{"id":52993,"date":"2019-11-21T00:00:00","date_gmt":"2019-11-20T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/funktsional-sovremennyh-sistem-zashhity-prilozhenij-waf-dolzhen-byt-gorazdo-shire-spiska-uyazvimostej-iz-owasp-top-10"},"modified":"2020-02-18T14:00:49","modified_gmt":"2020-02-18T11:00:49","slug":"funktsional-sovremennyh-sistem-zashhity-prilozhenij-waf-dolzhen-byt-gorazdo-shire-spiska-uyazvimostej-iz-owasp-top-10","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/funktsional-sovremennyh-sistem-zashhity-prilozhenij-waf-dolzhen-byt-gorazdo-shire-spiska-uyazvimostej-iz-owasp-top-10","title":{"rendered":"Funksionaliteti i sistemeve moderne t\u00eb mbrojtjes s\u00eb aplikacioneve (WAF) duhet t\u00eb jet\u00eb shum\u00eb m\u00eb i gjer\u00eb se sa lista e dob\u00ebsive nga OWASP Top 10","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<h4>Retrospektiva<\/h4>\n<p>\nSkalet, p\u00ebrb\u00ebrja dhe struktura e k\u00ebrc\u00ebnimeve kibernetike p\u00ebr aplikacione po evolucionojn\u00eb me shpejt\u00ebsi. Q\u00eb nga vitet e fundit, p\u00ebrdoruesit kan\u00eb aksesuar aplikacionet web p\u00ebrmes internetit p\u00ebrmes shfletuesve t\u00eb njohur. N\u00eb \u00e7do moment, ka qen\u00eb e nevojshme t\u00eb mbahen 2-5 shfletues web, dhe grupi i standardeve p\u00ebr zhvillimin dhe testimin e aplikacioneve web ka qen\u00eb mjaft i kufizuar. P\u00ebr shembull, pothuajse t\u00eb gjitha bazat e t\u00eb dh\u00ebnave jan\u00eb nd\u00ebrtuar duke p\u00ebrdorur SQL. Fatkeq\u00ebsisht, pas nj\u00eb periudhe t\u00eb shkurt\u00ebr, haker\u00ebt m\u00ebsuan t\u00eb p\u00ebrdorin aplikacionet web p\u00ebr t\u00eb vjedhur, fshir\u00eb ose ndryshuar t\u00eb dh\u00ebna. Ata fituan akses t\u00eb paligjsh\u00ebm dhe keqinterpretuar mund\u00ebsit\u00eb e aplikacioneve duke p\u00ebrdorur teknika t\u00eb ndryshme, duke p\u00ebrfshir\u00eb mashtrimin e p\u00ebrdoruesve t\u00eb aplikacioneve, injektimin dhe punimin e kodit nga distanca. S\u00eb shpejti n\u00eb treg u shfaq\u00ebn mjete komerciale mbrojt\u00ebse p\u00ebr aplikacionet web, t\u00eb njohura si Firewall p\u00ebr Aplikacione Web (WAF), dhe shoq\u00ebria reagoi duke krijuar nj\u00eb projekt t\u00eb hapur p\u00ebr sigurimin e aplikacioneve web, Open Web Application Security Project (OWASP), me q\u00ebllim t\u00eb p\u00ebrcaktimit dhe mbajtjes s\u00eb standardeve dhe metodologjive p\u00ebr zhvillimin e aplikacioneve t\u00eb sigurta.<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h4>Mbrojtja e baz\u00ebs s\u00eb aplikacioneve<\/h4>\n<p>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/radware.pro\/downloads\/OWASP_Top_10-2017-ru.pdf\">Lista OWASP Top 10<\/a><\/noindex> p\u00ebrb\u00ebn nj\u00eb pik\u00eb fillestare p\u00ebr sigurimin e aplikacioneve dhe p\u00ebrmban nj\u00eb list\u00eb t\u00eb k\u00ebrc\u00ebnimeve m\u00eb t\u00eb rrezikshme dhe konfigurimeve t\u00eb gabuara q\u00eb mund t\u00eb \u00e7ojn\u00eb n\u00eb dob\u00ebsi t\u00eb aplikacioneve, si edhe taktikat e zbulimit dhe zmbrapsjes s\u00eb sulmeve. OWASP Top 