Files
projet_gestion_commande/monitoring/security/OWASP_MODSECURITY_RULES.md
T
2026-06-10 17:50:44 +02:00

8.3 KiB
Raw Blame History

OWASP Top 10 ModSecurity Rules — Wazuh Active Response

Vue d'ensemble

Ce système détecte et répond aux attaques OWASP Top 10 via ModSecurity + Wazuh.

Deux couches de détection :

Type Trigger Règle Level AR
Bloqué (403) HTTP 403 100220-100281 12-15 Fermer 4h-24h
Remontée (Warning) Anomaly scoring 100320-100381 6-11 Fermer 30min-6h

Correspondances CRS ModSecurity

941xxx — XSS (Cross-Site Scripting)
942xxx — SQL Injection, LDAP Injection, etc.
943xxx — XXE (XML External Entity)
930xxx — Path Traversal, RFI, RCE, LFI
932xxx — Remote Command Execution
933xxx — PHP Injection
934xxx — Java Injection
950xxx — Exploit attempts
951xxx — Regex DoS, Scanner detection
952xxx — Restricted File Access
953xxx — Insecure File Upload
954xxx — Proxy abuse, Scanner detection
955xxx — HTTP Response Splitting, Header Injection
970xxx — SSRF (Server-Side Request Forgery)
971xxx — SSRF (alternative patterns)

Règles par OWASP Category

OWASP #1 : Broken Access Control

Détecte : Path Traversal, File Inclusion, Unauthorized Access

Rule ID Type Patterns Level Description
100250 Bloqué 930xx (path|traversal|lfi) 12 LFI/Path Traversal bloquée
100251 Bloqué 930xx (rfi|remote|include) 13 RFI bloquée
100252 Bloqué 952xx 11 File Access bloquée
100293 Bloqué Freq(100250)×4/180s 12 Path Traversal brute-force
100350 Remontée 930xx (path|traversal|lfi) 8 LFI attempt (warning)
100351 Remontée 930xx (rfi|remote|include) 9 RFI attempt (warning)
100352 Remontée 952xx 8 File Access attempt (warning)

Active Response :

  • Bloqué : firewall-drop 6h
  • Brute-force : firewall-drop 24h
  • Remontée : firewall-drop 2h-4h

OWASP #3 : Injection

Détecte : SQLi, LDAP, Command Injection, PHP/Java Injection

Rule ID Type Patterns Level Description
100220 Bloqué 942xx 13 SQL Injection bloquée
100221 Bloqué 942xx (LDAP pattern) 12 LDAP Injection bloquée
100222 Bloqué 932xx 14 Command Injection bloquée
100223 Bloqué 933xx 13 PHP Injection bloquée
100224 Bloqué 934xx 13 Java Injection bloquée
100290 Bloqué Freq(100220)×3/60s 14 SQLi brute-force
100292 Bloqué Freq(100222)×2/60s 15 Command Injection CRITICAL
100320 Remontée 942xx 9 SQLi attempt (warning)
100321 Remontée 932xx 10 Command Injection attempt
100322 Remontée 942xx (LDAP) 9 LDAP Injection attempt
100323 Remontée 933xx|934xx 9 PHP/Java Injection attempt
100394 Remontée Freq(100320)×5/300s 10 SQLi anomaly scoring
100396 Remontée Freq(100321)×2/60s 12 Command Injection CRITICAL

Active Response :

  • SQLi Bloquée : firewall-drop 6h
  • SQLi Brute-force : firewall-drop 24h + host-deny permanent
  • Command Injection : firewall-drop 24h + host-deny
  • Command Injection CRITICAL : firewall-drop permanent + host-deny permanent
  • SQLi Remontée : firewall-drop 2h
  • SQLi Anomaly : firewall-drop 4h
  • Command Injection Remontée : firewall-drop 4h

OWASP #6 : Vulnerable & Outdated Components

Détecte : RCE, Exploit attempts, known vulnerabilities

Rule ID Type Patterns Level Description
100230 Bloqué 930xx|950xx 14 RCE/Exploit bloquée
100330 Remontée 930xx|950xx 11 RCE/Exploit attempt (warning)

Active Response :

