Google Cloud Armor ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™ ๊ฐœ์š”

Google Cloud Armor ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์€ ์˜คํ”ˆ์†Œ์Šค ์—…๊ณ„ ํ‘œ์ค€์—์„œ ์ปดํŒŒ์ผ๋œ ์„œ๋ช…์ด ์ˆ˜์‹ญ ๊ฐœ ์žˆ๋Š” ๋ณต์žกํ•œ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐฉํ™”๋ฒฝ(WAF) ๊ทœ์น™์ž…๋‹ˆ๋‹ค. ๊ฐ ์„œ๋ช…์€ ๊ทœ์น™ ์ง‘ํ•ฉ์˜ ๊ณต๊ฒฉ ๊ฐ์ง€ ๊ทœ์น™์— ํ•ด๋‹นํ•ฉ๋‹ˆ๋‹ค. Google์€ ์ด๋Ÿฌํ•œ ๊ทœ์น™์„ ์žˆ๋Š” ๊ทธ๋Œ€๋กœ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ๊ทœ์น™์„ ์‚ฌ์šฉํ•˜๋ฉด Google Cloud Armor์—์„œ ๊ฐ ์„œ๋ช…์„ ์ˆ˜๋™์œผ๋กœ ์ •์˜ํ•  ํ•„์š” ์—†์ด ํŽธ๋ฆฌํ•œ ์ด๋ฆ„์˜ ๊ทœ์น™์„ ์ฐธ์กฐํ•˜์—ฌ ๊ณ ์œ ํ•œ ํŠธ๋ž˜ํ”ฝ ์„œ๋ช… ์ˆ˜์‹ญ ๊ฐœ๋ฅผ ํ‰๊ฐ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Google Cloud Armor ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์€ ์š”๊ตฌ์‚ฌํ•ญ์— ๋งž๊ฒŒ ์กฐ์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทœ์น™์„ ์กฐ์ •ํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ Google Cloud Armor ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™ ์กฐ์ •์„ ์ฐธ์กฐํ•˜์„ธ์š”.

๋‹ค์Œ ํ‘œ์—๋Š” Google Cloud Armor ๋ณด์•ˆ ์ •์ฑ…์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ WAF ๊ทœ์น™์˜ ์ „์ฒด ๋ชฉ๋ก์ด ๋‚˜์™€ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทœ์น™ ์†Œ์Šค๋Š” OWASP Core Rule Set(CRS) 3.3.2์ž…๋‹ˆ๋‹ค. ๋ฒ„์ „ 3.3์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฏผ๊ฐ๋„๋ฅผ ๋†’์ด๊ณ  ๋ณดํ˜ธ๋œ ๊ณต๊ฒฉ ์œ ํ˜•์˜ ๋ฒ”์œ„๋ฅผ ๋„“ํžˆ๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. CRS 3.0์— ๋Œ€ํ•œ ์ง€์›์€ ๊ณ„์†๋ฉ๋‹ˆ๋‹ค.

CRS 3.3

Google Cloud Armor ๊ทœ์น™ ์ด๋ฆ„ OWASP ๊ทœ์น™ ์ด๋ฆ„ ํ˜„์žฌ ์ƒํƒœ
SQL ์‚ฝ์ž… sqli-v33-stable sqli-v33-canary์™€ ๋™๊ธฐํ™”
sqli-v33-canary ์ตœ์‹ 
๊ต์ฐจ ์‚ฌ์ดํŠธ ์Šคํฌ๋ฆฝํŒ… xss-v33-stable xss-v33-canary์™€ ๋™๊ธฐํ™”
xss-v33-canary ์ตœ์‹ 
๋กœ์ปฌ ํŒŒ์ผ ํฌํ•จ lfi-v33-stable lfi-v33-canary์™€ ๋™๊ธฐํ™”
lfi-v33-canary ์ตœ์‹ 
์›๊ฒฉ ํŒŒ์ผ ํฌํ•จ rfi-v33-stable rfi-v33-canary์™€ ๋™๊ธฐํ™”
rfi-v33-canary ์ตœ์‹ 
์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ rce-v33-stable rce-v33-canary์™€ ๋™๊ธฐํ™”
rce-v33-canary ์ตœ์‹ 
๋ฉ”์„œ๋“œ ์ ์šฉ methodenforcement-v33-stable methodenforcement-v33-canary์™€ ๋™๊ธฐํ™”
methodenforcement-v33-canary ์ตœ์‹ 
์Šค์บ๋„ˆ ๊ฐ์ง€ scannerdetection-v33-stable scannerdetection-v33-canary์™€ ๋™๊ธฐํ™”
scannerdetection-v33-canary ์ตœ์‹ 
ํ”„๋กœํ† ์ฝœ ๊ณต๊ฒฉ protocolattack-v33-stable protocolattack-v33-canary์™€ ๋™๊ธฐํ™”
protocolattack-v33-canary ์ตœ์‹ 
PHP ์‚ฝ์ž… ๊ณต๊ฒฉ php-v33-stable php-v33-canary์™€ ๋™๊ธฐํ™”
php-v33-canary ์ตœ์‹ 
์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ sessionfixation-v33-stable sessionfixation-v33-canary์™€ ๋™๊ธฐํ™”
sessionfixation-v33-canary ์ตœ์‹ 
Java ๊ณต๊ฒฉ java-v33-stable java-v33-canary์™€ ๋™๊ธฐํ™”
java-v33-canary ์ตœ์‹ 
NodeJS ๊ณต๊ฒฉ nodejs-v33-stable nodejs-v33-canary์™€ ๋™๊ธฐํ™”
nodejs-v33-canary ์ตœ์‹ 

CRS 3.0

Google Cloud Armor ๊ทœ์น™ ์ด๋ฆ„ OWASP ๊ทœ์น™ ์ด๋ฆ„ ํ˜„์žฌ ์ƒํƒœ
SQL ์‚ฝ์ž… sqli-stable sqli-canary์™€ ๋™๊ธฐํ™”
sqli-canary ์ตœ์‹ 
๊ต์ฐจ ์‚ฌ์ดํŠธ ์Šคํฌ๋ฆฝํŒ… xss-stable xss-canary์™€ ๋™๊ธฐํ™”
xss-canary ์ตœ์‹ 
๋กœ์ปฌ ํŒŒ์ผ ํฌํ•จ lfi-stable lfi-canary์™€ ๋™๊ธฐํ™”
lfi-canary ์ตœ์‹ 
์›๊ฒฉ ํŒŒ์ผ ํฌํ•จ rfi-stable rfi-canary์™€ ๋™๊ธฐํ™”
rfi-canary ์ตœ์‹ 
์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ rce-stable rce-canary์™€ ๋™๊ธฐํ™”
rce-canary ์ตœ์‹ 
๋ฉ”์„œ๋“œ ์ ์šฉ methodenforcement-stable methodenforcement-canary์™€ ๋™๊ธฐํ™”
methodenforcement-canary ์ตœ์‹ 
์Šค์บ๋„ˆ ๊ฐ์ง€ scannerdetection-stable scannerdetection-canary์™€ ๋™๊ธฐํ™”
scannerdetection-canary ์ตœ์‹ 
ํ”„๋กœํ† ์ฝœ ๊ณต๊ฒฉ protocolattack-stable protocolattack-canary์™€ ๋™๊ธฐํ™”
protocolattack-canary ์ตœ์‹ 
PHP ์‚ฝ์ž… ๊ณต๊ฒฉ php-stable php-canary์™€ ๋™๊ธฐํ™”
php-canary ์ตœ์‹ 
์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ sessionfixation-stable sessionfixation-canary์™€ ๋™๊ธฐํ™”
sessionfixation-canary ์ตœ์‹ 
Java ๊ณต๊ฒฉ Not included
NodeJS ๊ณต๊ฒฉ Not included