10 \u00ebsht\u00eb nj\u00eb referenc\u00eb e njohur n\u00eb industrin\u00eb e siguris\u00eb kibernetike p\u00ebr aplikacione n\u00eb t\u00eb gjith\u00eb bot\u00ebn dhe p\u00ebrcakton nj\u00eb list\u00eb bazike t\u00eb mund\u00ebsive q\u00eb duhet t\u00eb ket\u00eb nj\u00eb sistem mbrojt\u00ebs p\u00ebr aplikacione web (WAF). <\/p>\n<p>P\u00ebrve\u00e7 k\u00ebsaj, funksionaliteti i WAF duhet t\u00eb marr\u00eb parasysh sulme t\u00eb tjera t\u00eb zakonshme ndaj aplikacioneve web, duke p\u00ebrfshir\u00eb mashtrimet me k\u00ebrkesa nd\u00ebrfaqe (CSRF), klikim t\u00eb mashtruar (Clickjacking), skrapimin e uebit (web scraping) dhe p\u00ebrfshirjen e skedar\u00ebve (RFI\/LFI).<\/p>\n<h4>K\u00ebrc\u00ebnimet dhe sfidat e sigurimit t\u00eb aplikacioneve moderne<\/h4>\n<p>\nSot, akoma nuk t\u00eb gjitha aplikacionet jan\u00eb t\u00eb zhvilluara si aplikacione rrjeti. Ka aplikacione cloud, aplikacione mobile, API, dhe n\u00eb arkitektur\u00ebn m\u00eb t\u00eb re madje edhe funksione individuale software. T\u00eb gjitha k\u00ebto lloje aplikacionesh k\u00ebrkojn\u00eb sinkronizim dhe kontroll, pasi ato krijojn\u00eb, ndryshojn\u00eb dhe p\u00ebrpunojn\u00eb t\u00eb dh\u00ebnat tona. Me shfaqjen e teknologjive dhe paradigmatikave t\u00eb reja, shfaqen sfida dhe probleme t\u00eb reja n\u00eb t\u00eb gjitha fazat e ciklit t\u00eb jet\u00ebs s\u00eb aplikacioneve. Kjo p\u00ebrfshin integrimin e zhvillimit dhe operacioneve (DevOps), kontejner\u00ebve, Internetit t\u00eb Gj\u00ebrave (IoT), mjeteve me kod t\u00eb hapur, API dhe m\u00eb shum\u00eb. <\/p>\n<p>Shp\u00ebrndarja e aplikacioneve dhe diversiteti i teknologjive krijon sfida komplekse dhe t\u00eb nd\u00ebrlikuara, jo vet\u00ebm p\u00ebr specialist\u00ebt e siguris\u00eb informacionit, por edhe p\u00ebr prodhuesit e zgjidhjeve t\u00eb sigurise, t\u00eb cil\u00ebt nuk mund t\u00eb mb\u00ebshteten m\u00eb n\u00eb nj\u00eb qasje t\u00eb unifikuar. Mjetet e mbrojtjes p\u00ebr aplikacione duhet t\u00eb marrin parasysh specifikat e biznesit p\u00ebr t\u00eb parandaluar njoftimet e gabuara dhe p\u00ebr t\u00eb ruajtur cil\u00ebsin\u00eb e sh\u00ebrbimeve p\u00ebr p\u00ebrdoruesit. <\/p>\n<p>Q\u00ebllimi p\u00ebrfundimtar i haker\u00ebve zakonisht \u00ebsht\u00eb ose vjedhja e t\u00eb dh\u00ebnave, ose shkelja e disponueshm\u00ebris\u00eb s\u00eb sh\u00ebrbimeve. Keqb\u00ebr\u00ebsit gjithashtu fitojn\u00eb p\u00ebrfitime gjat\u00eb evolucionit teknologjik. S\u00eb pari, zhvillimi i teknologjive t\u00eb reja krijon m\u00eb shum\u00eb hap\u00ebsira potenciale dhe dob\u00ebsi. S\u00eb dyti, ata disponojn\u00eb m\u00eb shum\u00eb mjete dhe njohuri p\u00ebr t\u00eb anashkaluar mjetet tradicionale t\u00eb mbrojtjes. Kjo rrit ndjesh\u00ebm at\u00eb q\u00eb quhet 'sip\u00ebrfaqja e sulmit' dhe b\u00ebhet m\u00eb e rrezikshme p\u00ebr organizatat nga rreziqet e reja. Politikat e siguris\u00eb duhet t\u00eb ndryshojn\u00eb vazhdimisht n\u00eb p\u00ebrputhje me ndryshimet n\u00eb teknologji dhe aplikacione. <\/p>\n<p>Prandaj, aplikacionet duhet t\u00eb