ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ืžืขืจื›ื•ืช ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ืžื•ื“ืจื ื™ื•ืช (WAF) ืฆืจื™ื›ื” ืœื”ื™ื•ืช ื”ืจื‘ื” ื™ื•ืชืจ ืจื—ื‘ื” ืžืจืฉื™ืžืช ื”ืคื’ื™ืขื•ื™ื•ืช ืž-OWASP Top 10

ืจึถื˜ืจื•ึนืกืคึผึถืงื˜ึดื™ื‘ึดื™

ื”ื”ื™ืงืฃ, ื”ื”ืจื›ื‘ ื•ื”ื”ืจื›ื‘ ืฉืœ ืื™ื•ืžื™ ืกื™ื™ื‘ืจ ืขืœ ื™ื™ืฉื•ืžื™ื ืžืชืคืชื—ื™ื ื‘ืžื”ื™ืจื•ืช. ื‘ืžืฉืš ืฉื ื™ื ืจื‘ื•ืช, ืžืฉืชืžืฉื™ื ื ื™ื’ืฉื• ืœื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ื“ืจืš ื”ืื™ื ื˜ืจื ื˜ ื‘ืืžืฆืขื•ืช ื“ืคื“ืคื ื™ ืื™ื ื˜ืจื ื˜ ืคื•ืคื•ืœืจื™ื™ื. ื”ื™ื” ืฆื•ืจืš ืœืชืžื•ืš ื‘-2-5 ื“ืคื“ืคื ื™ ืื™ื ื˜ืจื ื˜ ื‘ื›ืœ ื–ืžืŸ ื ืชื•ืŸ, ื•ืžืขืจืš ื”ืกื˜ื ื“ืจื˜ื™ื ืœืคื™ืชื•ื— ื•ื‘ื“ื™ืงืช ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ื”ื™ื” ืžื•ื’ื‘ืœ ืœืžื“ื™. ืœื“ื•ื’ืžื”, ื›ืžืขื˜ ื›ืœ ืžืกื“ื™ ื”ื ืชื•ื ื™ื ื ื‘ื ื• ื‘ืืžืฆืขื•ืช SQL. ืœืจื•ืข ื”ืžื–ืœ, ืœืื—ืจ ื–ืžืŸ ืงืฆืจ, ื”ืืงืจื™ื ืœืžื“ื• ืœื”ืฉืชืžืฉ ื‘ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ื›ื“ื™ ืœื’ื ื•ื‘, ืœืžื—ื•ืง ืื• ืœืฉื ื•ืช ื ืชื•ื ื™ื. ื”ื ื”ืฉื™ื’ื• ื’ื™ืฉื” ื‘ืœืชื™ ื—ื•ืงื™ืช ืœื™ื›ื•ืœื•ืช ื”ืืคืœื™ืงืฆื™ื” ื•ื ื™ืฆืœื• ืื•ืชืŸ ืœืจืขื” ืชื•ืš ืฉื™ืžื•ืฉ ื‘ืžื’ื•ื•ืŸ ื˜ื›ื ื™ืงื•ืช, ื›ื•ืœืœ ื”ื˜ืขื™ื” ืฉืœ ืžืฉืชืžืฉื™ ืืคืœื™ืงืฆื™ื”, ื”ื–ืจืงื” ื•ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง. ืขื“ ืžื”ืจื”, ื›ืœื™ ืื‘ื˜ื—ื” ืžืกื—ืจื™ื™ื ืฉืœ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ื”ื ืงืจืื™ื Web Application Firewalls (WAFs) ื”ื’ื™ืขื• ืœืฉื•ืง, ื•ื”ืงื”ื™ืœื” ื”ื’ื™ื‘ื” ื‘ื™ืฆื™ืจืช ืคืจื•ื™ืงื˜ ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ืคืชื•ื—, Open Web Application Security Project (OWASP), ื›ื“ื™ ืœื”ื’ื“ื™ืจ ื•ืœืชื—ื–ืง ืชืงื ื™ ืคื™ืชื•ื— ื•ืžืชื•ื“ื•ืœื•ื’ื™ื•ืช. ื™ื™ืฉื•ืžื™ื ืžืื•ื‘ื˜ื—ื™ื.