๋˜ํ•œ ๋ชจ๋“  Google Cloud Armor ๊ณ ๊ฐ์€ ๋‹ค์Œ cve-canary ๊ทœ์น™์„ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค์Œ ์ทจ์•ฝ์ ์„ ๊ฐ์ง€ํ•˜๊ณ  ์„ ํƒ์ ์œผ๋กœ ์ฐจ๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • CVE-2021-44228 ๋ฐ CVE-2021-45046 Log4j RCE ์ทจ์•ฝ์ 
  • 942550-sqli JSON ํ˜•์‹์˜ ์ฝ˜ํ…์ธ  ์ทจ์•ฝ์ 
Google Cloud Armor ๊ทœ์น™ ์ด๋ฆ„ ์ง€์›๋˜๋Š” ์ทจ์•ฝ์  ์œ ํ˜•
cve-canary Log4j ์ทจ์•ฝ์ 
json-sqli-canary JSON ๊ธฐ๋ฐ˜ SQL ์‚ฝ์ž… ์šฐํšŒ ์ทจ์•ฝ์ 

์‚ฌ์ „ ์„ค์ •๋œ OWASP ๊ทœ์น™

์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ๊ฐ WAF ๊ทœ์น™์—๋Š” OWASP CRS paranoia ์ˆ˜์ค€์— ํ•ด๋‹นํ•˜๋Š” ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์ด ๋‚ฎ์„์ˆ˜๋ก ์„œ๋ช…์˜ ์‹ ๋ขฐ๋„๊ฐ€ ๋†’์œผ๋ฏ€๋กœ ๊ฑฐ์ง“์–‘์„ฑ์„ ์ƒ์„ฑํ•  ๊ฐ€๋Šฅ์„ฑ์ด ๋‚ฎ์Šต๋‹ˆ๋‹ค. ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์ด ๋†’์•„์ง€๋ฉด ๋ณด์•ˆ์ด ํ–ฅ์ƒ๋˜์ง€๋งŒ ๊ฑฐ์ง“์–‘์„ฑ์ด ์ƒ์„ฑ๋  ์œ„ํ—˜์ด ์ฆ๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

SQL ์‚ฝ์ž…(SQLi)

๋‹ค์Œ ํ‘œ์—์„œ๋Š” SQLi ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id942100-sqli 1 libinjection์„ ํ†ตํ•œ SQL ์‚ฝ์ž… ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id942140-sqli 1 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ผ๋ฐ˜์ ์ธ DB ์ด๋ฆ„์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id942160-sqli 1 sleep() ๋˜๋Š” benchmark()๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ธ”๋ผ์ธ๋“œ SQLi ํ…Œ์ŠคํŠธ ๊ฐ์ง€
owasp-crs-v030301-id942170-sqli 1 ์กฐ๊ฑด๋ถ€ ์ฟผ๋ฆฌ๋ฅผ ํฌํ•จํ•˜์—ฌ SQL ๋ฒค์น˜๋งˆํฌ ๋ฐ ์ˆ˜๋ฉด ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030301-id942190-sqli 1 MSSQL ์ฝ”๋“œ ์‹คํ–‰ ๋ฐ ์ •๋ณด ์ˆ˜์ง‘ ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030301-id942220-sqli 1 ์ •์ˆ˜ ์˜ค๋ฒ„ํ”Œ๋กœ ๊ณต๊ฒฉ ์ฐพ๊ธฐ
owasp-crs-v030301-id942230-sqli 1 ์กฐ๊ฑด๋ถ€ SQL ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030301-id942240-sqli 1 MySQL ๋ฌธ์ž ์ง‘ํ•ฉ ์ „ํ™˜ ๋ฐ MSSQL DoS ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030301-id942250-sqli 1 MATCH AGAINST ๊ฐ์ง€
owasp-crs-v030301-id942270-sqli 1 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ์ฐพ๊ธฐ(mysql์— ๋Œ€ํ•œ ์ผ๋ฐ˜์ ์ธ ๊ณต๊ฒฉ ๋ฌธ์ž์—ด)
owasp-crs-v030301-id942280-sqli 1 Postgres pg_sleep ์‚ฝ์ž… ๊ฐ์ง€
owasp-crs-v030301-id942290-sqli 1 ๊ธฐ๋ณธ MongoDB SQL ์‚ฝ์ž… ์‹œ๋„ ์ฐพ๊ธฐ
owasp-crs-v030301-id942320-sqli 1 MySQL ๋ฐ PostgreSQL ์ €์žฅ ํ”„๋กœ์‹œ์ ธ/ํ•จ์ˆ˜ ์‚ฝ์ž… ๊ฐ์ง€
owasp-crs-v030301-id942350-sqli 1 MySQL UDF ์‚ฝ์ž… ๋ฐ ๊ธฐํƒ€ ๋ฐ์ดํ„ฐ/๊ตฌ์กฐ ์กฐ์ž‘ ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030301-id942360-sqli 1 ์—ฐ๊ฒฐ๋œ ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ๋ฐ SQLLFI ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030301-id942500-sqli 1 MySQL ์ธ๋ผ์ธ ์ฃผ์„์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id942110-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ผ๋ฐ˜์ ์ธ ์‚ฝ์ž… ํ…Œ์ŠคํŠธ๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id942120-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: SQL ์—ฐ์‚ฐ์ž๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id942130-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: SQL Tautology๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id942150-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id942180-sqli 2 ๊ธฐ๋ณธ SQL ์ธ์ฆ ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€ 1/3
owasp-crs-v030301-id942200-sqli 2 MySQL comment-/space-obfuscated ์‚ฝ์ž… ๋ฐ ๋ฐฑํ‹ฑ ์ข…๋ฃŒ ๊ฐ์ง€
owasp-crs-v030301-id942210-sqli 2 ์—ฐ๊ฒฐ๋œ SQL ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€ 1/2
owasp-crs-v030301-id942260-sqli 2 ๊ธฐ๋ณธ SQL ์ธ์ฆ ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€ 2/3
owasp-crs-v030301-id942300-sqli 2 MySQL ์ฃผ์„ ๊ฐ์ง€
owasp-crs-v030301-id942310-sqli 2 ์—ฐ๊ฒฐ๋œ SQL ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€ 2/2
owasp-crs-v030301-id942330-sqli 2 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ํ”„๋กœ๋ธŒ ๊ฐ์ง€ 1/2
owasp-crs-v030301-id942340-sqli 2 ๊ธฐ๋ณธ SQL ์ธ์ฆ ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€ 3/3
owasp-crs-v030301-id942361-sqli 2 ํ‚ค์›Œ๋“œ ๋ณ€๊ฒฝ ๋˜๋Š” ํ†ตํ•ฉ์— ๊ธฐ๋ฐ˜ํ•œ ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ๊ฐ์ง€
owasp-crs-v030301-id942370-sqli 2 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ํ”„๋กœ๋ธŒ ๊ฐ์ง€ 2/3
owasp-crs-v030301-id942380-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id942390-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id942400-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id942410-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id942470-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id942480-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id942430-sqli 2 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(args): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(12)
owasp-crs-v030301-id942440-sqli 2 SQL ์ฃผ์„ ์‹œํ€€์Šค๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id942450-sqli 2 ์‹๋ณ„๋œ SQL 16์ง„์ˆ˜ ์ธ์ฝ”๋”ฉ
owasp-crs-v030301-id942510-sqli 2 ํ‹ฑ ๋˜๋Š” ๋ฐฑํ‹ฑ์— ์˜ํ•œ SQLi ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€๋จ
owasp-crs-v030301-id942251-sqli 3 HAVING ์‚ฝ์ž… ๊ฐ์ง€
owasp-crs-v030301-id942490-sqli 3 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ํ”„๋กœ๋ธŒ ๊ฐ์ง€ 3/3
owasp-crs-v030301-id942420-sqli 3 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(์ฟ ํ‚ค): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(8)
owasp-crs-v030301-id942431-sqli 3 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(args): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(6)
owasp-crs-v030301-id942460-sqli 3 ๋ฉ”ํƒ€ ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€ ์•Œ๋ฆผ - ๋น„๋‹จ์–ด ๋ฐ˜๋ณต ๋ฌธ์ž
owasp-crs-v030301-id942101-sqli 3 libinjection์„ ํ†ตํ•œ SQL ์‚ฝ์ž… ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id942511-sqli 3 ํ‹ฑ์— ์˜ํ•œ SQLi ์šฐํšŒ ์‹œ๋„๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id942421-sqli 4 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(์ฟ ํ‚ค): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(3)
owasp-crs-v030301-id942432-sqli 4 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(args): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(2)

