cancel
Showing results for 
Search instead for 
Did you mean: 
Login & Join the DevCentral Connects Group to watch the Recorded LiveStream (May 12) on Basic iControl Security - show notes included.
Nir_Zigler_7297
Altostratus
Altostratus

F5 offers security solutions for AWS customers who use the platform's hosting and load balancing services along with the AWS WAF offering.


F5 Rules for AWS WAF - Web exploits OWASP RulesF5 Rules for AWS WAF - Bot Protection RulesF5 Rules for AWS WAF - Common Vulnerabilities and Exposures (CVE)F5 Rules for AWS WAF - API Security Rules


With the recent addition of logging capabilities of requests that had a match with one of the rule sets, there is now an option to:


  1. See the full request that had a match with the rule ID.
  2. Understand the attack type that relates to the rule ID.
  3. Remove specific rule ID from the rule set in the case it generates false positives.


The following CSV maps between rule IDs and attack types, and will help customers of the F5 Rules for AWS WAF products to better manage rule exclusions in their Access Lists.


For more details on AWS-WAF logging configuration please visit:https://docs.aws.amazon.com/waf/latest/developerguide/logging.html

Comments
Jat_Bhogal
Nimbostratus
Nimbostratus

That CSV file doesn't exist anymore. Can somebody please update this post, with an updates link to the CSV file ASAP.

 

Thanks

 

Jat

Jat_Bhogal
Nimbostratus
Nimbostratus

Please update this post asap with a valid document link.

Chase_Abbott
F5 Employee
F5 Employee

  Updated.

Jat_Bhogal
Nimbostratus
Nimbostratus

Thanks Chase, can we please keep on top of the content in the csv file. I'm sure the rules being exploited are changing very frequently meaning that this document needs to follow suit?

Jat_Bhogal
Nimbostratus
Nimbostratus

For the fact that my company pays a subscription to F5 for this WAF Marketplace rule, I think I'm more than within my rights to be asking for this.

Chase_Abbott
F5 Employee
F5 Employee

  The team responsible for this does maintain the file, in this particular case the file had an invalid URL due to our recent migration. The file is now part of the article moving forward and will stay current by the team that manages the AWS subscription service.

Jat_Bhogal
Nimbostratus
Nimbostratus

Ok, thanks for addressing this Chase. No doubt I will be coming back to this document frequently.

 

Regards

 

Jat

Version history
Last update:
‎21-Jan-2019 03:00
Updated by:
Contributors