F5 Rules for AWS WAF - Rule ID to Attack Type Reference
F5 offers security solutions for AWS customers who use the platform's hosting and load balancing services along with the AWS WAF offering.
F5 Rules for AWS WAF - Web exploits OWASP RulesF5 Rules for AWS WAF - Bot Protection RulesF5 Rules for AWS WAF - Common Vulnerabilities and Exposures (CVE)F5 Rules for AWS WAF - API Security Rules
With the recent addition of logging capabilities of requests that had a match with one of the rule sets, there is now an option to:
- See the full request that had a match with the rule ID.
- Understand the attack type that relates to the rule ID.
- Remove specific rule ID from the rule set in the case it generates false positives.
The following CSV maps between rule IDs and attack types, and will help customers of the F5 Rules for AWS WAF products to better manage rule exclusions in their Access Lists.
For more details on AWS-WAF logging configuration please visit:https://docs.aws.amazon.com/waf/latest/developerguide/logging.html
- Jat_BhogalNimbostratus
That CSV file doesn't exist anymore. Can somebody please update this post, with an updates link to the CSV file ASAP.
Thanks
Jat
- Jat_BhogalNimbostratus
Please update this post asap with a valid document link.
- Chase_AbbottEmployee
Updated.
- Jat_BhogalNimbostratus
Thanks Chase, can we please keep on top of the content in the csv file. I'm sure the rules being exploited are changing very frequently meaning that this document needs to follow suit?
- Jat_BhogalNimbostratus
For the fact that my company pays a subscription to F5 for this WAF Marketplace rule, I think I'm more than within my rights to be asking for this.
- Chase_AbbottEmployee
The team responsible for this does maintain the file, in this particular case the file had an invalid URL due to our recent migration. The file is now part of the article moving forward and will stay current by the team that manages the AWS subscription service.
- Jat_BhogalNimbostratus
Ok, thanks for addressing this Chase. No doubt I will be coming back to this document frequently.
Regards
Jat
- worapojcAltostratus
It seems the attached file is corrupted. Could you please re-upload the file?
worapojc - the file appears to have been corrected. Thanks for letting us know.