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
Not included 1 libinjection์„ ํ†ตํ•œ SQL ์‚ฝ์ž… ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id942140-sqli 1 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ผ๋ฐ˜์ ์ธ DB ์ด๋ฆ„์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id942160-sqli 1 sleep() ๋˜๋Š” benchmark()๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ธ”๋ผ์ธ๋“œ SQLi ํ…Œ์ŠคํŠธ ๊ฐ์ง€
owasp-crs-v030001-id942170-sqli 1 ์กฐ๊ฑด๋ถ€ ์ฟผ๋ฆฌ๋ฅผ ํฌํ•จํ•˜์—ฌ SQL ๋ฒค์น˜๋งˆํฌ ๋ฐ ์ˆ˜๋ฉด ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030001-id942190-sqli 1 MSSQL ์ฝ”๋“œ ์‹คํ–‰ ๋ฐ ์ •๋ณด ์ˆ˜์ง‘ ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030001-id942220-sqli 1 ์ •์ˆ˜ ์˜ค๋ฒ„ํ”Œ๋กœ ๊ณต๊ฒฉ ์ฐพ๊ธฐ
owasp-crs-v030001-id942230-sqli 1 ์กฐ๊ฑด๋ถ€ SQL ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030001-id942240-sqli 1 MySQL ๋ฌธ์ž ์ง‘ํ•ฉ ์ „ํ™˜ ๋ฐ MSSQL DoS ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030001-id942250-sqli 1 MATCH AGAINST ๊ฐ์ง€
owasp-crs-v030001-id942270-sqli 1 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ์ฐพ๊ธฐ(mysql์— ๋Œ€ํ•œ ์ผ๋ฐ˜์ ์ธ ๊ณต๊ฒฉ ๋ฌธ์ž์—ด)
owasp-crs-v030001-id942280-sqli 1 Postgres pg_sleep ์‚ฝ์ž… ๊ฐ์ง€
owasp-crs-v030001-id942290-sqli 1 ๊ธฐ๋ณธ MongoDB SQL ์‚ฝ์ž… ์‹œ๋„ ์ฐพ๊ธฐ
owasp-crs-v030001-id942320-sqli 1 MySQL ๋ฐ PostgreSQL ์ €์žฅ ํ”„๋กœ์‹œ์ ธ/ํ•จ์ˆ˜ ์‚ฝ์ž… ๊ฐ์ง€
owasp-crs-v030001-id942350-sqli 1 MySQL UDF ์‚ฝ์ž… ๋ฐ ๊ธฐํƒ€ ๋ฐ์ดํ„ฐ/๊ตฌ์กฐ ์กฐ์ž‘ ์‹œ๋„ ๊ฐ์ง€
owasp-crs-v030001-id942360-sqli 1 ์—ฐ๊ฒฐ๋œ ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ๋ฐ SQLLFI ์‹œ๋„ ๊ฐ์ง€
Not included 1 MySQL ์ธ๋ผ์ธ ์ฃผ์„์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id942110-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ผ๋ฐ˜์ ์ธ ์‚ฝ์ž… ํ…Œ์ŠคํŠธ๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030001-id942120-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: SQL ์—ฐ์‚ฐ์ž๊ฐ€ ๊ฐ์ง€๋จ
Not included 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ: SQL Tautology๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030001-id942150-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030001-id942180-sqli 2 ๊ธฐ๋ณธ SQL ์ธ์ฆ ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€ 1/3
owasp-crs-v030001-id942200-sqli 2 MySQL comment-/space-obfuscated ์‚ฝ์ž… ๋ฐ ๋ฐฑํ‹ฑ ์ข…๋ฃŒ ๊ฐ์ง€
owasp-crs-v030001-id942210-sqli 2 ์—ฐ๊ฒฐ๋œ SQL ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€ 1/2
owasp-crs-v030001-id942260-sqli 2 ๊ธฐ๋ณธ SQL ์ธ์ฆ ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€ 2/3
owasp-crs-v030001-id942300-sqli 2 MySQL ์ฃผ์„ ๊ฐ์ง€
owasp-crs-v030001-id942310-sqli 2 ์—ฐ๊ฒฐ๋œ SQL ์‚ฝ์ž… ์‹œ๋„ ๊ฐ์ง€ 2/2
owasp-crs-v030001-id942330-sqli 2 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ํ”„๋กœ๋ธŒ ๊ฐ์ง€ 1/2
owasp-crs-v030001-id942340-sqli 2 ๊ธฐ๋ณธ SQL ์ธ์ฆ ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€ 3/3
Not included 2 ํ‚ค์›Œ๋“œ ๋ณ€๊ฒฝ ๋˜๋Š” ํ†ตํ•ฉ์— ๊ธฐ๋ฐ˜ํ•œ ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ๊ฐ์ง€
Not included 2 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ํ”„๋กœ๋ธŒ ๊ฐ์ง€ 2/3
owasp-crs-v030001-id942380-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030001-id942390-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030001-id942400-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030001-id942410-sqli 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
Not included 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
Not included 2 SQL ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030001-id942430-sqli 2 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(args): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(12)
owasp-crs-v030001-id942440-sqli 2 SQL ์ฃผ์„ ์‹œํ€€์Šค๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030001-id942450-sqli 2 ์‹๋ณ„๋œ SQL 16์ง„์ˆ˜ ์ธ์ฝ”๋”ฉ
Not included 2 ํ‹ฑ ๋˜๋Š” ๋ฐฑํ‹ฑ์— ์˜ํ•œ SQLi ์šฐํšŒ ์‹œ๋„ ๊ฐ์ง€๋จ
owasp-crs-v030001-id942251-sqli 3 HAVING ์‚ฝ์ž… ๊ฐ์ง€
Not included 2 ๊ธฐ๋ณธ SQL ์‚ฝ์ž… ํ”„๋กœ๋ธŒ ๊ฐ์ง€ 3/3
owasp-crs-v030001-id942420-sqli 3 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(์ฟ ํ‚ค): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(8)
owasp-crs-v030001-id942431-sqli 3 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(args): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(6)
owasp-crs-v030001-id942460-sqli 3 ๋ฉ”ํƒ€ ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€ ์•Œ๋ฆผ - ๋น„๋‹จ์–ด ๋ฐ˜๋ณต ๋ฌธ์ž
Not included 3 libinjection์„ ํ†ตํ•œ SQL ์‚ฝ์ž… ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
Not included 3 ํ‹ฑ์— ์˜ํ•œ SQLi ์šฐํšŒ ์‹œ๋„๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030001-id942421-sqli 4 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(์ฟ ํ‚ค): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(3)
owasp-crs-v030001-id942432-sqli 4 ์ œํ•œ๋œ SQL ๋ฌธ์ž ์ด์ƒ ๊ฐ์ง€(args): ํŠน์ˆ˜ ๋ฌธ์ž ์ดˆ๊ณผ ์ˆ˜(2)