ื”ื’ื ื” ื‘ืกื™ืกื™ืช ืขืœ ื™ื™ืฉื•ืžื™ื

ืจืฉื™ืžืช 10 ื”ืžื•ื‘ื™ืœื™ื ืฉืœ OWASP ืžื”ื•ื•ื” ื ืงื•ื“ืช ืžื•ืฆื ืœืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ื•ืžื›ื™ืœื” ืจืฉื™ืžื” ืฉืœ ื”ืื™ื•ืžื™ื ื•ื”ืชืฆื•ืจื•ืช ื”ืฉื’ื•ื™ื•ืช ื”ืžืกื•ื›ื ื•ืช ื‘ื™ื•ืชืจ ืฉืขืœื•ืœื•ืช ืœื”ื•ื‘ื™ืœ ืœืคืจืฆื•ืช ื™ื™ืฉื•ืžื™ื, ื›ืžื• ื’ื ื˜ืงื˜ื™ืงื•ืช ืœื–ื™ื”ื•ื™ ื•ื”ื‘ืกื” ืฉืœ ื”ืชืงืคื•ืช. OWASP Top 10 ื”ื•ื ืืžืช ืžื™ื“ื” ืžื•ื›ืจืช ื‘ืชืขืฉื™ื™ืช ืื‘ื˜ื—ืช ื”ืกื™ื™ื‘ืจ ืฉืœ ื™ื™ืฉื•ืžื™ื ื‘ืจื—ื‘ื™ ื”ืขื•ืœื ื•ืžื’ื“ื™ืจ ืืช ืจืฉื™ืžืช ื”ืœื™ื‘ื” ืฉืœ ื™ื›ื•ืœื•ืช ืฉืžืขืจื›ืช ืื‘ื˜ื—ืช ืืคืœื™ืงืฆื™ื•ืช ืื™ื ื˜ืจื ื˜ (WAF) ืฆืจื™ื›ื” ืœื”ื™ื•ืช.

ื‘ื ื•ืกืฃ, ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช WAF ื—ื™ื™ื‘ืช ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ื”ืชืงืคื•ืช ื ืคื•ืฆื•ืช ืื—ืจื•ืช ืขืœ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜, ืœืจื‘ื•ืช ื–ื™ื•ืฃ ื‘ืงืฉื•ืช ื—ื•ืฆื•ืช ืืชืจื™ื (CSRF), ื—ื˜ื™ืคืช ืงืœื™ืงื™ื, ื’ื™ืจื•ื“ ืื™ื ื˜ืจื ื˜ ื•ื”ื›ืœืœืช ืงื‘ืฆื™ื (RFI/LFI).

ืื™ื•ืžื™ื ื•ืืชื’ืจื™ื ืœื”ื‘ื˜ื—ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื™ื™ืฉื•ืžื™ื ืžื•ื“ืจื ื™ื™ื

ื›ื™ื•ื, ืœื ื›ืœ ื”ืืคืœื™ืงืฆื™ื•ืช ืžื™ื•ืฉืžื•ืช ื‘ื’ืจืกืช ืจืฉืช. ื™ืฉ ืืคืœื™ืงืฆื™ื•ืช ืขื ืŸ, ืืคืœื™ืงืฆื™ื•ืช ืœื ื™ื™ื“, ืžืžืฉืงื™ API, ื•ื‘ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช ื”ืขื“ื›ื ื™ื•ืช ื‘ื™ื•ืชืจ, ืืคื™ืœื• ืคื•ื ืงืฆื™ื•ืช ืชื•ื›ื ื” ืžื•ืชืืžื•ืช ืื™ืฉื™ืช. ื›ืœ ืกื•ื’ื™ ื”ื™ื™ืฉื•ืžื™ื ื”ืœืœื• ืฆืจื™ื›ื™ื ืœื”ื™ื•ืช ืžืกื•ื ื›ืจื ื™ื ื•ืœืฉืœื•ื˜ ื‘ื–ืžืŸ ืฉื”ื ื™ื•ืฆืจื™ื, ืžืฉื ื™ื ื•ืžืขื‘ื“ื™ื ืืช ื”ื ืชื•ื ื™ื ืฉืœื ื•. ืขื ื”ื•ืคืขืชืŸ ืฉืœ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื•ืคืจื“ื™ื’ืžื•ืช ื—ื“ืฉื•ืช, ืžืชืขื•ืจืจื•ืช ืžื•ืจื›ื‘ื•ืช ื•ืืชื’ืจื™ื ื—ื“ืฉื™ื ื‘ื›ืœ ืฉืœื‘ื™ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ืฉืœ ื”ืืคืœื™ืงืฆื™ื”. ื–ื” ื›ื•ืœืœ ืฉื™ืœื•ื‘ ืคื™ืชื•ื— ื•ืชืคืขื•ืœ (DevOps), ืงื•ื ื˜ื™ื™ื ืจื™ื, ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ื“ื‘ืจื™ื (IoT), ื›ืœื™ ืงื•ื“ ืคืชื•ื—, APIs ื•ืขื•ื“.

