{"id":55733,"date":"2020-01-27T00:00:00","date_gmt":"2020-01-26T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/evolyutsiya-web-application-firewall-ot-setevyh-ekranov-do-oblachnyh-sistem-zashhity-s-mashinnym-obucheniem"},"modified":"2020-02-18T14:03:52","modified_gmt":"2020-02-18T11:03:52","slug":"evolyutsiya-web-application-firewall-ot-setevyh-ekranov-do-oblachnyh-sistem-zashhity-s-mashinnym-obucheniem","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/evolyutsiya-web-application-firewall-ot-setevyh-ekranov-do-oblachnyh-sistem-zashhity-s-mashinnym-obucheniem","title":{"rendered":"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><b>N\u00eb materialin ton\u00eb t\u00eb kaluar mbi tem\u00ebn e cloud-it ne <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ru_mts\/blog\/472892\/\">treguam<\/a><\/noindex>, si t\u00eb mbrohet infrastruktura IT n\u00eb cloud publik dhe pse antivirus\u00ebt tradicional\u00eb nuk jan\u00eb krejt\u00ebsisht t\u00eb p\u00ebrshtatsh\u00ebm p\u00ebr k\u00ebto q\u00ebllime. N\u00eb k\u00ebt\u00eb postim do t\u00eb vazhdojm\u00eb tem\u00ebn e siguris\u00eb n\u00eb cloud dhe do t\u00eb flasim p\u00ebr evoluimin e WAF dhe se \u00e7far\u00eb \u00ebsht\u00eb m\u00eb mir\u00eb t\u00eb zgjidhni: harduer, softuer ose cloud.\u00a0<\/b><\/p>\n<p><img decoding=\"async\" alt=\"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik\" src=\"\/wp-content\/uploads\/2020\/01\/5b41836fd429c5c434c6289e583500c9.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>\u00c7far\u00eb \u00ebsht\u00eb WAF<\/h3>\n<p>\nM\u00eb shum\u00eb se 75% e sulmeve nga hakera jan\u00eb t\u00eb drejtuara ndaj dob\u00ebsive t\u00eb aplikacioneve web dhe faqeve: k\u00ebto sulme zakonisht jan\u00eb t\u00eb padukshme p\u00ebr infrastruktur\u00ebn dhe sh\u00ebrbimet e siguris\u00eb. Dob\u00ebsit\u00eb e aplikacioneve web p\u00ebrmbajn\u00eb, nga ana e tyre, rreziqe t\u00eb kompromentimit dhe mashtrimit t\u00eb llogarive dhe t\u00eb dh\u00ebnave personale t\u00eb p\u00ebrdoruesve, fjal\u00ebkalimeve, numrave t\u00eb kartave t\u00eb kreditit. P\u00ebr m\u00eb tep\u00ebr, dob\u00ebsit\u00eb n\u00eb nj\u00eb faqe interneti sh\u00ebrbejn\u00eb si pik\u00eb hyrjeje p\u00ebr sulmuesit n\u00eb rrjetin korporativ.<\/p>\n<p>Web Application Firewall (WAF) paraqet nj\u00eb ekran mbrojt\u00ebs, i cili bllokon sulmet ndaj aplikacioneve web: SQL injeksione, skriptim t\u00eb nd\u00ebrfaqes s\u00eb p\u00ebrdoruesit, ekzekutimin e kodit n\u00eb distanc\u00eb, brute force dhe shmangien e autorizimit (auth bypass). Kjo p\u00ebrfshin edhe sulmet q\u00eb p\u00ebrdorin dob\u00ebsi zero-day. Firewall-\u00ebt e aplikacioneve sigurojn\u00eb mbrojtje duke monitoruar p\u00ebrmbajtjen e faqeve web, duke p\u00ebrfshir\u00eb HTML, DHTML dhe CSS, dhe duke filtruar k\u00ebrkesat potencialisht d\u00ebmtuese p\u00ebrmes HTTP\/HTTPS.