  • Bloqué : firewall-drop 24h
  • Remontée : firewall-drop 6h

OWASP #7 : Authentication & Session Management

Détecte : XSS, Header Injection, Session hijacking attempts

Rule ID Type Patterns Level Description
100240 Bloqué 941xx 12 XSS bloquée
100241 Bloqué 955xx 12 Header Injection bloquée
100291 Bloqué Freq(100240)×5/120s 13 XSS anomaly scoring
100340 Remontée 941xx 8 XSS attempt (warning)
100341 Remontée 955xx 8 Header Injection attempt
100395 Remontée Freq(100340)×8/300s 10 XSS anomaly scoring

Active Response :

  • XSS Bloquée : firewall-drop 4h
  • XSS Anomaly : firewall-drop 6h
  • Header Injection : firewall-drop 6h
  • XSS Remontée : firewall-drop 1h
  • Header Remontée : firewall-drop 2h

OWASP #8 : Software & Data Integrity Failures

Détecte : XXE, Deserialization attacks

Rule ID Type Patterns Level Description
100260 Bloqué 943xx 13 XXE bloquée
100360 Remontée 943xx 9 XXE attempt (warning)

Active Response :

  • Bloqué : firewall-drop 12h
  • Remontée : firewall-drop 4h

OWASP #9 : Logging & Monitoring Failures

Détecte : Web scanners, bot activity, reconnaissance

Rule ID Type Patterns Level Description
100270 Bloqué 951xx|954xx 10 Scanner detection (bloquée)
100370 Remontée 951xx|954xx 6 Scanner detection (warning)

Active Response :

  • Bloqué : firewall-drop 2h
  • Remontée : firewall-drop 30min

Autres : SSRF & File Upload

Rule ID Type Patterns Level Description
100280 Bloqué 970xx|971xx 13 SSRF bloquée
100281 Bloqué 953xx 12 File Upload bloquée
100380 Remontée 970xx|971xx 9 SSRF attempt
100381 Remontée 953xx 8 File Upload attempt

Active Response :

  • SSRF Bloquée : firewall-drop 12h
  • File Upload Bloquée : firewall-drop 6h
  • SSRF Remontée : firewall-drop 4h
  • File Upload Remontée : firewall-drop 2h

Timeline des Active Responses

Bloquées (HTTP 403)

Durée Règles Motif
Permanent 100292 Command Injection CRITICAL (2+ tentatives / 60s)
24h 100290 SQLi brute-force (3+ / 60s)
24h 100230 RCE/Exploit
12h 100251, 100260, 100280 RFI, XXE, SSRF
6h 100220, 100221, 100250, 100252, 100281, 100330 SQLi, LDAP, Path Traversal, File Access, Upload, RCE
4h 100240 XSS
2h 100270 Scanner

Remontées (Anomaly Scoring)

Durée Règles Motif
Permanent 100396 Command Injection (2+ / 60s)
6h 100395, 100330, 100351 XSS anomaly, RCE, RFI
4h 100394, 100321, 100323, 100360, 100380 SQLi anomaly, Cmd Inj, PHP/Java, XXE, SSRF
2h 100320, 100322, 100341, 100350, 100352, 100381 SQLi, LDAP, Header Inj, Path Traversal, File Access, Upload
30min 100370 Scanner

Files

  • modsecurity_owasp_rules.xml — Définition des règles (100220-100396)
  • ossec.conf — Active-response configs (firewall-drop, durées)
  • firewall-monitoring-uber.sh — iptables pour autoriser trafic ModSec

Monitoring

Dashboard Wazuh :

  1. Alerts → Security Events → OWASP
  2. Visualization:
    • Blocking rate (HTTP 403)
    • Anomaly scoring trends
    • Top attackers (srcip)
    • Attack distribution by category

Logs:

# On monitoring-uber
tail -f /var/ossec/logs/alerts/alerts.json | grep -i "owasp\|100[23][0-9][0-9]"

Tuning

Les seuils de fréquence peuvent être ajustés :

  • SQLi anomaly: frequency="5" timeframe="300" → Réduire pour être plus agressif
  • XSS anomaly: frequency="8" timeframe="300" → Augmenter pour réduire false positives
  • Command Injection: frequency="2" timeframe="60" → Critique, ne pas modifier

Notes

  • First-match semantics: Wazuh évalue les règles par ID croissant → les règles bloquées (100220+) ont priorité sur les remontées (100320+)
  • Field matching: Les patterns utilisent <field name="transaction.messages.message"> pour matcher les CRS rule IDs dans les logs ModSecurity
  • SCA suppressed: Les alertes SCA (CIS benchmark) sont à level 0 (voir local_sca_noise.xml)
  • Persistence: Tous les AR sont sauvegardés dans iptables-save → survient les reboots