jen\u00eb t\u00eb mbrojtura nga nj\u00eb shum\u00ebllojshm\u00ebri n\u00eb rritje t\u00eb metodave dhe burimeve t\u00eb sulmeve, dhe zmbrapsja e sulmeve automatike duhet t\u00eb b\u00ebhet n\u00eb koh\u00eb reale, bazuar n\u00eb vendime t\u00eb informuara. Si pasoj\u00eb, rriten kostot operative dhe puna manuale p\u00ebrball\u00eb pozita m\u00eb t\u00eb dob\u00ebta n\u00eb siguri. <\/p>\n<h4>Detyra Nr. 1: Menaxhimi i bot\u00ebve<\/h4>\n<p>\nM\u00eb shum\u00eb se 60% e trafikut t\u00eb internetit gjenerohet nga bot\u00ebt, gjysma e t\u00eb cilit lidhet me trafikun 'e keq' (sipas t\u00eb dh\u00ebnave <noindex><a rel=\"nofollow\" href=\"https:\/\/radware.pro\/catalog\/2018-2019-radware-global-application-network-security-report\/\">t\u00eb raportit t\u00eb siguris\u00eb Radware<\/a><\/noindex>). Organizat\u00eb po investojn\u00eb n\u00eb rritjen e kapacitetit t\u00eb rrjetit, n\u00eb thelb, sh\u00ebrbyer nj\u00eb ngarkes\u00eb t\u00eb rreme. Dallimi i sakt\u00eb midis trafikut t\u00eb v\u00ebrtet\u00eb t\u00eb p\u00ebrdoruesve dhe trafikut t\u00eb bot\u00ebve, si dhe 'bot\u00ebve t\u00eb mira' (p.sh., robot\u00ebt e k\u00ebrkimit dhe sh\u00ebrbimet e krahasimit t\u00eb \u00e7mimeve) dhe 'bot\u00ebve t\u00eb k\u00ebqij' mund t\u00eb sjell\u00eb nj\u00eb kursim t\u00eb r\u00ebnd\u00ebsish\u00ebm t\u00eb kostove dhe p\u00ebrmir\u00ebsimin e cil\u00ebsis\u00eb s\u00eb sh\u00ebrbimeve p\u00ebr p\u00ebrdoruesit. <\/p>\n<p>Bot\u00ebt nuk do ta leht\u00ebsojn\u00eb k\u00ebt\u00eb detyr\u00eb, dhe ato mund t\u00eb imitojn\u00eb sjelljen e p\u00ebrdoruesve t\u00eb v\u00ebrtet\u00eb, duke kaluar CAPTCHA dhe pengesa t\u00eb tjera. P\u00ebr m\u00eb tep\u00ebr, n\u00eb rastet e sulmeve q\u00eb p\u00ebrdorin adresa IP dinamike, mbrojtja e bazuar n\u00eb filtrimin e adresave IP b\u00ebhet e pasuksesshme. Shpesh, mjete zhvillimi me burim t\u00eb hapur (p\u00ebr shembull, Phantom JS), t\u00eb cilat mund t\u00eb ekzekutojn\u00eb JavaScript-in e klientit, p\u00ebrdoren p\u00ebr t\u00eb kryer sulme brute-force, sulme credential stuffing, sulme DDoS dhe sulme automatike nga bot\u00ebt. <\/p>\n<p>P\u00ebr menaxhimin efektiv t\u00eb trafikut t\u00eb bot\u00ebve nevojitet identifikim unik i burimit t\u00eb tij (si\u00e7 \u00ebsht\u00eb nj\u00eb gjurm\u00eb gishtash). Duke qen\u00eb se n\u00eb rast t\u00eb sulmit nga bot\u00ebt krijohet nj\u00eb sasi e madhe regjistrimesh, gjurma e saj lejon identifikimin e aktiviteteve t\u00eb dyshimta dhe atribuimin e pik\u00ebve, mbi t\u00eb cilat sistemi i mbrojtjes s\u00eb aplikacioneve merr nj\u00eb vendim t\u00eb informuar \u2013 t\u00eb bllokoj\u00eb\/lejoj\u00eb \u2013 me nj\u00eb nivel t\u00eb ul\u00ebt t\u00eb rezultateve fals pozitive. <\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/radware.pro\/catalog\/2018-2019-radware-global-application-network-security-report\/\"><img decoding=\"async\" alt=\"Funksionaliteti i sistemeve moderne t\u00eb mbrojtjes s\u00eb aplikacioneve (WAF) duhet t\u00eb jet\u00eb shum\u00eb m\u00eb i gjer\u00eb se sa lista e