ื”ืคืจื™ืกื” ื”ืžื‘ื•ื–ืจืช ืฉืœ ื™ื™ืฉื•ืžื™ื ื•ืžื’ื•ื•ืŸ ื”ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื™ื•ืฆืจืช ืืชื’ืจื™ื ืžื•ืจื›ื‘ื™ื ื•ืžื•ืจื›ื‘ื™ื ืœื ืจืง ืขื‘ื•ืจ ืื ืฉื™ ืื‘ื˜ื—ืช ืžื™ื“ืข, ืืœื ื’ื ืขื‘ื•ืจ ืกืคืงื™ ืคืชืจื•ื ื•ืช ืื‘ื˜ื—ื” ืฉืื™ื ื ื™ื›ื•ืœื™ื ืขื•ื“ ืœื”ืกืชืžืš ืขืœ ื’ื™ืฉื” ืžืื•ื—ื“ืช. ืืžืฆืขื™ ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ื—ื™ื™ื‘ื™ื ืœืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ืืช ื”ืคืจื˜ื™ื ื”ืขืกืงื™ื™ื ืฉืœื”ื ื›ื“ื™ ืœืžื ื•ืข ืชื•ืฆืื•ืช ืฉื•ื•ื ื•ื”ืคืจืขื” ื‘ืื™ื›ื•ืช ื”ืฉื™ืจื•ืชื™ื ืœืžืฉืชืžืฉื™ื.

ื”ืžื˜ืจื” ื”ืกื•ืคื™ืช ืฉืœ ื”ืืงืจื™ื ื”ื™ื ื‘ื“ืจืš ื›ืœืœ ืื• ืœื’ื ื•ื‘ ื ืชื•ื ื™ื ืื• ืœืฉื‘ืฉ ืืช ื–ืžื™ื ื•ืช ื”ืฉื™ืจื•ืชื™ื. ื”ืชื•ืงืคื™ื ื ื”ื ื™ื ื’ื ืžื”ืื‘ื•ืœื•ืฆื™ื” ื”ื˜ื›ื ื•ืœื•ื’ื™ืช. ืจืืฉื™ืช, ืคื™ืชื•ื— ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื—ื“ืฉื•ืช ื™ื•ืฆืจ ื™ื•ืชืจ ืคืขืจื™ื ื•ืคื’ื™ืขื•ืช ืคื•ื˜ื ืฆื™ืืœื™ื™ื. ืฉื ื™ืช, ื™ืฉ ืœื”ื ื™ื•ืชืจ ื›ืœื™ื ื•ื™ื“ืข ื‘ืืจืกื ืœ ืฉืœื”ื ื›ื“ื™ ืœืขืงื•ืฃ ืืžืฆืขื™ ืื‘ื˜ื—ื” ืžืกื•ืจืชื™ื™ื. ื–ื” ืžื’ื“ื™ืœ ืžืื•ื“ ืืช ืžื” ืฉืžื›ื•ื ื” "ืžืฉื˜ื— ื”ื”ืชืงืคื”" ื•ืืช ื”ื—ืฉื™ืคื” ืฉืœ ืืจื’ื•ื ื™ื ืœืกื™ื›ื•ื ื™ื ื—ื“ืฉื™ื. ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ื—ื™ื™ื‘ืช ืœื”ืฉืชื ื•ืช ื›ืœ ื”ื–ืžืŸ ื‘ืชื’ื•ื‘ื” ืœืฉื™ื ื•ื™ื™ื ื‘ื˜ื›ื ื•ืœื•ื’ื™ื” ื•ื‘ืืคืœื™ืงืฆื™ื•ืช.

ืœืคื™ื›ืš, ื™ืฉ ืœื”ื’ืŸ ืขืœ ื™ื™ืฉื•ืžื™ื ืžืžื’ื•ื•ืŸ ื”ื•ืœืš ื•ื’ื“ืœ ืฉืœ ืฉื™ื˜ื•ืช ื•ืžืงื•ืจื•ืช ืชืงื™ืคื”, ื•ื™ืฉ ืœื”ืชืžื•ื“ื“ ืขื ื”ืชืงืคื•ืช ืื•ื˜ื•ืžื˜ื™ื•ืช ื‘ื–ืžืŸ ืืžืช ืขืœ ืกืžืš ื”ื—ืœื˜ื•ืช ืžื•ืฉื›ืœื•ืช. ื”ืชื•ืฆืื” ื”ื™ื ืขืœื•ื™ื•ืช ืขืกืงื” ืžื•ื’ื‘ืจื•ืช ื•ืขื‘ื•ื“ื” ื™ื“ื ื™ืช, ื™ื—ื“ ืขื ืชื ื•ื—ืช ืื‘ื˜ื—ื” ืžื•ื—ืœืฉืช.