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('sqli-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('sqli-v33-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('sqli-v33-stable', {'sensitivity': 3})
4 evaluatePreconfiguredWaf('sqli-v33-stable', {'sensitivity': 4})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('sqli-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('sqli-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('sqli-stable', {'sensitivity': 3})
4 evaluatePreconfiguredWaf('sqli-stable', {'sensitivity': 4})

๊ต์ฐจ ์‚ฌ์ดํŠธ ์Šคํฌ๋ฆฝํŒ…(XSS)

๋‹ค์Œ ํ‘œ์—์„œ๋Š” XSS ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ WAF ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id941100-xss 1 libinjection์„ ํ†ตํ•œ XSS ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941110-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 1: ์Šคํฌ๋ฆฝํŠธ ํƒœ๊ทธ ๋ฒกํ„ฐ
owasp-crs-v030301-id941120-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 2: ์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ ๋ฒกํ„ฐ
owasp-crs-v030301-id941130-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 3: ์†์„ฑ ๋ฒกํ„ฐ
owasp-crs-v030301-id941140-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 4: ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ URI ๋ฒกํ„ฐ
owasp-crs-v030301-id941160-xss 1 NoScript XSS InjectionChecker: HTML ์‚ฝ์ž…
owasp-crs-v030301-id941170-xss 1 NoScript XSS InjectionChecker: ์†์„ฑ ์‚ฝ์ž…
owasp-crs-v030301-id941180-xss 1 Node-Validator ๋ธ”๋ž™๋ฆฌ์ŠคํŠธ ํ‚ค์›Œ๋“œ
owasp-crs-v030301-id941190-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941200-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941210-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941220-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941230-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941240-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941250-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941260-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941270-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941280-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941290-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941300-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941310-xss 1 US-ASCII ํ˜•์‹์ด ์ž˜๋ชป๋œ ์ธ์ฝ”๋”ฉ XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941350-xss 1 UTF-7 ์ธ์ฝ”๋”ฉ IE XSS - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941360-xss 1 ์ƒํ˜• ์ด๋ฏธ์ง€ ๋‚œ๋…ํ™”
owasp-crs-v030301-id941370-xss 1 JavaScript ์ „์—ญ ๋ณ€์ˆ˜๊ฐ€ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id941101-xss 2 libinjection์„ ํ†ตํ•œ XSS ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941150-xss 2 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 5: ํ—ˆ์šฉ๋˜์ง€ ์•Š๋Š” HTML ์†์„ฑ
owasp-crs-v030301-id941320-xss 2 ๊ฐ€๋Šฅํ•œ XSS ๊ณต๊ฒฉ์ด ํƒ์ง€๋จ - HTML ํƒœ๊ทธ ํ•ธ๋“ค๋Ÿฌ
owasp-crs-v030301-id941330-xss 2 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941340-xss 2 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030301-id941380-xss 2 AngularJS ํด๋ผ์ด์–ธํŠธ์ธก ํ…œํ”Œ๋ฆฟ ์‚ฝ์ž…์ด ๊ฐ์ง€๋จ

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
Not included 1 libinjection์„ ํ†ตํ•œ XSS ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941110-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 1: ์Šคํฌ๋ฆฝํŠธ ํƒœ๊ทธ ๋ฒกํ„ฐ
owasp-crs-v030001-id941120-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 2: ์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ ๋ฒกํ„ฐ
owasp-crs-v030001-id941130-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 3: ์†์„ฑ ๋ฒกํ„ฐ
owasp-crs-v030001-id941140-xss 1 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 4: ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ URI ๋ฒกํ„ฐ
owasp-crs-v030001-id941160-xss 1 NoScript XSS InjectionChecker: HTML ์‚ฝ์ž…
owasp-crs-v030001-id941170-xss 1 NoScript XSS InjectionChecker: ์†์„ฑ ์‚ฝ์ž…
owasp-crs-v030001-id941180-xss 1 Node-Validator ๋ธ”๋ž™๋ฆฌ์ŠคํŠธ ํ‚ค์›Œ๋“œ
owasp-crs-v030001-id941190-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941200-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941210-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941220-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941230-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941240-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941250-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941260-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941270-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941280-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941290-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941300-xss 1 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941310-xss 1 US-ASCII ํ˜•์‹์ด ์ž˜๋ชป๋œ ์ธ์ฝ”๋”ฉ XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941350-xss 1 UTF-7 ์ธ์ฝ”๋”ฉ IE XSS - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
Not included 1 JSFuck/์ƒํ˜•์ฒด ๋‚œ๋…ํ™”๊ฐ€ ๊ฐ์ง€๋จ
Not included 1 JavaScript ์ „์—ญ ๋ณ€์ˆ˜๊ฐ€ ๋ฐœ๊ฒฌ๋จ
Not included 2 libinjection์„ ํ†ตํ•œ XSS ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941150-xss 2 XSS ํ•„ํ„ฐ - ์นดํ…Œ๊ณ ๋ฆฌ 5: ํ—ˆ์šฉ๋˜์ง€ ์•Š๋Š” HTML ์†์„ฑ
owasp-crs-v030001-id941320-xss 2 ๊ฐ€๋Šฅํ•œ XSS ๊ณต๊ฒฉ์ด ํƒ์ง€๋จ - HTML ํƒœ๊ทธ ํ•ธ๋“ค๋Ÿฌ
owasp-crs-v030001-id941330-xss 2 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
owasp-crs-v030001-id941340-xss 2 IE XSS ํ•„ํ„ฐ - ๊ณต๊ฒฉ์ด ๊ฐ์ง€๋จ
Not included 2 AngularJS ํด๋ผ์ด์–ธํŠธ์ธก ํ…œํ”Œ๋ฆฟ ์‚ฝ์ž…์ด ๊ฐ์ง€๋จ

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('xss-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('xss-v33-stable', {'sensitivity': 2})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('xss-stable', {'sensitivity': 1})

๋กœ์ปฌ ํŒŒ์ผ ํฌํ•จ(LFI)

๋‹ค์Œ ํ‘œ์—์„œ๋Š” LFI ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id930100-lfi 1 ๊ฒฝ๋กœ ์ˆœํšŒ ๊ณต๊ฒฉ(/../)
owasp-crs-v030301-id930110-lfi 1 ๊ฒฝ๋กœ ์ˆœํšŒ ๊ณต๊ฒฉ(/../)
owasp-crs-v030301-id930120-lfi 1 OS ํŒŒ์ผ ์•ก์„ธ์Šค ์‹œ๋„
owasp-crs-v030301-id930130-lfi 1 ์ œํ•œ๋œ ํŒŒ์ผ ์•ก์„ธ์Šค ์‹œ๋„

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id930100-lfi 1 ๊ฒฝ๋กœ ์ˆœํšŒ ๊ณต๊ฒฉ(/../)
owasp-crs-v030001-id930110-lfi 1 ๊ฒฝ๋กœ ์ˆœํšŒ ๊ณต๊ฒฉ(/../)
owasp-crs-v030001-id930120-lfi 1 OS ํŒŒ์ผ ์•ก์„ธ์Šค ์‹œ๋„
owasp-crs-v030001-id930130-lfi 1 ์ œํ•œ๋œ ํŒŒ์ผ ์•ก์„ธ์Šค ์‹œ๋„

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. LFI์˜ ๋ชจ๋“  ์„œ๋ช…์€ ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ 1์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ ๊ตฌ์„ฑ์€ ๋ชจ๋“  ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('lfi-v33-stable', {'sensitivity': 1})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('lfi-stable', {'sensitivity': 1})

์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰(RCE)