dob\u00ebsive nga OWASP Top 10\" src=\"\/wp-content\/uploads\/2019\/11\/54764c31a86863be4e6f4ed16ff4b65c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<h4>Detyra \u21162: Mbrojtja e API-ve<\/h4>\n<p>\nShum\u00eb aplikacione mblidhen informacion dhe t\u00eb dh\u00ebna nga sh\u00ebrbimet me t\u00eb cilat ato bashk\u00ebveprojn\u00eb p\u00ebrmes API-ve. Kur transmetojn\u00eb t\u00eb dh\u00ebna t\u00eb ndjeshme p\u00ebrmes API-ve, mbi 50% e organizatave nuk kryejn\u00eb as verifikimin, as mbrojtjen e API-ve p\u00ebr t\u00eb identifikuar sulmet cibernetike. <\/p>\n<p>Shembuj t\u00eb p\u00ebrdorimeve t\u00eb API-ve:<\/p>\n<ul>\n<li>Integrimi i Internetit t\u00eb GThings (IoT)<\/li>\n<li>Bashk\u00ebveprimi midis makinerive<\/li>\n<li>Mjediset pa server <\/li>\n<li>Aplikacione mobile<\/li>\n<li>Aplikacione t\u00eb menaxhuara nga ngjarjet<\/li>\n<\/ul>\n<p>\nP\u00ebrgjegj\u00ebsit\u00eb e API-ve jan\u00eb t\u00eb ngjashme me ato t\u00eb aplikacioneve dhe p\u00ebrfshijn\u00eb injeksione, sulme protokollesh, manipulime parametrash, ridrejtime dhe sulme nga bot\u00ebt. Portat e d\u00ebmtuara t\u00eb API-ve sigurojn\u00eb p\u00ebrputhshm\u00ebrin\u00eb e sh\u00ebrbimeve t\u00eb aplikacioneve q\u00eb bashk\u00ebveprojn\u00eb p\u00ebrmes API-ve. Megjithat\u00eb, ato nuk ofrojn\u00eb sigurin\u00eb e plot\u00eb t\u00eb aplikacioneve, ashtu si\u00e7 mund ta b\u00ebj\u00eb WAF me mjetet e nevojshme t\u00eb siguris\u00eb, si analizimi i titujve HTTP, lista e menaxhimit t\u00eb qasjes Layer 7 (ACL), analizimi dhe verifikimi i ngarkesave JSON\/XML, si dhe mbrojtja nga t\u00eb gjitha vulnerabilitetet n\u00eb list\u00ebn OWASP Top 10. Kjo arrihet p\u00ebrmes inspektimit t\u00eb vlerave ky\u00e7e t\u00eb API-s\u00eb duke p\u00ebrdorur modele pozitive dhe negative. <\/p>\n<h4>Detyra \u21163: Sh\u00ebrbimi i r\u00ebn\u00eb<\/h4>\n<p>\nVektori i vjet\u00ebr i sulmeve \u2013 Sh\u00ebrbimi i r\u00ebn\u00eb (DoS) \u2013 vazhdon t\u00eb tregoj\u00eb efektivitetin e tij n\u00eb sulmet ndaj aplikacioneve. Agresor\u00ebt kan\u00eb nj\u00eb s\u00ebr\u00eb teknikash t\u00eb suksesshme p\u00ebr t\u00eb shqet\u00ebsuar funksionimin e sh\u00ebrbimeve t\u00eb aplikacioneve, duke p\u00ebrfshir\u00eb flooding HTTP ose HTTPS, sulme t\u00eb dob\u00ebta dhe t\u00eb ngadalt\u00eb (\"low-and-slow\", si\u00e7 \u00ebsht\u00eb SlowLoris, LOIC, Torshammer), sulme q\u00eb p\u00ebrdorin adresa IP dinamike, mbushje t\u00eb tamponit, sulme brute-force, dhe shum\u00eb t\u00eb tjera. Me zhvillimin e Internetit t\u00eb GThings dhe shfaqjen e botnet\u00ebve IoT, sulmet ndaj aplikacioneve jan\u00eb b\u00ebr\u00eb nj\u00eb drejtim kryesor i sulmeve DDoS. Shumica e WAF-ve me monitorimin e gjendjes s\u00eb lidhjes mund t\u00eb p\u00ebrballen vet\u00ebm me nj\u00eb volum t\u00eb kufizuar ngarkese. Megjithat\u00eb, ato mund t\u00eb inspektojn\u00eb rrjedhat e trafikut HTTP\/S dhe t\u00eb eliminojn\u00eb trafikun e sulmeve dhe lidhjet e d\u00ebmshme. Pas identifikimit t\u00eb nj\u00eb sulmi, nuk ka asnj\u00eb kuptim t\u00eb lejohet