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>Cilat ishin zgjidhjet e para?<\/h3>\n<p>\nP\u00ebrpjekjet e para p\u00ebr t\u00eb krijuar Web Application Firewall u b\u00ebn\u00eb q\u00eb n\u00eb fillim t\u00eb viteve '90. Dihet t\u00eb pakt\u00ebn p\u00ebr tre inxhinier\u00eb q\u00eb punuan n\u00eb k\u00ebt\u00eb fush\u00eb. I pari \u2014 profesori i shkencave kompjuterike Jean Spafford nga Universiteti Purdue. Ai p\u00ebrshkroi arkitektur\u00ebn e nj\u00eb firewall-i aplikacionesh me proxy dhe e publikoi at\u00eb n\u00eb 1991 n\u00eb librin <noindex><a rel=\"nofollow\" href=\"https:\/\/www.oreilly.com\/library\/view\/practical-unix-and\/0596003234\/\">\u201eSiguria UNIX n\u00eb praktik\u00eb\u201c<\/a><\/noindex>.<\/p>\n<p>I dyti dhe i treti \u2014 ishin specialist\u00ebt e siguris\u00eb William Cheswick dhe Marcus Ranum nga Bell Labs. Ata zhvilluan nj\u00eb nga prototipet e para t\u00eb firewall-\u00ebve t\u00eb aplikacioneve. Shp\u00ebrndarja e tij u realizua nga kompania DEC \u2014 produkti u l\u00ebshua me emrin SEAL (Secure External Access Link). <\/p>\n<p>Por SEAL nuk ishte nj\u00eb zgjidhje e plot\u00eb WAF. Ai p\u00ebrb\u00ebnte nj\u00eb firewall t\u00eb zakonsh\u00ebm t\u00eb rrjetit me funksionalitet t\u00eb zgjeruar \u2014 mund\u00ebsin\u00eb p\u00ebr t\u00eb bllokuar sulmet ndaj FTP dhe RSH. P\u00ebr k\u00ebt\u00eb arsye, sot zgjidhja e par\u00eb WAF konsiderohet produkti i kompanis\u00eb Perfecto Technologies (m\u00eb pas Sanctum). N\u00eb vitin 1999 ajo <noindex><a rel=\"nofollow\" href=\"http:\/\/www.internetnews.com\/ec-news\/article.php\/190571\/Perfecto+Technologies+Delivers+AppShield+for+EBusiness.htm\">ka prezantuar<\/a><\/noindex> sistemin AppShield. N\u00eb at\u00eb koh\u00eb, Perfecto Technologies po merreshin me zhvillimin e zgjidhjeve t\u00eb siguris\u00eb p\u00ebr e-commerce dhe audienca q\u00eb kishin synuar p\u00ebr produktin e tyre t\u00eb ri ishin dyqanet online. AppShield kishte aft\u00ebsin\u00eb t\u00eb analizonte k\u00ebrkesat HTTP dhe bllokonte sulmet n\u00eb baz\u00eb t\u00eb politikave dinamike t\u00eb siguris\u00eb.<\/p>\n<p>Rreth t\u00eb nj\u00ebjt\u00ebs koh\u00eb me AppShield (n\u00eb vitin 2002) u shfaq WAF-i i par\u00eb me kod t\u00eb hapur. Ai quhej <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/ModSecurity\">ModSecurity<\/a><\/noindex>. Ai u krijua me q\u00ebllim q\u00eb t\u00eb popullarizonte teknologjit\u00eb WAF dhe mb\u00ebshtetet ende nga komuniteti IT (ja <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/SpiderLabs\/ModSecurity\">repoja e tij n\u00eb GitHub<\/a><\/noindex>). ModSecurity bllokon sulmet ndaj aplikacioneve duke u bazuar n\u00eb nj\u00eb grup standard t\u00eb shprehjeve t\u00eb rregullta (n\u00ebnshkrimeve) \u2014 mjete p\u00ebr kontrollin e k\u00ebrkesave sipas nj\u00eb modeli \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/SpiderLabs\/owasp-modsecurity-crs\">Seti Kryesor i Rregullave t\u00eb OWASP<\/a><\/noindex>.