ืžืฉื™ืžื” ืžืก' 1: ื ื™ื”ื•ืœ ื‘ื•ื˜ื™ื

ื™ื•ืชืจ ืž-60% ืžืชืขื‘ื•ืจืช ื”ืื™ื ื˜ืจื ื˜ ื ื•ืฆืจืช ืขืœ ื™ื“ื™ ื‘ื•ื˜ื™ื, ืžื—ืฆื™ืชื” ื”ื™ื ืชืขื‘ื•ืจื” "ืจืขื”" (ืขืœ ืคื™ ื“ื•ื— ืื‘ื˜ื—ื” ืฉืœ Radware). ืืจื’ื•ื ื™ื ืžืฉืงื™ืขื™ื ื‘ื”ื’ื“ืœืช ืงื™ื‘ื•ืœืช ื”ืจืฉืช, ื•ื‘ืขืฆื ืžืฉืจืชื™ื ืขื•ืžืก ืคื™ืงื˜ื™ื‘ื™. ื”ื‘ื—ื ื” ืžื“ื•ื™ืงืช ื‘ื™ืŸ ืชื ื•ืขืช ืžืฉืชืžืฉื™ื ืืžื™ืชื™ืช ื•ืชืขื‘ื•ืจืช ื‘ื•ื˜ื™ื, ื›ืžื• ื’ื ื‘ื•ื˜ื™ื "ื˜ื•ื‘ื™ื" (ืœื“ื•ื’ืžื”, ืžื ื•ืขื™ ื—ื™ืคื•ืฉ ื•ืฉื™ืจื•ืชื™ ื”ืฉื•ื•ืืช ืžื—ื™ืจื™ื) ื•ื‘ื•ื˜ื™ื "ืจืขื™ื" ื™ื›ื•ืœื” ืœื”ื‘ื™ื ืœื—ื™ืกื›ื•ืŸ ืžืฉืžืขื•ืชื™ ื‘ืขืœื•ื™ื•ืช ื•ืœืฉื™ืคื•ืจ ืื™ื›ื•ืช ื”ืฉื™ืจื•ืช ืœืžืฉืชืžืฉื™ื.

ื‘ื•ื˜ื™ื ืœื ื™ื”ืคื›ื• ืืช ื”ืžืฉื™ืžื” ื”ื–ื• ืœืงืœื”, ื•ื”ื ื™ื›ื•ืœื™ื ืœื—ืงื•ืช ืืช ื”ื”ืชื ื”ื’ื•ืช ืฉืœ ืžืฉืชืžืฉื™ื ืืžื™ืชื™ื™ื, ืœืขืงื•ืฃ CAPTCHA ื•ืžื›ืฉื•ืœื™ื ืื—ืจื™ื. ื™ืชืจื” ืžื›ืš, ื‘ืžืงืจื” ืฉืœ ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช ื›ืชื•ื‘ื•ืช IP ื“ื™ื ืžื™ื•ืช, ื”ื’ื ื” ื”ืžื‘ื•ืกืกืช ืขืœ ืกื™ื ื•ืŸ ื›ืชื•ื‘ื•ืช IP ื”ื•ืคื›ืช ืœืœื ื™ืขื™ืœื”. ืœืขืชื™ื ืงืจื•ื‘ื•ืช, ื›ืœื™ื ืœืคื™ืชื•ื— ืงื•ื“ ืคืชื•ื— (ืœื“ื•ื’ืžื”, Phantom JS) ืฉื™ื›ื•ืœื™ื ืœื”ืชืžื•ื“ื“ ืขื JavaScript ื‘ืฆื“ ื”ืœืงื•ื— ืžืฉืžืฉื™ื ืœื”ืคืขืœืช ื”ืชืงืคื•ืช ื‘ื›ื•ื— ื’ืก, ื”ืชืงืคื•ืช ืžื™ืœื•ื™ ืื™ืฉื•ืจื™ื, ื”ืชืงืคื•ืช DDoS ื•ื”ืชืงืคื•ืช ื‘ื•ื˜ื™ื ืื•ื˜ื•ืžื˜ื™ื•ืช.

ื›ื“ื™ ืœื ื”ืœ ื‘ื™ืขื™ืœื•ืช ืืช ืชืขื‘ื•ืจืช ื”ื‘ื•ื˜ื™ื, ื ื“ืจืฉ ื–ื™ื”ื•ื™ ื™ื™ื—ื•ื“ื™ ืฉืœ ื”ืžืงื•ืจ ืฉืœื” (ื›ืžื• ื˜ื‘ื™ืขืช ืืฆื‘ืข). ืžืื—ืจ ืฉืชืงื™ืคืช ื‘ื•ื˜ ืžื™ื™ืฆืจืช ืจืฉื•ืžื•ืช ืžืจื•ื‘ื•ืช, ื˜ื‘ื™ืขืช ื”ืืฆื‘ืข ืฉืœื” ืžืืคืฉืจืช ืœื–ื”ื•ืช ืคืขื™ืœื•ืช ื—ืฉื•ื“ื” ื•ืœื”ืงืฆื•ืช ืฆื™ื•ื ื™ื, ืขืœ ื‘ืกื™ืกื ืžืขืจื›ืช ื”ื”ื’ื ื” ืขืœ ื”ืืคืœื™ืงืฆื™ื” ืžืงื‘ืœืช ื”ื—ืœื˜ื” ืžื•ืฉื›ืœืช - ื—ืกื•ื/ืืคืฉืจ - ืขื ืฉื™ืขื•ืจ ืžื™ื ื™ืžืœื™ ืฉืœ ืชื•ืฆืื•ืช ื—ื™ื•ื‘ื™ื•ืช ืฉื’ื•ื™ื•ืช.

ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ืžืขืจื›ื•ืช ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ืžื•ื“ืจื ื™ื•ืช (WAF) ืฆืจื™ื›ื” ืœื”ื™ื•ืช ื”ืจื‘ื” ื™ื•ืชืจ ืจื—ื‘ื” ืžืจืฉื™ืžืช ื”ืคื’ื™ืขื•ื™ื•ืช ืž-OWASP Top 10

ืืชื’ืจ ืžืก' 2: ื”ื’ื ื” ืขืœ ื”-API

ื™ื™ืฉื•ืžื™ื ืจื‘ื™ื ืื•ืกืคื™ื ืžื™ื“ืข ื•ื ืชื•ื ื™ื ืžืฉื™ืจื•ืชื™ื ืื™ืชื ื”ื ืžืงื™ื™ืžื™ื ืื™ื ื˜ืจืืงืฆื™ื” ื‘ืืžืฆืขื•ืช ืžืžืฉืงื™ API. ื‘ืขืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื ืจื’ื™ืฉื™ื ื“ืจืš ืžืžืฉืงื™ API, ื™ื•ืชืจ ืž-50% ืžื”ืืจื’ื•ื ื™ื ืœื ืžืืžืชื™ื ื•ืœื ืžืื‘ื˜ื—ื™ื ืžืžืฉืงื™ API ื›ื“ื™ ืœื–ื”ื•ืช ืžืชืงืคื•ืช ืกื™ื™ื‘ืจ.

ื“ื•ื’ืžืื•ืช ืœืฉื™ืžื•ืฉ ื‘-API:

  • ืื™ื ื˜ื’ืจืฆื™ื” ืฉืœ ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ื“ื‘ืจื™ื (IoT).
  • ืชืงืฉื•ืจืช ื‘ื™ืŸ ืžื›ื•ื ื” ืœืžื›ื•ื ื”
  • ืกื‘ื™ื‘ื•ืช ืœืœื ืฉืจืช
  • ืืคืœื™ืงืฆื™ื•ืช ื ื™ื™ื“ื•ืช
  • ื™ื™ืฉื•ืžื™ื ืžื•ื ืขื™ ืื™ืจื•ืขื™ื

ืคื’ื™ืขื•ื™ื•ืช API ื“ื•ืžื•ืช ืœืคื’ื™ืขื•ื™ื•ืช ืฉืœ ื™ื™ืฉื•ืžื™ื ื•ื›ื•ืœืœื•ืช ื”ื–ืจืงื•ืช, ื”ืชืงืคื•ืช ืคืจื•ื˜ื•ืงื•ืœ, ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืคืจืžื˜ืจื™ื, ื”ืคื ื™ื•ืช ืžื—ื“ืฉ ื•ื”ืชืงืคื•ืช ื‘ื•ื˜ื™ื. ืฉืขืจื™ื ื™ื™ืขื•ื“ื™ื™ื ืฉืœ API ืขื•ื–ืจื™ื ืœื”ื‘ื˜ื™ื— ืชืื™ืžื•ืช ื‘ื™ืŸ ืฉื™ืจื•ืชื™ ื™ื™ืฉื•ืžื™ื ื”ืžืงื™ื™ืžื™ื ืื™ื ื˜ืจืืงืฆื™ื” ื‘ืืžืฆืขื•ืช ืžืžืฉืงื™ API. ืขื ื–ืืช, ื”ื ืื™ื ื ืžืกืคืงื™ื ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ืžืงืฆื” ืœืงืฆื” ื›ืžื• WAF ื™ื›ื•ืœ ืขื ื›ืœื™ ืื‘ื˜ื—ื” ื—ื™ื•ื ื™ื™ื ื›ื’ื•ืŸ ื ื™ืชื•ื— ื›ื•ืชืจื•ืช HTTP, ืจืฉื™ืžืช ื‘ืงืจืช ื’ื™ืฉื” ืฉืœ ืฉื›ื‘ื” 7 (ACL), ื ื™ืชื•ื— ื•ื‘ื“ื™ืงื” ืฉืœ ืขื•ืžืกื™ JSON/XML ื•ื”ื’ื ื” ืžืคื ื™ ื›ืœ ื”ืคื’ื™ืขื•ื™ื•ืช ืฉืœ ืจืฉื™ืžืช 10 ื”ืžื•ื‘ื™ืœื™ื ืฉืœ OWASP. ื–ื” ืžื•ืฉื’ ืขืœ ื™ื“ื™ ื‘ื“ื™ืงืช ืขืจื›ื™ ืžืคืชื— API ื‘ืืžืฆืขื•ืช ืžื•ื“ืœื™ื ื—ื™ื•ื‘ื™ื™ื ื•ืฉืœื™ืœื™ื™ื.