p\u00ebrs\u00ebri ky trafik. Duke qen\u00eb se kapaciteti i WAF p\u00ebr t\u00eb kund\u00ebrshtuar sulmet \u00ebsht\u00eb i kufizuar, nevojitet nj\u00eb zgjidhje shtes\u00eb n\u00eb perimeterin e rrjetit p\u00ebr t\u00eb bllokuar automatikisht paketat \"e k\u00ebqija\". P\u00ebr k\u00ebt\u00eb skenar mbrojtjeje, t\u00eb dy zgjidhjet duhet t\u00eb ken\u00eb aft\u00ebsin\u00eb t\u00eb bashk\u00ebpunojn\u00eb p\u00ebr shk\u00ebmbimin e informacionit mbi sulmet. <\/p>\n<p><img decoding=\"async\" alt=\"Funksionaliteti i sistemeve moderne t\u00eb mbrojtjes s\u00eb aplikacioneve (WAF) duhet t\u00eb jet\u00eb shum\u00eb m\u00eb i gjer\u00eb se sa lista e dob\u00ebsive nga OWASP Top 10\" src=\"\/wp-content\/uploads\/2019\/11\/0891b6ac8b043b813a831fc8bede5122.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Fig. 1. Organizimi i mbrojtjes komplekse t\u00eb rrjetit dhe aplikacioneve mbi shembujt e zgjidhjeve Radware<\/i><\/p>\n<h4>Detyra \u21164: Mbrojtja e vazhdueshme<\/h4>\n<p>\nAplikacionet shpesh p\u00ebrjetojn\u00eb ndryshime. Metodologjit\u00eb e zhvillimit dhe implementimit, t\u00eb tilla si vazhdim\u00ebsia e p\u00ebrdit\u00ebsimeve, n\u00ebnkuptojn\u00eb se modifikimet b\u00ebhen pa pjes\u00ebmarrje ose kontroll njer\u00ebzor. N\u00eb k\u00ebto kushte dinamike, \u00ebsht\u00eb e v\u00ebshtir\u00eb t\u00eb ruhet politika e siguris\u00eb q\u00eb funksionon n\u00eb m\u00ebnyr\u00eb adekuate pa nj\u00eb num\u00ebr t\u00eb lart\u00eb fals pozitive. Aplikacionet mobile p\u00ebrdit\u00ebsohen shum\u00eb m\u00eb shpesh se ato web. Aplikacionet e pal\u00ebve t\u00eb treta mund t\u00eb ndryshojn\u00eb pa dijenin\u00eb tuaj. Disa organizata p\u00ebrpiqen t\u00eb fitojn\u00eb m\u00eb shum\u00eb kontroll dhe vizualizim p\u00ebr t\u00eb mbetur n\u00eb dijeni t\u00eb rreziqeve potenciale. Megjithat\u00eb, kjo nuk \u00ebsht\u00eb gjithmon\u00eb e arritshme, dhe mbrojtja e besueshme e aplikacioneve duhet t\u00eb p\u00ebrdor\u00eb mund\u00ebsit\u00eb e m\u00ebsimit t\u00eb makineris\u00eb p\u00ebr t\u00eb marr\u00eb n\u00eb konsiderat\u00eb dhe paraqitur vizualisht burimet ekzistuese, p\u00ebr t\u00eb analizuar k\u00ebrc\u00ebnimet potenciale, dhe p\u00ebr t\u00eb krijuar dhe optimizuar politikat e siguris\u00eb n\u00eb rastin e modifikimit t\u00eb aplikacioneve.<\/p>\n<h4>P\u00ebrfundimet<\/h4>\n<p>\nNd\u00ebrsa aplikacionet luajn\u00eb nj\u00eb rol gjithnj\u00eb e m\u00eb t\u00eb r\u00ebnd\u00ebsish\u00ebm n\u00eb jet\u00ebn e p\u00ebrditshme, ato po b\u00ebhen nj\u00eb objektiv kryesor p\u00ebr hakerat. Shanset p\u00ebr sulmuesit dhe humbjet potenciale p\u00ebr bizneset jan\u00eb t\u00eb m\u00ebdha. Kompleksiteti i siguris\u00eb s\u00eb aplikacioneve nuk mund t\u00eb n\u00ebnvler\u00ebsohet, duke marr\u00eb parasysh numrin dhe variacionet e aplikacioneve dhe k\u00ebrc\u00ebnimeve. <\/p>\n<p>Fatmir\u00ebsisht, ndodhemi n\u00eb nj\u00eb moment ku inteligjenca artificiale mund t\u00eb na ndihmoj\u00eb. Algoritmet e bazuara n\u00eb m\u00ebsimin e makinerive ofrojn\u00eb mbrojtje adaptuese n\u00eb koh\u00eb reale nga k\u00ebrc\u00ebnimet m\u00eb t\u00eb avancuara kibernetike ndaj aplikacioneve. Ato gjithashtu p\u00ebrdit\u00ebsojn\u00eb automatikisht politikat e siguris\u00eb p\u00ebr t\u00eb mbrojtur aplikacionet web, mobile dhe cloud \u2014 si dhe API-t\u00eb \u2014 pa ndodhur alarme false.