<\/p>\n<p>Si rezultat, zhvilluesit arrit\u00ebn ta realizonin q\u00ebllimin e tyre \u2014 n\u00eb treg filluan t\u00eb shfaqen zgjidhje t\u00eb reja WAF, p\u00ebrfshir\u00eb ato t\u00eb nd\u00ebrtuara mbi ModSecurity.<\/p>\n<h3>T\u00eb treja gjeneratat \u2014 tashm\u00eb histori<\/h3>\n<p>\nPraket e zakonshme jan\u00eb identifikimi i tre gjeneratave t\u00eb sistemeve WAF, t\u00eb cilat kan\u00eb evoluar me zhvillimin e teknologjive.<\/p>\n<p><b>Gjenerata e par\u00eb<\/b>. Puna me shprehje t\u00eb rregullta (ose gramatika). Nd\u00ebr t\u00eb tjera \u00ebsht\u00eb ModSecurity. Ofruesi i sistemit studion llojet e sulmeve ndaj aplikacioneve dhe formon modele q\u00eb p\u00ebrshkruajn\u00eb k\u00ebrkesa legjitime dhe potencialisht t\u00eb d\u00ebmshme. WAF-i p\u00ebrputhet me k\u00ebto listat dhe vendos se \u00e7far\u00eb t\u00eb b\u00ebj\u00eb n\u00eb situata t\u00eb caktuara \u2014 t\u00eb bllokoj\u00eb trafik apo jo.<\/p>\n<p>Nj\u00eb shembull i zbulimit n\u00eb baz\u00eb t\u00eb shprehjeve t\u00eb rregullta \u00ebsht\u00eb projekti q\u00eb u p\u00ebrmend m\u00eb par\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/SpiderLabs\/owasp-modsecurity-crs\">Seti Kryesor i Rregullave<\/a><\/noindex> me kod t\u00eb hapur. Nj\u00eb shembull tjet\u00ebr \u00ebsht\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nbs-system\/naxsi\">Naxsi<\/a><\/noindex>, i cili gjithashtu \u00ebsht\u00eb me kod t\u00eb hapur. Sistemet me shprehje t\u00eb rregullta kan\u00eb disa disavantazhe, ve\u00e7an\u00ebrisht, kur zbulohet nj\u00eb dob\u00ebsi e re, administratori duhet t\u00eb krijoj\u00eb rregulla shtes\u00eb manualisht. N\u00eb rastin e nj\u00eb infrastrukture t\u00eb madhe IT, rregullat mund t\u00eb jen\u00eb mij\u00ebra. T\u00eb menaxhosh nj\u00eb num\u00ebr kaq t\u00eb madh shprehjesh t\u00eb rregullta \u00ebsht\u00eb mjaft e v\u00ebshtir\u00eb, p\u00ebrve\u00e7 faktit se kontrolli i tyre mund t\u00eb ul\u00eb performanc\u00ebn e rrjetit.<\/p>\n<p>Po gjithashtu, shprehjet e rregullta kan\u00eb nj\u00eb nivel t\u00eb lart\u00eb t\u00eb rremeve pozitive. Ling\u00fcisti i njohur Noam Chomsky ofroi nj\u00eb klasifikim t\u00eb gramatikave, duke i ndar\u00eb ato n\u00eb kat\u00ebr nivele t\u00eb kushtuesh\u00ebm kompleksiteti. Sipas k\u00ebsaj klasifikimi, me shprehje t\u00eb rregullta mund t\u00eb p\u00ebrshkruhen vet\u00ebm rregullat e firewall-it q\u00eb nuk parashikojn\u00eb devijime nga modeli. Kjo do t\u00eb thot\u00eb se ata q\u00eb kryejn\u00eb sulme mund t\u00eb 'mashtrojn\u00eb' leht\u00ebsisht WAF-in e gjenerat\u00ebs s\u00eb par\u00eb. Nj\u00eb nga metodat p\u00ebr ta luftuar k\u00ebt\u00eb \u00ebsht\u00eb t\u00eb shtohen n\u00eb k\u00ebrkesat p\u00ebr aplikacione simbole speciale q\u00eb nuk ndikojn\u00eb n\u00eb logjik\u00ebn e t\u00eb dh\u00ebnave t\u00eb d\u00ebmshme, por p\u00ebrshtatin rregullin e n\u00ebnshkrimit.