๋‹ค์Œ ํ‘œ์—์„œ๋Š” RCE ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id932100-rce 1 UNIX ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030301-id932105-rce 1 UNIX ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030301-id932110-rce 1 Windows ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030301-id932115-rce 1 Windows ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030301-id932120-rce 1 Windows PowerShell ๋ช…๋ น์–ด ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id932130-rce 1 Unix ์…ธ ํ‘œํ˜„์‹ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id932140-rce 1 Windows FOR/IF ๋ช…๋ น์–ด ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id932150-rce 1 Direct UNIX ๋ช…๋ น์–ด ์‹คํ–‰
owasp-crs-v030301-id932160-rce 1 UNIX ์…ธ ์ฝ”๋“œ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id932170-rce 1 Shellshock(CVE-2014-6271)
owasp-crs-v030301-id932171-rce 1 Shellshock(CVE-2014-6271)
owasp-crs-v030301-id932180-rce 1 ์ œํ•œ๋œ ํŒŒ์ผ ์—…๋กœ๋“œ ์‹œ๋„
owasp-crs-v030301-id932200-rce 2 RCE ์šฐํšŒ ๊ธฐ์ˆ 
owasp-crs-v030301-id932106-rce 3 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: Unix ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030301-id932190-rce 3 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์™€์ผ๋“œ ์นด๋“œ ์šฐํšŒ ๊ธฐ์ˆ  ์‹œ๋„

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id932100-rce 1 UNIX ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030001-id932105-rce 1 UNIX ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030001-id932110-rce 1 Windows ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030001-id932115-rce 1 Windows ๋ช…๋ น์–ด ์‚ฝ์ž…
owasp-crs-v030001-id932120-rce 1 Windows PowerShell ๋ช…๋ น์–ด ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id932130-rce 1 Unix ์…ธ ํ‘œํ˜„์‹ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id932140-rce 1 Windows FOR/IF ๋ช…๋ น์–ด ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id932150-rce 1 Direct UNIX ๋ช…๋ น์–ด ์‹คํ–‰
owasp-crs-v030001-id932160-rce 1 UNIX ์…ธ ์ฝ”๋“œ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id932170-rce 1 Shellshock(CVE-2014-6271)
owasp-crs-v030001-id932171-rce 1 Shellshock(CVE-2014-6271)
Not included 1 ์ œํ•œ๋œ ํŒŒ์ผ ์—…๋กœ๋“œ ์‹œ๋„
Not included 2 RCE ์šฐํšŒ ๊ธฐ์ˆ 
Not included 3 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: Unix ๋ช…๋ น์–ด ์‚ฝ์ž…
Not included 3 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์™€์ผ๋“œ ์นด๋“œ ์šฐํšŒ ๊ธฐ์ˆ  ์‹œ๋„

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. RCE์˜ ๋ชจ๋“  ์„œ๋ช…์€ ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ 1์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ ๊ตฌ์„ฑ์€ ๋ชจ๋“  ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('rce-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('rce-v33-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('rce-v33-stable', {'sensitivity': 3})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('rce-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('rce-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('rce-stable', {'sensitivity': 3})

์›๊ฒฉ ํŒŒ์ผ ํฌํ•จ(RCI)

๋‹ค์Œ ํ‘œ์—์„œ๋Š” RFI ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id931100-rfi 1 IP ์ฃผ์†Œ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” URL ๋งค๊ฐœ๋ณ€์ˆ˜
owasp-crs-v030301-id931110-rfi 1 URL ํŽ˜์ด๋กœ๋“œ์™€ ํ•จ๊ป˜ ์‚ฌ์šฉ๋˜๋Š” ์ผ๋ฐ˜์ ์ธ RFI ์ทจ์•ฝ ๋งค๊ฐœ๋ณ€์ˆ˜ ์ด๋ฆ„
owasp-crs-v030301-id931120-rfi 1 ๋ฌผ์Œํ‘œ ๋ฌธ์ž(?)๊ฐ€ ๋’ค์— ์˜ค๋Š” URL ํŽ˜์ด๋กœ๋“œ
owasp-crs-v030301-id931130-rfi 2 ๋„๋ฉ”์ธ ์™ธ๋ถ€ ์ฐธ์กฐ/๋งํฌ

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id931100-rfi 1 IP ์ฃผ์†Œ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” URL ๋งค๊ฐœ๋ณ€์ˆ˜
owasp-crs-v030001-id931110-rfi 1 URL ํŽ˜์ด๋กœ๋“œ์™€ ํ•จ๊ป˜ ์‚ฌ์šฉ๋˜๋Š” ์ผ๋ฐ˜์ ์ธ RFI ์ทจ์•ฝ ๋งค๊ฐœ๋ณ€์ˆ˜ ์ด๋ฆ„
owasp-crs-v030001-id931120-rfi 1 ๋ฌผ์Œํ‘œ ๋ฌธ์ž(?)๊ฐ€ ๋’ค์— ์˜ค๋Š” URL ํŽ˜์ด๋กœ๋“œ
owasp-crs-v030001-id931130-rfi 2 ๋„๋ฉ”์ธ ์™ธ๋ถ€ ์ฐธ์กฐ/๋งํฌ

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('rfi-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('rfi-v33-stable', {'sensitivity': 2})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('rfi-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('rfi-stable', {'sensitivity': 2})

๋ฉ”์„œ๋“œ ์ ์šฉ

๋‹ค์Œ ํ‘œ์—์„œ๋Š” ๋ฉ”์„œ๋“œ ์ ์šฉ ์‚ฌ์ „ ๊ตฌ์„ฑ ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id911100-methodenforcement 1 ์ •์ฑ…์ด ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š” ๋ฉ”์„œ๋“œ

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id911100-methodenforcement 1 ์ •์ฑ…์ด ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š” ๋ฉ”์„œ๋“œ

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('methodenforcement-v33-stable', {'sensitivity': 1})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('methodenforcement-stable', {'sensitivity': 1})

์Šค์บ๋„ˆ ๊ฐ์ง€

๋‹ค์Œ ํ‘œ์—์„œ๋Š” ์Šค์บ๋„ˆ ๊ฐ์ง€ ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id913100-scannerdetection 1 ๋ณด์•ˆ ์Šค์บ๋„ˆ์™€ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ ๋ฐœ๊ฒฌ
owasp-crs-v030301-id913110-scannerdetection 1 ๋ณด์•ˆ ์Šค์บ๋„ˆ์™€ ์—ฐ๊ฒฐ๋œ ์š”์ฒญ ํ—ค๋” ๋ฐœ๊ฒฌ
owasp-crs-v030301-id913120-scannerdetection 1 ๋ณด์•ˆ ์Šค์บ๋„ˆ์™€ ์—ฐ๊ฒฐ๋œ ์š”์ฒญ ํŒŒ์ผ ์ด๋ฆ„/์ธ์ˆ˜ ๋ฐœ๊ฒฌ
owasp-crs-v030301-id913101-scannerdetection 2 ์Šคํฌ๋ฆฝํŒ…/์ผ๋ฐ˜ HTTP ํด๋ผ์ด์–ธํŠธ์™€ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ ๋ฐœ๊ฒฌ
owasp-crs-v030301-id913102-scannerdetection 2 ์›น ํฌ๋กค๋Ÿฌ/๋ด‡๊ณผ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ ๋ฐœ๊ฒฌ

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id913100-scannerdetection 1 ๋ณด์•ˆ ์Šค์บ๋„ˆ์™€ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ ๋ฐœ๊ฒฌ
owasp-crs-v030001-id913110-scannerdetection 1 ๋ณด์•ˆ ์Šค์บ๋„ˆ์™€ ์—ฐ๊ฒฐ๋œ ์š”์ฒญ ํ—ค๋” ๋ฐœ๊ฒฌ
owasp-crs-v030001-id913120-scannerdetection 1 ๋ณด์•ˆ ์Šค์บ๋„ˆ์™€ ์—ฐ๊ฒฐ๋œ ์š”์ฒญ ํŒŒ์ผ ์ด๋ฆ„/์ธ์ˆ˜ ๋ฐœ๊ฒฌ
owasp-crs-v030001-id913101-scannerdetection 2 ์Šคํฌ๋ฆฝํŒ…/์ผ๋ฐ˜ HTTP ํด๋ผ์ด์–ธํŠธ์™€ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ ๋ฐœ๊ฒฌ
owasp-crs-v030001-id913102-scannerdetection 2 ์›น ํฌ๋กค๋Ÿฌ/๋ด‡๊ณผ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ ๋ฐœ๊ฒฌ