<\/p>\n<p>\u00cbsht\u00eb e v\u00ebshtir\u00eb t\u00eb parashikosh me sakt\u00ebsi se si do t\u00eb jen\u00eb gjeneratat e reja t\u00eb k\u00ebrc\u00ebnimeve kibernetike p\u00ebr aplikacionet (ndoshta gjithashtu t\u00eb bazuara n\u00eb m\u00ebsimin e makinerive). Por organizatat mund t\u00eb b\u00ebjn\u00eb hapa t\u00eb r\u00ebnd\u00ebsish\u00ebm p\u00ebr t\u00eb siguruar t\u00eb dh\u00ebnat e klient\u00ebve, pron\u00ebn intelektuale dhe garantimin e disponueshm\u00ebris\u00eb s\u00eb sh\u00ebrbimeve, duke p\u00ebrfituar shum\u00eb p\u00ebr biznesin.<\/p>\n<p>Qasjet dhe metodat efektive p\u00ebr sigurimin e aplikacioneve, llojet kryesore dhe vektor\u00ebt e sulmeve, zonat e rrezikut dhe boshll\u00ebqet n\u00eb sigurin\u00eb kibernetike t\u00eb aplikacioneve web, si dhe p\u00ebrvoja dhe praktikat m\u00eb t\u00eb mira globale, jan\u00eb paraqitur n\u00eb hulumtimin dhe raportin e Radware \u201c<noindex><a rel=\"nofollow\" href=\"https:\/\/radware.pro\/catalog\/web_application_security_digitally_connected_world_2019\/\">Siguria e Aplikacioneve Web n\u00eb nj\u00eb Bot\u00eb Digjitale t\u00eb Lidhur<\/a><\/noindex>\u201d.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/476490\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0435\u0442\u0440\u043e\u0441\u043f\u0435\u043a\u0442\u0438\u0432\u0430 \u041c\u0430\u0441\u0448\u0442\u0430\u0431, \u0441\u043e\u0441\u0442\u0430\u0432 \u0438 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043a\u0438\u0431\u0435\u0440\u0443\u0433\u0440\u043e\u0437 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0431\u044b\u0441\u0442\u0440\u043e \u044d\u0432\u043e\u043b\u044e\u0446\u0438\u043e\u043d\u0438\u0440\u0443\u044e\u0442. \u0414\u043e\u043b\u0433\u0438\u0435 \u0433\u043e\u0434\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u043b\u0438 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0432\u0435\u0431-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c \u0447\u0435\u0440\u0435\u0437 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u0432\u0435\u0431-\u0431\u0440\u0430\u0443\u0437\u0435\u0440\u043e\u0432. \u0412 \u043a\u0430\u0436\u0434\u044b\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u0431\u044b\u043b\u043e \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0442\u044c 2-5 \u0432\u0435\u0431-\u0431\u0440\u0430\u0443\u0437\u0435\u0440\u043e\u0432, \u0438 \u043d\u0430\u0431\u043e\u0440 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0438 \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0432\u0435\u0431-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0431\u044b\u043b \u0432 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e\u0439 \u0441\u0442\u0435\u043f\u0435\u043d\u0438 \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d. \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u043e\u0447\u0442\u0438 \u0432\u0441\u0435 \u0431\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445 \u0431\u044b\u043b\u0438 \u043f\u043e\u0441\u0442\u0440\u043e\u0435\u043d\u044b \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c SQL. \u041a [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-52993","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0435\u0442\u0440\u043e\u0441\u043f\u0435\u043a\u0442\u0438\u0432\u0430 \u041c\u0430\u0441\u0448\u0442\u0430\u0431, \u0441\u043e\u0441\u0442\u0430\u0432 \u0438 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043a\u0438\u0431\u0435\u0440\u0443\u0433\u0440\u043e\u0437 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0431\u044b\u0441\u0442\u0440\u043e \u044d\u0432\u043e\u043b\u044e\u0446\u0438\u043e\u043d\u0438\u0440\u0443\u044e\u0442. \u0414\u043e\u043b\u0433\u0438\u0435 \u0433\u043e\u0434\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u043b\u0438 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0432\u0435\u0431-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c \u0447\u0435\u0440\u0435\u0437 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u0432\u0435\u0431-\u0431\u0440\u0430\u0443\u0437\u0435\u0440\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/funktsional-sovremennyh-sistem-zashhity-prilozhenij-waf-dolzhen-byt-gorazdo-shire-spiska-uyazvimostej-iz-owasp-top-10\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0424\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u0437\u0430\u0449\u0438\u0442\u044b \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 (WAF) \u0434\u043e\u043b\u0436\u0435\u043d \u0431\u044b\u0442\u044c \u0433\u043e\u0440\u0430\u0437\u0434\u043e \u0448\u0438\u0440\u0435 \u0441\u043f\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438\u0437 OWASP \u0422\u043e\u043f 10 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0435\u0442\u0440\u043e\u0441\u043f\u0435\u043a\u0442\u0438\u0432\u0430 \u041c\u0430\u0441\u0448\u0442\u0430\u0431, \u0441\u043e\u0441\u0442\u0430\u0432 \u0438 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043a\u0438\u0431\u0435\u0440\u0443\u0433\u0440\u043e\u0437 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0431\u044b\u0441\u0442\u0440\u043e \u044d\u0432\u043e\u043b\u044e\u0446\u0438\u043e\u043d\u0438\u0440\u0443\u044e\u0442. \u0414\u043e\u043b\u0433\u0438\u0435 \u0433\u043e\u0434\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u043b\u0438 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0432\u0435\u0431-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c \u0447\u0435\u0440\u0435\u0437 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u0432\u0435\u0431-\u0431\u0440\u0430\u0443\u0437\u0435\u0440\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/funktsional-sovremennyh-sistem-zashhity-prilozhenij-waf-dolzhen-byt-gorazdo-shire-spiska-uyazvimostej-iz-owasp-top-10\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-20T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:00:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Funksionaliteti