<\/p>\n<p><img decoding=\"async\" alt=\"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik\" src=\"\/wp-content\/uploads\/2020\/01\/e4ca4ddd7e6dc099c8168b02c365bdc5.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>Gjenerata e dyt\u00eb<\/b>. P\u00ebr t\u00eb anashkaluar problemet q\u00eb lidhen me performanc\u00ebn dhe sakt\u00ebsin\u00eb e WAF-it, jan\u00eb zhvilluar firewall-a t\u00eb aplikacioneve t\u00eb gjenerat\u00ebs s\u00eb dyt\u00eb. Aty jan\u00eb shfaqur parser\u00eb q\u00eb jan\u00eb p\u00ebrgjegj\u00ebs p\u00ebr identifikimin e tipeve strikte t\u00eb sulmeve (n\u00eb HTML, JS etj.). K\u00ebta parser\u00eb punojn\u00eb me token\u00eb t\u00eb ve\u00e7ant\u00eb q\u00eb p\u00ebrshkruajn\u00eb k\u00ebrkesat (p.sh., variable, string, unknown, number). Sekuencat potencialisht t\u00eb d\u00ebmshme t\u00eb token\u00ebve nxirren n\u00eb nj\u00eb list\u00eb t\u00eb ve\u00e7ant\u00eb, me t\u00eb cil\u00ebn WAF-i kontrollohet rregullisht. Ky qasje u tregua p\u00ebr her\u00eb t\u00eb par\u00eb n\u00eb konferenc\u00ebn Black Hat 2012 n\u00eb form\u00ebn e bibliotek\u00ebs C\/C++\u00a0<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/client9\/libinjection\">libinjection<\/a><\/noindex>, e cila lejon identifikimin e injeksioneve SQL.<\/p>\n<p>N\u00eb krahasim me WAF-in e gjenerat\u00ebs s\u00eb par\u00eb, parser\u00ebt e specializuar mund t\u00eb punojn\u00eb m\u00eb shpejt. Megjithat\u00eb, ata nuk zgjidhin v\u00ebshtir\u00ebsit\u00eb q\u00eb lidhen me konfigurimin manual t\u00eb sistemit kur shfaqen sulme t\u00eb reja t\u00eb d\u00ebmshme. <\/p>\n<p><img decoding=\"async\" alt=\"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik\" src=\"\/wp-content\/uploads\/2020\/01\/beb4b34f64438af88c8b23ef0808f403.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>Gjenerata e tret\u00eb<\/b>. Evolucioni n\u00eb logjik\u00ebn e zbulimit t\u00eb gjenerat\u00ebs s\u00eb tret\u00eb q\u00ebndron n\u00eb p\u00ebrdorimin e metodave t\u00eb m\u00ebsimit t\u00eb makinerive, q\u00eb ofron mund\u00ebsin\u00eb m\u00eb t\u00eb af\u00ebrt p\u00ebr gramatik\u00ebn e zbulimit me gramatik\u00ebn reale SQL\/HTML\/JS t\u00eb sistemeve t\u00eb mbrojtura. Kjo logjik\u00eb zbulimi \u00ebsht\u00eb n\u00eb gjendje t\u00eb adaptohet me makin\u00ebn Turing p\u00ebr t\u00eb mbuluar gramatikat q\u00eb num\u00ebrohen rekurzivisht. M\u00eb par\u00eb, detyra e krijimit t\u00eb nj\u00eb makine Turing t\u00eb adaptueshme ka qen\u00eb e pazgjidhshme, derisa jan\u00eb publikuar hulumtimet e para mbi makinat neuronale Turing.