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('scannerdetection-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('scannerdetection-v33-stable', {'sensitivity': 2})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('scannerdetection-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('scannerdetection-stable', {'sensitivity': 2})

ํ”„๋กœํ† ์ฝœ ๊ณต๊ฒฉ

๋‹ค์Œ ํ‘œ๋Š” ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ํ”„๋กœํ† ์ฝœ ๊ณต๊ฒฉ ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
Not included 1 HTTP ์š”์ฒญ ์Šค๋จธ๊ธ€๋ง ๊ณต๊ฒฉ
owasp-crs-v030301-id921110-protocolattack 1 HTTP ์š”์ฒญ ์Šค๋จธ๊ธ€๋ง ๊ณต๊ฒฉ
owasp-crs-v030301-id921120-protocolattack 1 HTTP ์‘๋‹ต ๋ถ„ํ•  ๊ณต๊ฒฉ
owasp-crs-v030301-id921130-protocolattack 1 HTTP ์‘๋‹ต ๋ถ„ํ•  ๊ณต๊ฒฉ
owasp-crs-v030301-id921140-protocolattack 1 ํ—ค๋”๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id921150-protocolattack 1 ํŽ˜์ด๋กœ๋“œ๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ(CR/LF ๊ฐ์ง€๋จ)
owasp-crs-v030301-id921160-protocolattack 1 ํŽ˜์ด๋กœ๋“œ๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ(CR/LF ๋ฐ ํ—ค๋” ์ด๋ฆ„ ๊ฐ์ง€๋จ)
owasp-crs-v030301-id921190-protocolattack 1 HTTP ๋ถ„ํ• (์š”์ฒญ ํŒŒ์ผ ์ด๋ฆ„์˜ CR/LF ๊ฐ์ง€๋จ)
owasp-crs-v030301-id921200-protocolattack 1 LDAP ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030301-id921151-protocolattack 2 ํŽ˜์ด๋กœ๋“œ๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ(CR/LF ๊ฐ์ง€๋จ)
owasp-crs-v030301-id921170-protocolattack 3 HTTP ๋งค๊ฐœ๋ณ€์ˆ˜ ์˜ค์—ผ

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id921100-protocolattack 1 HTTP ์š”์ฒญ ์Šค๋จธ๊ธ€๋ง ๊ณต๊ฒฉ
owasp-crs-v030001-id921110-protocolattack 1 HTTP ์š”์ฒญ ์Šค๋จธ๊ธ€๋ง ๊ณต๊ฒฉ
owasp-crs-v030001-id921120-protocolattack 1 HTTP ์‘๋‹ต ๋ถ„ํ•  ๊ณต๊ฒฉ
owasp-crs-v030001-id921130-protocolattack 1 HTTP ์‘๋‹ต ๋ถ„ํ•  ๊ณต๊ฒฉ
owasp-crs-v030001-id921140-protocolattack 1 ํ—ค๋”๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030001-id921150-protocolattack 1 ํŽ˜์ด๋กœ๋“œ๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ(CR/LF ๊ฐ์ง€๋จ)
owasp-crs-v030001-id921160-protocolattack 1 ํŽ˜์ด๋กœ๋“œ๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ(CR/LF ๋ฐ ํ—ค๋” ์ด๋ฆ„ ๊ฐ์ง€๋จ)
Not included 1 HTTP ๋ถ„ํ• (์š”์ฒญ ํŒŒ์ผ ์ด๋ฆ„์˜ CR/LF ๊ฐ์ง€๋จ)
Not included 1 LDAP ์‚ฝ์ž… ๊ณต๊ฒฉ
owasp-crs-v030001-id921151-protocolattack 2 ํŽ˜์ด๋กœ๋“œ๋ฅผ ํ†ตํ•œ HTTP ํ—ค๋” ์‚ฝ์ž… ๊ณต๊ฒฉ(CR/LF ๊ฐ์ง€๋จ)
owasp-crs-v030001-id921170-protocolattack 3 HTTP ๋งค๊ฐœ๋ณ€์ˆ˜ ์˜ค์—ผ

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('protocolattack-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('protocolattack-v33-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('protocolattack-v33-stable', {'sensitivity': 3})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('protocolattack-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('protocolattack-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('protocolattack-stable', {'sensitivity': 3})

PHP

๋‹ค์Œ ํ‘œ์—์„œ๋Š” PHP ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id933100-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ๊ณต๊ฐœ ํƒœ๊ทธ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933110-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ์Šคํฌ๋ฆฝํŠธ ํŒŒ์ผ ์—…๋กœ๋“œ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933120-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๊ตฌ์„ฑ ์ง€์‹œ๋ฌธ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933130-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933140-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: I/O ์ŠคํŠธ๋ฆผ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933200-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ž˜ํผ ์Šคํ‚ค๋งˆ ๊ฐ์ง€๋จ
owasp-crs-v030301-id933150-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๊ณ ์œ„ํ—˜ PHP ํ•จ์ˆ˜ ์ด๋ฆ„ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933160-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๊ณ ์œ„ํ—˜ PHP ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933170-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ง๋ ฌํ™”๋œ ๊ฐ์ฒด ์‚ฝ์ž…
owasp-crs-v030301-id933180-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933210-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933151-php 2 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ค‘์œ„ํ—˜ PHP ํ•จ์ˆ˜ ์ด๋ฆ„ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933131-php 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933161-php 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋‚ฎ์€ ๊ฐ’์˜ PHP ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933111-php 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ์Šคํฌ๋ฆฝํŠธ ํŒŒ์ผ ์—…๋กœ๋“œ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030301-id933190-php 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ๋‹ซ๋Š” ํƒœ๊ทธ ๋ฐœ๊ฒฌ๋จ

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id933100-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ๊ณต๊ฐœ ํƒœ๊ทธ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933110-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ์Šคํฌ๋ฆฝํŠธ ํŒŒ์ผ ์—…๋กœ๋“œ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933120-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๊ตฌ์„ฑ ์ง€์‹œ๋ฌธ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933130-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933140-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: I/O ์ŠคํŠธ๋ฆผ ๋ฐœ๊ฒฌ๋จ
Not included 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ž˜ํผ ์Šคํ‚ค๋งˆ ๊ฐ์ง€๋จ
owasp-crs-v030001-id933150-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๊ณ ์œ„ํ—˜ PHP ํ•จ์ˆ˜ ์ด๋ฆ„ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933160-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๊ณ ์œ„ํ—˜ PHP ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933170-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ง๋ ฌํ™”๋œ ๊ฐ์ฒด ์‚ฝ์ž…
owasp-crs-v030001-id933180-php 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
Not included 1 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933151-php 2 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ์ค‘์œ„ํ—˜ PHP ํ•จ์ˆ˜ ์ด๋ฆ„ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933131-php 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋ณ€์ˆ˜ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933161-php 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: ๋‚ฎ์€ ๊ฐ’์˜ PHP ํ•จ์ˆ˜ ํ˜ธ์ถœ ๋ฐœ๊ฒฌ๋จ
owasp-crs-v030001-id933111-php 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ์Šคํฌ๋ฆฝํŠธ ํŒŒ์ผ ์—…๋กœ๋“œ ๋ฐœ๊ฒฌ๋จ
Not included 3 PHP ์‚ฝ์ž… ๊ณต๊ฒฉ: PHP ๋‹ซ๋Š” ํƒœ๊ทธ ๋ฐœ๊ฒฌ๋จ