i sistemeve moderne t\u00eb mbrojtjes s\u00eb aplikacioneve (WAF) duhet t\u00eb jet\u00eb shum\u00eb m\u00eb i gjer\u00eb se lista e dob\u00ebsive nga OWASP Top 10 | ProHoster","description":"Retrospektiv\u00eb Masat, p\u00ebrb\u00ebrja dhe struktura e k\u00ebrc\u00ebnimeve kibernetike p\u00ebr aplikacione po evoluojn\u00eb me shpejt\u00ebsi. P\u00ebr nj\u00eb koh\u00eb t\u00eb gjat\u00eb, p\u00ebrdoruesit kan\u00eb accesuar n\u00eb aplikacionet web p\u00ebrmes internetit duke p\u00ebrdorur shfletues t\u00eb njohur.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/funktsional-sovremennyh-sistem-zashhity-prilozhenij-waf-dolzhen-byt-gorazdo-shire-spiska-uyazvimostej-iz-owasp-top-10","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0424\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u0437\u0430\u0449\u0438\u0442\u044b \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 (WAF) \u0434\u043e\u043b\u0436\u0435\u043d \u0431\u044b\u0442\u044c \u0433\u043e\u0440\u0430\u0437\u0434\u043e \u0448\u0438\u0440\u0435 \u0441\u043f\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438\u0437 OWASP \u0422\u043e\u043f 10 | ProHoster","og:description":"\u0420\u0435\u0442\u0440\u043e\u0441\u043f\u0435\u043a\u0442\u0438\u0432\u0430 \u041c\u0430\u0441\u0448\u0442\u0430\u0431, \u0441\u043e\u0441\u0442\u0430\u0432 \u0438 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043a\u0438\u0431\u0435\u0440\u0443\u0433\u0440\u043e\u0437 \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0431\u044b\u0441\u0442\u0440\u043e \u044d\u0432\u043e\u043b\u044e\u0446\u0438\u043e\u043d\u0438\u0440\u0443\u044e\u0442. \u0414\u043e\u043b\u0433\u0438\u0435 \u0433\u043e\u0434\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043f\u043e\u043b\u0443\u0447\u0430\u043b\u0438 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0432\u0435\u0431-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u043c \u0447\u0435\u0440\u0435\u0437 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u0432\u0435\u0431-\u0431\u0440\u0430\u0443\u0437\u0435\u0440\u043e\u0432.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/funktsional-sovremennyh-sistem-zashhity-prilozhenij-waf-dolzhen-byt-gorazdo-shire-spiska-uyazvimostej-iz-owasp-top-10","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-20T21:00:00+00:00","article:modified_time":"2020-02-18T11:00:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"52993","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 05:40:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:33:28","updated":"2026-01-24 05:40:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=52993"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/52993\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=52993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=52993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=52993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}