全球主机交流论坛

标题: 请教Cloudflare的WAF防火墙Package: OWASP ModSecurity Core Rule Set作用 [打印本页]

作者: t9913085    时间: 2015-10-17 23:16
标题: 请教Cloudflare的WAF防火墙Package: OWASP ModSecurity Core Rule Set作用
What is OWASP?

This package consists of rulesets derived from the OWASP ModSecurity Core Rule Set. These provide an easily pluggable set of generic attack detection rules that provide a base level of protection for any web application.

The OWASP rules operate in scoring threshold mode: each match against a rule increases the threat score of that request. Once a request exceeds a configurable sensitivity threshold (off, low, or high), the action is taken. This action can be simulate (create a log entry but do not block the request), challenge (present the user with an in-browser challenge page, and log), or block (reject the request and log).

Individual rule groups within the OWASP package can be enabled or disabled in "rule details", after which rules can be managed at the individual rule level through the advanced option.
作者: 62900015    时间: 2015-10-17 23:34
比较直白的翻译——web漏洞防御。




欢迎光临 全球主机交流论坛 (https://d.168530.xyz/) Powered by Discuz! X3.4