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('php-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('php-v33-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('php-v33-stable', {'sensitivity': 3})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('php-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('php-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('php-stable', {'sensitivity': 3})

์„ธ์…˜ ๊ณ ์ •

๋‹ค์Œ ํ‘œ๋Š” ์„ธ์…˜ ๊ณ ์ • ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id943100-sessionfixation 1 ๊ฐ€๋Šฅํ•œ ์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ: HTML์—์„œ ์ฟ ํ‚ค ๊ฐ’ ์„ค์ •
owasp-crs-v030301-id943110-sessionfixation 1 ๊ฐ€๋Šฅํ•œ ์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ: ์˜คํ”„ ๋„๋ฉ”์ธ ๋ฆฌํผ๋Ÿฌ๊ฐ€ ํฌํ•จ๋œ SessionID ๋งค๊ฐœ๋ณ€์ˆ˜ ์ด๋ฆ„
owasp-crs-v030301-id943120-sessionfixation 1 ๊ฐ€๋Šฅํ•œ ์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ: ๋ฆฌํผ๋Ÿฌ๊ฐ€ ์—†๋Š” SessionID ๋งค๊ฐœ๋ณ€์ˆ˜ ์ด๋ฆ„

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id943100-sessionfixation 1 ๊ฐ€๋Šฅํ•œ ์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ: HTML์—์„œ ์ฟ ํ‚ค ๊ฐ’ ์„ค์ •
owasp-crs-v030001-id943110-sessionfixation 1 ๊ฐ€๋Šฅํ•œ ์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ: ์˜คํ”„ ๋„๋ฉ”์ธ ๋ฆฌํผ๋Ÿฌ๊ฐ€ ํฌํ•จ๋œ SessionID ๋งค๊ฐœ๋ณ€์ˆ˜ ์ด๋ฆ„
owasp-crs-v030001-id943120-sessionfixation 1 ๊ฐ€๋Šฅํ•œ ์„ธ์…˜ ๊ณ ์ • ๊ณต๊ฒฉ: ๋ฆฌํผ๋Ÿฌ๊ฐ€ ์—†๋Š” SessionID ๋งค๊ฐœ๋ณ€์ˆ˜ ์ด๋ฆ„

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์„ธ์…˜ ๊ณ ์ •์˜ ๋ชจ๋“  ์„œ๋ช…์€ ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ 1์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ ๊ตฌ์„ฑ์€ ๋ชจ๋“  ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('sessionfixation-v33-stable', {'sensitivity': 1})

CRS 3.0

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('sessionfixation-stable', {'sensitivity': 1})

Java ๊ณต๊ฒฉ

๋‹ค์Œ ํ‘œ์—์„œ๋Š” ์ž๋ฐ” ๊ณต๊ฒฉ ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id944100-java 1 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์˜์‹ฌ์Šค๋Ÿฌ์šด Java ํด๋ž˜์Šค๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id944110-java 1 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์ž๋ฐ” ํ”„๋กœ์„ธ์Šค ์ƒ์„ฑ(CVE-2017-9805)
owasp-crs-v030301-id944120-java 1 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์ž๋ฐ” ์ง๋ ฌํ™”(CVE-2015-4852)
owasp-crs-v030301-id944130-java 1 ์˜์‹ฌ์Šค๋Ÿฌ์šด Java ํด๋ž˜์Šค๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id944200-java 2 ๋งค์ง ๋ฐ”์ดํŠธ๊ฐ€ ๊ฐ์ง€๋จ, ์ž๋ฐ” ์ง๋ ฌํ™”๋ฅผ ์‚ฌ์šฉ ์ค‘์ผ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Œ
owasp-crs-v030301-id944210-java 2 Base64๋กœ ์ธ์ฝ”๋”ฉ๋œ ๋งค์ง ๋ฐ”์ดํŠธ๊ฐ€ ๊ฐ์ง€๋จ, ์ž๋ฐ” ์ง๋ ฌํ™”๋ฅผ ์‚ฌ์šฉ ์ค‘์ผ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Œ
owasp-crs-v030301-id944240-java 2 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์ž๋ฐ” ์ง๋ ฌํ™”(CVE-2015-4852)
owasp-crs-v030301-id944250-java 2 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์˜์‹ฌ์Šค๋Ÿฌ์šด Java ๋ฉ”์„œ๋“œ๊ฐ€ ๊ฐ์ง€๋จ
owasp-crs-v030301-id944300-java 3 ์ผ์น˜ํ•˜๋Š” ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ‚ค์›Œ๋“œ๊ฐ€ ์žˆ๋Š” Base64๋กœ ์ธ์ฝ”๋”ฉ๋œ ๋ฌธ์ž์—ด

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
Not included 1 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์˜์‹ฌ์Šค๋Ÿฌ์šด Java ํด๋ž˜์Šค๊ฐ€ ๊ฐ์ง€๋จ
Not included 1 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์ž๋ฐ” ํ”„๋กœ์„ธ์Šค ์ƒ์„ฑ(CVE-2017-9805)
Not included 1 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์ž๋ฐ” ์ง๋ ฌํ™”(CVE-2015-4852)
Not included 1 ์˜์‹ฌ์Šค๋Ÿฌ์šด Java ํด๋ž˜์Šค๊ฐ€ ๊ฐ์ง€๋จ
Not included 2 ๋งค์ง ๋ฐ”์ดํŠธ๊ฐ€ ๊ฐ์ง€๋จ, ์ž๋ฐ” ์ง๋ ฌํ™”๋ฅผ ์‚ฌ์šฉ ์ค‘์ผ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Œ
Not included 2 Base64๋กœ ์ธ์ฝ”๋”ฉ๋œ ๋งค์ง ๋ฐ”์ดํŠธ๊ฐ€ ๊ฐ์ง€๋จ, ์ž๋ฐ” ์ง๋ ฌํ™”๋ฅผ ์‚ฌ์šฉ ์ค‘์ผ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Œ
Not included 2 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์ž๋ฐ” ์ง๋ ฌํ™”(CVE-2015-4852)
Not included 2 ์›๊ฒฉ ๋ช…๋ น์–ด ์‹คํ–‰: ์˜์‹ฌ์Šค๋Ÿฌ์šด Java ๋ฉ”์„œ๋“œ๊ฐ€ ๊ฐ์ง€๋จ
Not included 3 ์ผ์น˜ํ•˜๋Š” ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ‚ค์›Œ๋“œ๊ฐ€ ์žˆ๋Š” Base64๋กœ ์ธ์ฝ”๋”ฉ๋œ ๋ฌธ์ž์—ด

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('java-v33-stable', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('java-v33-stable', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('java-v33-stable', {'sensitivity': 3})

NodeJS ๊ณต๊ฒฉ

๋‹ค์Œ ํ‘œ์—์„œ๋Š” NodeJS ๊ณต๊ฒฉ ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ์˜ ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ WAF ๊ทœ์น™ ์„œ๋ช…์€ CRS 3.3์—๋งŒ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

CRS 3.3

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030301-id934100-nodejs 1 Node.js ์‚ฝ์ž… ๊ณต๊ฒฉ

CRS 3.0

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
Not included 1 Node.js ์‚ฝ์ž… ๊ณต๊ฒฉ

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. NodeJS ๊ณต๊ฒฉ์˜ ๋ชจ๋“  ์„œ๋ช…์€ ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ 1์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ ๊ตฌ์„ฑ์€ ๋‹ค๋ฅธ ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('nodejs-v33-stable', {'sensitivity': 1})