<\/p>\n<p>M\u00ebsimi i makinave ofron nj\u00eb mund\u00ebsi unike p\u00ebr t\u00eb p\u00ebrshtatur \u00e7do gramatik\u00eb p\u00ebr t\u00eb mbuluar \u00e7do lloj sulmi pa krijuar manualisht lista n\u00ebnshkrimesh, si\u00e7 k\u00ebrkohej n\u00eb zbulimin e brezit t\u00eb par\u00eb, dhe pa zhvilluar tokenizues \/ parser\u00eb t\u00eb rinj p\u00ebr lloje t\u00eb reja sulmesh si Memcached, Redis, Cassandra, SSRF, ashtu si\u00e7 k\u00ebrkonte metodologjia e brezit t\u00eb dyt\u00eb. <\/p>\n<p>Duke bashkuar t\u00eb tre brezat e logjik\u00ebs s\u00eb zbulimit, ne mund t\u00eb vizatojm\u00eb nj\u00eb diagram t\u00eb ri, ku brezi i tret\u00eb i zbulimit \u00ebsht\u00eb i paraqitur me nj\u00eb vij\u00eb t\u00eb kuqe (shih. 3). N\u00eb k\u00ebt\u00eb brez p\u00ebrfshihet nj\u00eb nga zgjidhjet q\u00eb ne implementojm\u00eb n\u00eb mjete cloud n\u00eb bashk\u00ebpunim me 'Onsec', zhvilluesin e platform\u00ebs p\u00ebr mbrojtjen adaptuese t\u00eb aplikacioneve web dhe API-s\u00eb Valarm. <\/p>\n<p>Tani, logjika e zbulimit p\u00ebrdor feedback nga aplikacioni p\u00ebr vet\u00eb-rregullim. N\u00eb kuad\u00ebr t\u00eb m\u00ebsimit t\u00eb makinave, ky cik\u00ebl feedback quhet 'forcim'. N\u00eb p\u00ebrgjith\u00ebsi, ekzistojn\u00eb nj\u00eb ose m\u00eb shum\u00eb lloje t\u00eb k\u00ebtij forcmimi:<\/p>\n<ul>\n<li>Analiza e sjelljes s\u00eb p\u00ebrgjigjes s\u00eb aplikacionit (pasive)<\/li>\n<li>Skanime \/ fuzzing (aktive)<\/li>\n<li>Skedar\u00eb raportesh \/ procedura kap\u00ebse \/ kurthe (post factum)<\/li>\n<li>Manuale (e p\u00ebrcaktuar nga supervizori)<\/li>\n<\/ul>\n<p>\nSi rezultat, logjika e zbulimit t\u00eb brezit t\u00eb tret\u00eb gjithashtu zgjidh nj\u00eb \u00e7\u00ebshtje t\u00eb r\u00ebnd\u00ebsishme t\u00eb sakt\u00ebsis\u00eb. Tani \u00ebsht\u00eb e mundur jo vet\u00ebm t\u00eb shmangen njoftimet e rreme dhe mohim t\u00eb rrem\u00eb, por gjithashtu t\u00eb zbulohet p\u00ebrdorimi i rezultateve t\u00eb v\u00ebrteta negative t\u00eb pranueshme, si\u00e7 \u00ebsht\u00eb zbulimi i p\u00ebrdorimit t\u00eb komponentit SQL n\u00eb panelin e menaxhimit, ngarkimi i modeleve t\u00eb faqeve web, k\u00ebrkesat AJAX q\u00eb lidhen me gabimet JavaScript dhe t\u00eb tjera.<\/p>\n<p><img decoding=\"async\" alt=\"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik\" src=\"\/wp-content\/uploads\/2020\/01\/bf6a83883291cdd41b468dd8a197062e.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik\" src=\"\/wp-content\/uploads\/2020\/01\/7498f6e7978855df24c4e5b41376c0f7.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik\" src=\"\/wp-content\/uploads\/2020\/01\/1d811726a068994eeaaad24f0fa67783.