|---------|-------|-------|-----|
| **Bloqué (403)** | HTTP 403 | 100220-100281 | 12-15 | Fermer 4h-24h |
| **Remontée (Warning)** | Anomaly scoring | 100320-100381 | 6-11 | Fermer 30min-6h |
---
## Correspondances CRS ModSecurity
```
941xxx — XSS (Cross-Site Scripting)
942xxx — SQL Injection, LDAP Injection, etc.
943xxx — XXE (XML External Entity)
930xxx — Path Traversal, RFI, RCE, LFI
932xxx — Remote Command Execution
933xxx — PHP Injection
934xxx — Java Injection
950xxx — Exploit attempts
951xxx — Regex DoS, Scanner detection
952xxx — Restricted File Access
953xxx — Insecure File Upload
954xxx — Proxy abuse, Scanner detection
955xxx — HTTP Response Splitting, Header Injection
970xxx — SSRF (Server-Side Request Forgery)
971xxx — SSRF (alternative patterns)
```
---
## Règles par OWASP Category
### OWASP #1 : Broken Access Control
**Détecte :** Path Traversal, File Inclusion, Unauthorized Access
| Rule ID | Type | Patterns | Level | Description |
|---------|------|----------|-------|-------------|
| 100250 | Bloqué | 930xx (path\|traversal\|lfi) | 12 | LFI/Path Traversal bloquée |
| 100251 | Bloqué | 930xx (rfi\|remote\|include) | 13 | RFI bloquée |
| 100252 | Bloqué | 952xx | 11 | File Access bloquée |
| 100293 | Bloqué | Freq(100250)×4/180s | 12 | Path Traversal brute-force |
| 100350 | Remontée | 930xx (path\|traversal\|lfi) | 8 | LFI attempt (warning) |
| 100351 | Remontée | 930xx (rfi\|remote\|include) | 9 | RFI attempt (warning) |
| 100352 | Remontée | 952xx | 8 | File Access attempt (warning) |
**Active Response :**
- Bloqué : `firewall-drop 6h`
- Brute-force : `firewall-drop 24h`
- Remontée : `firewall-drop 2h-4h`
---
### OWASP #3 : Injection
**Détecte :** SQLi, LDAP, Command Injection, PHP/Java Injection
| Rule ID | Type | Patterns | Level | Description |
|---------|------|----------|-------|-------------|
| 100220 | Bloqué | 942xx | 13 | SQL Injection bloquée |
| 100221 | Bloqué | 942xx (LDAP pattern) | 12 | LDAP Injection bloquée |
| 100222 | Bloqué | 932xx | 14 | Command Injection bloquée |
| 100223 | Bloqué | 933xx | 13 | PHP Injection bloquée |
| 100224 | Bloqué | 934xx | 13 | Java Injection bloquée |
| 100290 | Bloqué | Freq(100220)×3/60s | 14 | SQLi brute-force |
| 100292 | Bloqué | Freq(100222)×2/60s | 15 | Command Injection CRITICAL |
| 100320 | Remontée | 942xx | 9 | SQLi attempt (warning) |
| 100321 | Remontée | 932xx | 10 | Command Injection attempt |
| 100322 | Remontée | 942xx (LDAP) | 9 | LDAP Injection attempt |
| 100323 | Remontée | 933xx\|934xx | 9 | PHP/Java Injection attempt |
| 100394 | Remontée | Freq(100320)×5/300s | 10 | SQLi anomaly scoring |
| 100396 | Remontée | Freq(100321)×2/60s | 12 | Command Injection CRITICAL |
**Active Response :**
- SQLi Bloquée : `firewall-drop 6h`
- SQLi Brute-force : `firewall-drop 24h + host-deny permanent`
- Command Injection : `firewall-drop 24h + host-deny`
- Command Injection CRITICAL : `firewall-drop permanent + host-deny permanent`
- SQLi Remontée : `firewall-drop 2h`
- SQLi Anomaly : `firewall-drop 4h`
- Command Injection Remontée : `firewall-drop 4h`
---
### OWASP #6 : Vulnerable & Outdated Components
**Détecte :** RCE, Exploit attempts, known vulnerabilities
| Rule ID | Type | Patterns | Level | Description |
|---------|------|----------|-------|-------------|
| 100230 | Bloqué | 930xx\|950xx | 14 | RCE/Exploit bloquée |
| 100330 | Remontée | 930xx\|950xx | 11 | RCE/Exploit attempt (warning) |
**Active Response :**
- Bloqué : `firewall-drop 24h`
- Remontée : `firewall-drop 6h`
---
### OWASP #7 : Authentication & Session Management
**Détecte :** XSS, Header Injection, Session hijacking attempts
| Rule ID | Type | Patterns | Level | Description |
|---------|------|----------|-------|-------------|
| 100240 | Bloqué | 941xx | 12 | XSS bloquée |
| 100241 | Bloqué | 955xx | 12 | Header Injection bloquée |
| 100291 | Bloqué | Freq(100240)×5/120s | 13 | XSS anomaly scoring |
| 100340 | Remontée | 941xx | 8 | XSS attempt (warning) |