CVE ๋ฐ ๊ธฐํƒ€ ์ทจ์•ฝ์ 

๋‹ค์Œ ํ‘œ์—์„œ๋Š” CVE Log4j RCE ์ทจ์•ฝ์  ์‚ฌ์ „ ๊ตฌ์„ฑ ๊ทœ์น™์—์„œ ์ง€์›๋˜๋Š” ๊ฐ ์„œ๋ช…์˜ ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-v030001-id044228-cve 1 CVE-2021-44228 ๋ฐ CVE-2021-45046์˜ ์•…์šฉ ์‹œ๋„๋ฅผ ๊ฐ์ง€ํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋˜๋Š” ๊ธฐ๋ณธ ๊ทœ์น™
owasp-crs-v030001-id144228-cve 1 ๋” ๋งŽ์€ ์šฐํšŒ ๋ฐ ๋‚œ๋…ํ™” ์‹œ๋„๋ฅผ ์ฒ˜๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด Google์—์„œ ์ œ๊ณตํ•˜๋Š” ๊ฐœ์„ ์‚ฌํ•ญ
owasp-crs-v030001-id244228-cve 3 ๋” ๋งŽ์€ ์šฐํšŒ ๋ฐ ๋‚œ๋…ํ™” ์‹œ๋„๋ฅผ ํฌํ•จํ•˜๊ธฐ ์œ„ํ•œ ๊ฐ์ง€ ๋ฏผ๊ฐ๋„ ์ฆ๊ฐ€ ๋ฐ ๊ฑฐ์ง“์–‘์„ฑ ๊ฐ์ง€ ์œ„ํ—˜์˜ ๋ช…๋ชฉ์ƒ ์ฆ๊ฐ€
owasp-crs-v030001-id344228-cve 3 base64 ์ธ์ฝ”๋”ฉ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋” ๋งŽ์€ ์šฐํšŒ ๋ฐ ๋‚œ๋…ํ™” ์‹œ๋„๋ฅผ ํฌํ•จํ•˜๊ธฐ ์œ„ํ•œ ๊ฐ์ง€ ๋ฏผ๊ฐ๋„ ์ฆ๊ฐ€ ๋ฐ ๊ฑฐ์ง“์–‘์„ฑ ๊ฐ์ง€ ์œ„ํ—˜์˜ ๋ช…๋ชฉ์ƒ ์ฆ๊ฐ€

์‚ฌ์ „ ์„ค์ •๋œ ๋ฏผ๊ฐ๋„ ๋งค๊ฐœ๋ณ€์ˆ˜์™€ ํ•จ๊ป˜ evaluatePreconfiguredWaf()๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŠน์ • ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€์—์„œ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ทœ์น™ ์ง‘ํ•ฉ ๋ฏผ๊ฐ๋„๋ฅผ ๊ตฌ์„ฑํ•˜์ง€ ์•Š์œผ๋ฉด Google Cloud Armor๊ฐ€ ๋ชจ๋“  ์„œ๋ช…์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ํ‘œํ˜„์‹
1 evaluatePreconfiguredWaf('cve-canary', {'sensitivity': 1})
2 evaluatePreconfiguredWaf('cve-canary', {'sensitivity': 2})
3 evaluatePreconfiguredWaf('cve-canary', {'sensitivity': 3})

JSON ํ˜•์‹ ์ฝ˜ํ…์ธ  SQLi ์ทจ์•ฝ์ 

๋‹ค์Œ ํ‘œ์—๋Š” ์„œ๋ช… ID, ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€, ์ง€์›๋˜๋Š” ์„œ๋ช… 942550-sqli์˜ ์„ค๋ช…์ด ๋‚˜์™€ ์žˆ์œผ๋ฉฐ, ์ด๋Š” ์•…์„ฑ ๊ณต๊ฒฉ์ž๊ฐ€ SQL ์‚ฝ์ž… ํŽ˜์ด๋กœ๋“œ์— JSON ๊ตฌ๋ฌธ์„ ์ถ”๊ฐ€ํ•˜์—ฌ WAF๋ฅผ ์šฐํšŒํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์„ ๋‹ค๋ฃน๋‹ˆ๋‹ค.

์„œ๋ช… ID(๊ทœ์น™ ID) ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ ์„ค๋ช…
owasp-crs-id942550-sqli 2 URL์—์„œ ๋ฐœ๊ฒฌ๋œ SQLi ์„œ๋ช…์„ ํฌํ•จํ•œ ๋ชจ๋“  JSON ๊ธฐ๋ฐ˜ SQLi ๋ฒกํ„ฐ ๊ฐ์ง€

๋‹ค์Œ ํ‘œํ˜„์‹์„ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋ช…์„ ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค.

  evaluatePreconfiguredWaf('json-sqli-canary', {'sensitivity':0, 'opt_in_rule_ids': ['owasp-crs-id942550-sqli']})
  

๋˜ํ•œ ๋ฏผ๊ฐ๋„ ์ˆ˜์ค€ 2์—์„œ sqli-v33-stable์„ ์‚ฌ์šฉ ์„ค์ •ํ•˜์—ฌ JSON ๊ธฐ๋ฐ˜ SQL ์‚ฝ์ž… ์šฐํšŒ๋ฅผ ์™„์ „ํžˆ ์ฒ˜๋ฆฌํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

์ œํ•œ์‚ฌํ•ญ

Google Cloud Armor ์‚ฌ์ „ ๊ตฌ์„ฑ WAF ๊ทœ์น™์—๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ œํ•œ์‚ฌํ•ญ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

  • WAF ๊ทœ์น™ ๋ณ€๊ฒฝ์‚ฌํ•ญ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์ „๋‹ฌ๋˜๋Š” ๋ฐ ๋ช‡ ๋ถ„ ์ •๋„ ๊ฑธ๋ฆฝ๋‹ˆ๋‹ค.
  • Google Cloud Armor๋Š” ์š”์ฒญ ๋ณธ๋ฌธ์ด ์žˆ๋Š” HTTP ์š”์ฒญ ์œ ํ˜• ์ค‘์—์„œ POST ์š”์ฒญ๋งŒ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค. Google Cloud Armor๋Š” POST ๋ณธ๋ฌธ ์ฝ˜ํ…์ธ ์˜ ์ฒ˜์Œ 8KB์— ๋Œ€ํ•ด ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ ๊ทœ์น™์„ ํ‰๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ POST ๋ณธ๋ฌธ ๊ฒ€์‚ฌ ์ œํ•œ์‚ฌํ•ญ์„ ์ฐธ์กฐํ•˜์„ธ์š”.
  • Google Cloud Armor๋Š” JSON ๊ตฌ๋ฌธ ๋ถ„์„์ด ์ผ์น˜ํ•˜๋Š” Content-Type ํ—ค๋” ๊ฐ’์œผ๋กœ ์‚ฌ์šฉ ์„ค์ •๋œ ๊ฒฝ์šฐ JSON ํ˜•์‹ ์ฝ˜ํ…์ธ (์ œ๋Œ€๋กœ ํฌ๋งท๋œ HTTP๋ฅผ ํ†ตํ•œ GraphQL ์š”์ฒญ ํฌํ•จ)์— ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ WAF ๊ทœ์น™์„ ํŒŒ์‹ฑํ•˜๊ณ  ์ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ JSON ํŒŒ์‹ฑ์„ ์ฐธ์กฐํ•˜์„ธ์š”.
  • ์‚ฌ์ „ ๊ตฌ์„ฑ๋œ WAF ๊ทœ์น™์— ์š”์ฒญ ํ•„๋“œ ์ œ์™ธ๊ฐ€ ์—ฐ๊ฒฐ๋œ ๊ฒฝ์šฐ์—๋Š” allow ์ž‘์—…์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์˜ˆ์™ธ์— ์ผ์น˜ํ•˜๋Š” ์š”์ฒญ์€ ์ž๋™์œผ๋กœ ํ—ˆ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ ๋‹จ๊ณ„