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nM\u00eb tej, do t\u00eb shqyrtojm\u00eb mund\u00ebsit\u00eb teknologjike t\u00eb varianteve t\u00eb ndryshme t\u00eb implementimit t\u00eb WAF. <\/p>\n<h3>Harduer, softuer apo cloud \u2014 \u00e7far\u00eb t\u00eb zgjedhim?<\/h3>\n<p>\nNj\u00eb nga variantet e implementimit t\u00eb firewall-ve t\u00eb aplikacioneve \u00ebsht\u00eb zgjidhja 'harduer'. K\u00ebto sisteme jan\u00eb pajisje t\u00eb specializuara kompjuterike q\u00eb kompania i instalon lokal n\u00eb qendr\u00ebn e saj t\u00eb t\u00eb dh\u00ebnave. Por n\u00eb k\u00ebt\u00eb rast, duhet t\u00eb blihen pajisjet p\u00ebrkat\u00ebse dhe t\u00eb paguhen integrator\u00ebt p\u00ebr rregullimin dhe konfiguromin e saj (n\u00ebse kompania nuk ka departamentin e saj IT). Po ashtu, \u00e7do pajisje bazohet n\u00eb teknologji e vjetruar dhe mund t\u00eb d\u00ebshtoj\u00eb, prandaj klient\u00ebt jan\u00eb t\u00eb detyruar t\u00eb planifikojn\u00eb buxhet p\u00ebr rinovimin e pajisjeve.<\/p>\n<p>Nj\u00eb variant tjet\u00ebr i implementimit t\u00eb WAF \u00ebsht\u00eb zbatimi programor. Zgjidhja instalohet si nj\u00eb shtes\u00eb p\u00ebr ndonj\u00eb program t\u00eb caktuar (p.sh., ModSecurity konfigurohet mbi Apache) dhe punon n\u00eb t\u00eb nj\u00ebjtin server me t\u00eb. Si rregull, zgjidhje t\u00eb tilla mund t\u00eb implementohen si n\u00eb server\u00eb fizik\u00eb ashtu edhe n\u00eb cloud. Disavantazhi i tyre jan\u00eb mund\u00ebsit\u00eb e kufizuara t\u00eb shkall\u00ebzueshm\u00ebris\u00eb dhe mb\u00ebshtetje nga furnizuesi. <\/p>\n<p>Varianti i tret\u00eb \u00ebsht\u00eb konfigurimi i WAF nga cloud. Zgjidhjet e tilla ofrohen nga ofruesit cloud si nj\u00eb sh\u00ebrbim me abone. Kompanit\u00eb nuk kan\u00eb nevoj\u00eb t\u00eb blejn\u00eb dhe konfigurojn\u00eb harduer t\u00eb specializuar, k\u00ebto detyra bien n\u00eb krah\u00ebt e ofruesit t\u00eb sh\u00ebrbimit. Nj\u00eb pik\u00eb e r\u00ebnd\u00ebsishme \u00ebsht\u00eb se WAF moderne n\u00eb cloud nuk n\u00ebnkupton migrimin e burimeve n\u00eb platform\u00ebn e ofruesit. Website-i mund t\u00eb jet\u00eb i implementuar n\u00eb \u00e7do vend, madje edhe n\u00eb ambientin e brendsh\u00ebm.<\/p>\n<p>Pse tani e m\u00eb shum\u00eb po shikohet drejt WAF n\u00eb cloud, do ta tregojm\u00eb m\u00eb von\u00eb.<\/p>\n<h3>\u00c7far\u00eb mund t\u00eb b\u00ebj\u00eb WAF n\u00eb cloud<\/h3>\n<p>\nNga pik\u00ebpamja e mund\u00ebsive teknologjike:<\/p>\n<ul>\n<li><b>P\u00ebr azhurnimet \u00ebsht\u00eb p\u00ebrgjegj\u00ebs ofruesi<\/b>. WAF ofrohet me abone, prandaj p\u00ebr aktualitetin e azhurnimeve dhe licencave kujdeset ofruesi i sh\u00ebrbimit. Azhurnimet p\u00ebrfshijn\u00eb jo vet\u00ebm softuerin, por edhe harduerin. Ofruesi p\u00ebrmir\u00ebson parkun server dhe merret me mir\u00ebmbajtjen e tij. Ai gjithashtu \u00ebsht\u00eb