Forum Discussion
F5 ASM | Bot Signature
Hi!
I need to create a signature based in more than one header in the request payload. I see some articles about the bot signatures and if i understand correctly the signature only work for the User-agent header... this is correct?
My signature need to be created based in other headers regarding the User-agent.
Thanks
TP
- Jeffrey_GranierEmployee
Hi TP,
Yes you are correct the limitation is stated in the KB article below:
Bot signatures are developed using Snort syntax to search for bots in either the User-Agent field of the header or the URL, or both.
Hi tpimpao,
seems you are right. Testing with 16.1 and 17.1 the "Advanced Mode" only allows the following tags:
- headercontent (cannot be used without useragentonly)
- uricontent
Other options and modifiers (as documented in https://techdocs.f5.com/en-us/bigip-14-1-0/big-ip-asm-attack-and-bot-signatures-14-1-0/signature-syntax.html) do not work.
Please read also: BIG-IP Application Security Manager: Attack and Bot Signatures > Writing Custom Bot SignaturesYou could write an iRule, that will check for multiple headers or others attributes of the HTTP request and then block the request.
KR,
Daniel- tpimpaoAltostratus
Thanks!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com