ืืชื’ืจ ืžืก' 3: ืžื ื™ืขืช ืฉื™ืจื•ืช

ื•ืงื˜ื•ืจ ื”ืชืงืคื” ื™ืฉืŸ, ืžื ื™ืขืช ืฉื™ืจื•ืช (DoS), ืžืžืฉื™ืš ืœื”ื•ื›ื™ื— ืืช ื™ืขื™ืœื•ืชื• ื‘ืชืงื™ืคืช ื™ื™ืฉื•ืžื™ื. ืœืชื•ืงืคื™ื ื™ืฉ ืžื’ื•ื•ืŸ ืฉืœ ื˜ื›ื ื™ืงื•ืช ืžื•ืฆืœื—ื•ืช ืœืฉื‘ืฉ ืฉื™ืจื•ืชื™ ื™ื™ืฉื•ืžื™ื, ื›ื•ืœืœ ื”ืฆืคื•ืช HTTP ืื• HTTPS, ื”ืชืงืคื•ืช ื ืžื•ื›ื•ืช ื•ืื™ื˜ื™ื•ืช (ืœืžืฉืœ SlowLoris, LOIC, Torshammer), ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช ื›ืชื•ื‘ื•ืช IP ื“ื™ื ืžื™ื•ืช, ื”ืฆืคืช ื—ื™ืฅ, ื”ืชืงืคื•ืช ืฉืœ ื›ื•ื— ื’ืก ื•ืจื‘ื™ื ืื—ืจื™ื. . ืขื ื”ืชืคืชื—ื•ืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ื“ื‘ืจื™ื ื•ื”ื”ื•ืคืขื” ืฉืœืื—ืจ ืžื›ืŸ ืฉืœ ืจืฉืชื•ืช IoT, ื”ืชืงืคื•ืช ืขืœ ื™ื™ืฉื•ืžื™ื ื”ืคื›ื• ืœืžื•ืงื“ ื”ืขื™ืงืจื™ ืฉืœ ื”ืชืงืคื•ืช DDoS. ืจื•ื‘ ื”-WAFs ื”ืžืžืœื›ืชื™ื™ื ื™ื›ื•ืœื™ื ืœื”ืชืžื•ื“ื“ ืจืง ืขื ื›ืžื•ืช ืžื•ื’ื‘ืœืช ืฉืœ ืขื•ืžืก. ืขื ื–ืืช, ื”ื ื™ื›ื•ืœื™ื ืœื‘ื“ื•ืง ื–ืจื™ืžื•ืช ืชืขื‘ื•ืจืช HTTP/S ื•ืœื”ืกื™ืจ ืชืขื‘ื•ืจืช ืชืงื™ืคื” ื•ื—ื™ื‘ื•ืจื™ื ื–ื“ื•ื ื™ื™ื. ื‘ืจื’ืข ืฉื–ื•ื”ืชื” ืชืงื™ืคื”, ืื™ืŸ ื˜ืขื ืœื”ืขื‘ื™ืจ ืžื—ื“ืฉ ืืช ื”ืชื ื•ืขื” ื”ื–ื•. ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื›ื•ืœืช ืฉืœ ื”-WAF ืœื”ื“ื•ืฃ ื”ืชืงืคื•ืช ืžื•ื’ื‘ืœืช, ื™ืฉ ืฆื•ืจืš ื‘ืคืชืจื•ืŸ ื ื•ืกืฃ ื‘ื”ื™ืงืฃ ื”ืจืฉืช ื›ื“ื™ ืœื—ืกื•ื ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ื—ื‘ื™ืœื•ืช ื”"ืจืขื•ืช" ื”ื‘ืื•ืช. ืขื‘ื•ืจ ืชืจื—ื™ืฉ ืื‘ื˜ื—ื” ื–ื”, ืฉื ื™ ื”ืคืชืจื•ื ื•ืช ื—ื™ื™ื‘ื™ื ืœื”ื™ื•ืช ืžืกื•ื’ืœื™ื ืœืชืงืฉืจ ื–ื” ืขื ื–ื” ื›ื“ื™ ืœื”ื—ืœื™ืฃ ืžื™ื“ืข ืขืœ ื”ืชืงืคื•ืช.

ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ืžืขืจื›ื•ืช ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื ืžื•ื“ืจื ื™ื•ืช (WAF) ืฆืจื™ื›ื” ืœื”ื™ื•ืช ื”ืจื‘ื” ื™ื•ืชืจ ืจื—ื‘ื” ืžืจืฉื™ืžืช ื”ืคื’ื™ืขื•ื™ื•ืช ืž-OWASP Top 10
ืื™ื•ืจ 1. ืืจื’ื•ืŸ ืฉืœ ื”ื’ื ื” ืžืงื™ืคื” ืขืœ ืจืฉืช ื•ื™ื™ืฉื•ืžื™ื ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ ืคืชืจื•ื ื•ืช Radware

ืืชื’ืจ ืžืก' 4: ื”ื’ื ื” ืžืชืžืฉื›ืช

ื™ื™ืฉื•ืžื™ื ืžืฉืชื ื™ื ืœืขืชื™ื ืงืจื•ื‘ื•ืช. ืžืชื•ื“ื•ืœื•ื’ื™ื•ืช ืคื™ืชื•ื— ื•ื”ื˜ืžืขื” ื›ื’ื•ืŸ ืขื“ื›ื•ื ื™ื ืžืชื’ืœื’ืœื™ื ืื•ืžืจื•ืช ืฉืฉื™ื ื•ื™ื™ื ืžืชืจื—ืฉื™ื ืœืœื ื”ืชืขืจื‘ื•ืช ืื• ืฉืœื™ื˜ื” ืื ื•ืฉื™ืช. ื‘ืกื‘ื™ื‘ื•ืช ื“ื™ื ืžื™ื•ืช ื›ืืœื”, ืงืฉื” ืœืฉืžื•ืจ ืขืœ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ืžืชืคืงื“ืช ื›ืจืื•ื™ ืœืœื ืžืกืคืจ ื’ื‘ื•ื” ืฉืœ ืชื•ืฆืื•ืช ื›ื•ื–ื‘ื•ืช. ื™ื™ืฉื•ืžื™ื ื ื™ื™ื“ื™ื ืžืชืขื“ื›ื ื™ื ื‘ืชื“ื™ืจื•ืช ื’ื‘ื•ื”ื” ื”ืจื‘ื” ื™ื•ืชืจ ืžืืฉืจ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜. ื™ื™ืฉื•ืžื™ ืฆื“ ืฉืœื™ืฉื™ ืขืฉื•ื™ื™ื ืœื”ืฉืชื ื•ืช ืœืœื ื™ื“ื™ืขืชืš. ืืจื’ื•ื ื™ื ืžืกื•ื™ืžื™ื ืžื—ืคืฉื™ื ืฉืœื™ื˜ื” ื•ื ืจืื•ืช ืจื‘ื” ื™ื•ืชืจ ื›ื“ื™ ืœื”ื™ืฉืืจ ืขื ื”ืกื™ื›ื•ื ื™ื ื”ืคื•ื˜ื ืฆื™ืืœื™ื™ื. ืขื ื–ืืช, ื–ื” ืœื ืชืžื™ื“ ื‘ืจ ื”ืฉื’ื”, ื•ื”ื’ื ื” ืขืœ ื™ื™ืฉื•ืžื™ื ืืžื™ื ื” ื—ื™ื™ื‘ืช ืœื”ืฉืชืžืฉ ื‘ื›ื•ื—ื” ืฉืœ ืœืžื™ื“ืช ืžื›ื•ื ื” ื›ื“ื™ ืœืชืืจ ื•ืœื”ืžื—ื™ืฉ ืžืฉืื‘ื™ื ื–ืžื™ื ื™ื, ืœื ืชื— ืื™ื•ืžื™ื ืคื•ื˜ื ืฆื™ืืœื™ื™ื ื•ืœื™ืฆื•ืจ ื•ืœื™ื™ืขืœ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ื‘ืžืงืจื” ืฉืœ ืฉื™ื ื•ื™ื™ื ื‘ืืคืœื™ืงืฆื™ื”.