p\u00ebrgjegj\u00ebs p\u00ebr balancimin e ngarkes\u00ebs dhe rezervimin. N\u00ebse ndodh nj\u00eb d\u00ebshtim n\u00eb pun\u00ebn e serverit WAF, trafiku menj\u00ebher\u00eb ridrejtohet n\u00eb nj\u00eb makin\u00eb tjet\u00ebr. Shp\u00ebrndarja e arsyeshme e trafikut lejon shmangien e situatave kur firewalla kalon n\u00eb modin fail open - nuk p\u00ebrballon ngarkes\u00ebn dhe ndalon s\u00eb filtruar k\u00ebrkesat.<\/li>\n<li><b>Patch virtual<\/b>. Patch virtuale kufizon qaccess n\u00eb pjes\u00ebt e kompromentuara t\u00eb aplikacionit deri n\u00eb mbylljen e dob\u00ebsis\u00eb nga zhvilluesi. Si rezultat, klienti i ofruesit t\u00eb sh\u00ebrbimeve cloud ka mund\u00ebsin\u00eb t\u00eb pres\u00eb me qet\u00ebsi deri sa furnizuesi i softuerit t\u00eb publikoj\u00eb \"patch\"-et zyrtare. T\u00eb b\u00ebsh k\u00ebt\u00eb sa m\u00eb shpejt t\u00eb jet\u00eb e mundur \u00ebsht\u00eb nj\u00eb prioritet p\u00ebr furnizuesin e softuerit. P\u00ebr shembull, n\u00eb platform\u00ebn \"Valarm\", nj\u00eb modul i ve\u00e7ant\u00eb programor \u00ebsht\u00eb p\u00ebrgjegj\u00ebs p\u00ebr patch virtual. Administratori mund t\u00eb shtoj\u00eb shprehje t\u00eb rregullta t\u00eb personalizuara p\u00ebr t\u00eb bllokuar k\u00ebrkesat e d\u00ebmshme. Sistemi lejon sh\u00ebnimin e disa k\u00ebrkesave me flamurin \"T\u00eb dh\u00ebna t\u00eb Besueshme\". K\u00ebshtu, parametrat e tyre maskohen dhe ato nuk transmetohen n\u00ebn asnj\u00eb rrethan\u00eb jasht\u00eb zon\u00ebs operative t\u00eb firewall-it.<\/li>\n<li><b>Skeneri i integruar i perimetrave dhe dob\u00ebsive<\/b>. Kjo lejon p\u00ebrcaktimin e vet\u00eb kufijve rrjetit t\u00eb infrastruktur\u00ebs IT, duke p\u00ebrdorur t\u00eb dh\u00ebnat e k\u00ebrkesave DNS dhe protokollit WHOIS. M\u00eb pas, WAF automatikisht analizon sh\u00ebrbimet dhe sh\u00ebrbimet q\u00eb funksionojn\u00eb brenda perimetrave (b\u00ebn skanimin e porteve). Firewall-i \u00ebsht\u00eb n\u00eb gjendje t\u00eb zbuloj\u00eb t\u00eb gjitha tipet e zakonshme t\u00eb dob\u00ebsive \u2014 SQLi, XSS, XXE etj. \u2014 dhe t\u00eb identifikoj\u00eb gabimet n\u00eb konfigurimin e softuerit, si p.sh. aksesin e paautorizuar n\u00eb repositor\u00ebt Git dhe BitBucket dhe k\u00ebrkesat anonime ndaj Elasticsearch, Redis, MongoDB. <\/li>\n<li><b>Sulmet monitorohen nga burimet e cloud<\/b>. Zakonisht, ofruesit e cloud kan\u00eb kapacitete t\u00eb m\u00ebdha llogarit\u00ebse. Kjo lejon analizimin e k\u00ebrc\u00ebnimeve me sakt\u00ebsi dhe shpejt\u00ebsi t\u00eb lart\u00eb. N\u00eb cloud vendoset nj\u00eb klaster i nyjeve filtruese, p\u00ebrmes t\u00eb cilave kalon gjith\u00eb trafiku. K\u00ebto nyje bllokojn\u00eb sulmet ndaj aplikacioneve web dhe d\u00ebrgojn\u00eb statistikat n\u00eb Qendr\u00ebn e Analiz\u00ebs. Ajo p\u00ebrdor algoritme