| 100341 | Remontée | 955xx | 8 | Header Injection attempt |
| 100395 | Remontée | Freq(100340)×8/300s | 10 | XSS anomaly scoring |
**Active Response :**
- XSS Bloquée : `firewall-drop 4h`
- XSS Anomaly : `firewall-drop 6h`
- Header Injection : `firewall-drop 6h`
- XSS Remontée : `firewall-drop 1h`
- Header Remontée : `firewall-drop 2h`
---
### OWASP #8 : Software & Data Integrity Failures
**Détecte :** XXE, Deserialization attacks
| Rule ID | Type | Patterns | Level | Description |
|---------|------|----------|-------|-------------|
| 100260 | Bloqué | 943xx | 13 | XXE bloquée |
| 100360 | Remontée | 943xx | 9 | XXE attempt (warning) |
**Active Response :**
- Bloqué : `firewall-drop 12h`
- Remontée : `firewall-drop 4h`
---
### OWASP #9 : Logging & Monitoring Failures
**Détecte :** Web scanners, bot activity, reconnaissance
| Rule ID | Type | Patterns | Level | Description |
|---------|------|----------|-------|-------------|
| 100270 | Bloqué | 951xx\|954xx | 10 | Scanner detection (bloquée) |
| 100370 | Remontée | 951xx\|954xx | 6 | Scanner detection (warning) |
**Active Response :**
- Bloqué : `firewall-drop 2h`
- Remontée : `firewall-drop 30min`
---
### Autres : SSRF & File Upload
| Rule ID | Type | Patterns | Level | Description |
|---------|------|----------|-------|-------------|
| 100280 | Bloqué | 970xx\|971xx | 13 | SSRF bloquée |
| 100281 | Bloqué | 953xx | 12 | File Upload bloquée |
| 100380 | Remontée | 970xx\|971xx | 9 | SSRF attempt |
| 100381 | Remontée | 953xx | 8 | File Upload attempt |
**Active Response :**
- SSRF Bloquée : `firewall-drop 12h`
- File Upload Bloquée : `firewall-drop 6h`
- SSRF Remontée : `firewall-drop 4h`
- File Upload Remontée : `firewall-drop 2h`
---
## Timeline des Active Responses
### Bloquées (HTTP 403)
| Durée | Règles | Motif |
|-------|--------|-------|
| Permanent | 100292 | Command Injection CRITICAL (2+ tentatives / 60s) |
| 24h | 100290 | SQLi brute-force (3+ / 60s) |
| 24h | 100230 | RCE/Exploit |
| 12h | 100251, 100260, 100280 | RFI, XXE, SSRF |
| 6h | 100220, 100221, 100250, 100252, 100281, 100330 | SQLi, LDAP, Path Traversal, File Access, Upload, RCE |
| 4h | 100240 | XSS |
| 2h | 100270 | Scanner |
### Remontées (Anomaly Scoring)
| Durée | Règles | Motif |
|-------|--------|-------|
| Permanent | 100396 | Command Injection (2+ / 60s) |
| 6h | 100395, 100330, 100351 | XSS anomaly, RCE, RFI |
| 4h | 100394, 100321, 100323, 100360, 100380 | SQLi anomaly, Cmd Inj, PHP/Java, XXE, SSRF |
| 2h | 100320, 100322, 100341, 100350, 100352, 100381 | SQLi, LDAP, Header Inj, Path Traversal, File Access, Upload |
| 30min | 100370 | Scanner |
---
## Files
- **`modsecurity_owasp_rules.xml`** — Définition des règles (100220-100396)
- **`ossec.conf`** — Active-response configs (firewall-drop, durées)
- **`firewall-monitoring-uber.sh`** — iptables pour autoriser trafic ModSec
---
## Monitoring
**Dashboard Wazuh :**
1. **Alerts → Security Events → OWASP**
2. **Visualization:**
- Blocking rate (HTTP 403)
- Anomaly scoring trends
- Top attackers (srcip)
- Attack distribution by category
**Logs:**
```bash
# On monitoring-uber
tail -f /var/ossec/logs/alerts/alerts.json | grep -i "owasp\|100[23][0-9][0-9]"
```
---
## Tuning
Les seuils de fréquence peuvent être ajustés :
- **SQLi anomaly:** `frequency="5" timeframe="300"` → Réduire pour être plus agressif
- **XSS anomaly:** `frequency="8" timeframe="300"` → Augmenter pour réduire false positives
- **Command Injection:** `frequency="2" timeframe="60"` → Critique, ne pas modifier
---
## Notes
- **First-match semantics:** Wazuh évalue les règles par ID croissant → les règles bloquées (100220+) ont priorité sur les remontées (100320+)
- **Field matching:** Les patterns utilisent `<field name="transaction.messages.message">` pour matcher les CRS rule IDs dans les logs ModSecurity
- **SCA suppressed:** Les alertes SCA (CIS benchmark) sont à level 0 (voir `local_sca_noise.xml`)
- **Persistence:** Tous les AR sont sauvegardés dans `iptables-save` → survient les reboots