ืžืžืฆืื™ื

ืžื›ื™ื•ื•ืŸ ืฉืืคืœื™ืงืฆื™ื•ืช ืžืžืœืื•ืช ืชืคืงื™ื“ ื—ืฉื•ื‘ ื™ื•ืชืจ ื•ื™ื•ืชืจ ื‘ื—ื™ื™ ื”ื™ื•ืžื™ื•ื, ื”ืŸ ื”ื•ืคื›ื•ืช ืœืžื˜ืจื” ืžืจื›ื–ื™ืช ืขื‘ื•ืจ ื”ืืงืจื™ื. ื”ืชื’ืžื•ืœ ื”ืคื•ื˜ื ืฆื™ืืœื™ ืœืคื•ืฉืขื™ื ื•ื”ื”ืคืกื“ื™ื ื”ืคื•ื˜ื ืฆื™ืืœื™ื™ื ืœืขืกืงื™ื ื”ื ืขืฆื•ืžื™ื. ืœื ื ื™ืชืŸ ืœื”ืคืจื™ื– ื‘ืžื•ืจื›ื‘ื•ืช ืฉืœ ืžืฉื™ืžืช ืื‘ื˜ื—ืช ื”ื™ื™ืฉื•ืžื™ื ื‘ื”ืชื—ืฉื‘ ื‘ืžืกืคืจ ื•ื‘ื•ื•ืจื™ืืฆื™ื•ืช ืฉืœ ื™ื™ืฉื•ืžื™ื ื•ืื™ื•ืžื™ื.

ืœืžืจื‘ื” ื”ืžื–ืœ, ืื ื• ื ืžืฆืื™ื ื‘ื ืงื•ื“ืช ื–ืžืŸ ืฉื‘ื” ื‘ื™ื ื” ืžืœืื›ื•ืชื™ืช ื™ื›ื•ืœื” ืœื‘ื•ื ืœืขื–ืจืชื ื•. ืืœื’ื•ืจื™ืชืžื™ื ืžื‘ื•ืกืกื™ ืœืžื™ื“ืช ืžื›ื•ื ื” ืžืกืคืงื™ื ื”ื’ื ื” ืื“ืคื˜ื™ื‘ื™ืช ื‘ื–ืžืŸ ืืžืช ืžืคื ื™ ืื™ื•ืžื™ ื”ืกื™ื™ื‘ืจ ื”ืžืชืงื“ืžื™ื ื‘ื™ื•ืชืจ ื”ืžื›ื•ื•ื ื™ื ืœื™ื™ืฉื•ืžื™ื. ื”ื ื’ื ืžืขื“ื›ื ื™ื ืื•ื˜ื•ืžื˜ื™ืช ืืช ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜, ื ื™ื™ื“ื™ื ื•ืขื ืŸ - ื•ืžืžืฉืงื™ API - ืœืœื ืชื•ืฆืื•ืช ื›ื•ื–ื‘ื•ืช.

ืงืฉื” ืœื—ื–ื•ืช ื‘ื•ื•ื“ืื•ืช ืžื” ื™ื”ื™ื” ื”ื“ื•ืจ ื”ื‘ื ืฉืœ ืื™ื•ืžื™ ืกื™ื™ื‘ืจ ื™ื™ืฉื•ืžื™ื (ืื•ืœื™ ื’ื ืžื‘ื•ืกืกื™ื ืขืœ ืœืžื™ื“ืช ืžื›ื•ื ื”). ืื‘ืœ ืืจื’ื•ื ื™ื ื‘ื”ื—ืœื˜ ื™ื›ื•ืœื™ื ืœื ืงื•ื˜ ื‘ืฆืขื“ื™ื ื›ื“ื™ ืœื”ื’ืŸ ืขืœ ื ืชื•ื ื™ ืœืงื•ื—ื•ืช, ืœื”ื’ืŸ ืขืœ ืงื ื™ื™ืŸ ืจื•ื—ื ื™ ื•ืœื”ื‘ื˜ื™ื— ื–ืžื™ื ื•ืช ืฉื™ืจื•ืช ืขื ื™ืชืจื•ื ื•ืช ืขืกืงื™ื™ื ื’ื“ื•ืœื™ื.

ื’ื™ืฉื•ืช ื•ืฉื™ื˜ื•ืช ืืคืงื˜ื™ื‘ื™ื•ืช ืœื”ื‘ื˜ื—ืช ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ื, ื”ืกื•ื’ื™ื ื•ื”ื•ื•ืงื˜ื•ืจื™ื ื”ืขื™ืงืจื™ื™ื ืฉืœ ื”ืชืงืคื•ืช, ืื–ื•ืจื™ ืกื™ื›ื•ืŸ ื•ืคืขืจื™ื ื‘ื”ื’ื ืช ืกื™ื™ื‘ืจ ืฉืœ ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜, ื›ืžื• ื’ื ื ื™ืกื™ื•ืŸ ื’ืœื•ื‘ืœื™ ื•ืฉื™ื˜ื•ืช ืขื‘ื•ื“ื” ืžื•ืžืœืฆื•ืช ืžื•ืฆื’ื™ื ื‘ืžื—ืงืจ ื•ื‘ื“ื•ื— ืฉืœ Radware "ืื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ื‘ืขื•ืœื ืžื—ื•ื‘ืจ ื“ื™ื’ื™ื˜ืœื™ืช".

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”