t\u00eb m\u00ebsimit t\u00eb makinerive p\u00ebr t\u00eb p\u00ebrmir\u00ebsuar rregullat e bllokimit p\u00ebr t\u00eb gjitha aplikacionet e mbrojtura. Realizimi i nj\u00eb skeme t\u00eb till\u00eb \u00ebsht\u00eb i ilustruar n\u00eb fig. 4. Rregullat e tilla t\u00eb adaptuara t\u00eb siguris\u00eb minimizojn\u00eb numrin e rremeve t\u00eb zbulimit nga firewall-i. <\/li>\n<\/ul>\n<p>\n<img decoding=\"async\" alt=\"Evolucioni i Web Application Firewall: nga mur\u00ebt mbrojt\u00ebs te sistemet mbrojt\u00ebse n\u00eb cloud me m\u00ebsim automatik\" src=\"\/wp-content\/uploads\/2020\/01\/9fe1eaea62f0a9055df88352b654bfac.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nTani pak p\u00ebr ve\u00e7orit\u00eb e WAF-ve cloud nga perspektiva organizative dhe menaxheriale:<\/p>\n<ul>\n<li><b>Kalimi n\u00eb OpEx<\/b>. N\u00eb rastin e WAF-ve cloud, kostoja e implementimit do t\u00eb jet\u00eb zero, pasi t\u00eb gjitha pajisjet dhe licencat jan\u00eb paguar tashm\u00eb nga ofruesi, pagesa p\u00ebr sh\u00ebrbimin b\u00ebhet me an\u00eb t\u00eb nj\u00eb abonimi. <\/li>\n<li><b>Plan t\u00eb ndryshme tarifore<\/b>. P\u00ebrdoruesi i sh\u00ebrbimit t\u00eb ruajtjes mund t\u00eb lidh\u00eb ose \u00e7aktivizoj\u00eb opsione shtes\u00eb me shpejt\u00ebsi. Menaxhimi i funksioneve realizohet nga nj\u00eb panel i vet\u00ebm kontrolli, i cili gjithashtu \u00ebsht\u00eb i siguruar. Qasja n\u00eb t\u00eb b\u00ebhet p\u00ebrmes HTTPS, plus ekziston nj\u00eb mekaniz\u00ebm autentikimi me dy faktor\u00eb mbi baz\u00ebn e protokollit TOTP (Algoritmi i Fjal\u00ebkalimeve t\u00eb Aft\u00ebsis\u00eb Nj\u00ebher\u00ebsh t\u00eb Bazuar n\u00eb Kohe).<\/li>\n<li><b>Lidhja p\u00ebrmes DNS<\/b>. Mund t\u00eb ndryshoni vet\u00eb DNS dhe t\u00eb konfiguroni rrug\u00ebzimin n\u00eb rrjet. P\u00ebr t\u00eb zgjidhur k\u00ebto \u00e7\u00ebshtje, nuk \u00ebsht\u00eb e nevojshme t\u00eb angazhoni dhe trainoni specialist\u00eb t\u00eb ve\u00e7ant\u00eb. Si rregull, me konfigurimin mund t\u00eb ndihmoj\u00eb mb\u00ebshtetje teknike nga ofruesi.<\/li>\n<\/ul>\n<p>\nTeknologjit\u00eb WAF kan\u00eb kaluar nj\u00eb evolucion nga firewall-et e thjeshta me rregulla empirike n\u00eb sisteme komplekse mbrojtjeje me algoritme t\u00eb m\u00ebsimit t\u00eb makinerive. Aktualisht, firewall-et e aplikacioneve kan\u00eb nj\u00eb gam\u00eb t\u00eb gjer\u00eb funksionesh, t\u00eb cilat ishin t\u00eb v\u00ebshtira p\u00ebr t\u2019u realizuar n\u00eb vitet '90. N\u00eb shum\u00eb aspekte, shfaqja e funksionaliteteve t\u00eb reja \u00ebsht\u00eb b\u00ebr\u00eb e mundur fal\u00eb teknologjive cloud. Zgjidhjet WAF dhe komponent\u00ebt e tyre vazhdojn\u00eb t\u00eb zhvillohen. Po ashtu si dhe sferat e tjera t\u00eb siguris\u00eb kibernetike. <\/p>\n<p><i>Tekstin e p\u00ebrgatiti Aleksand\u00ebr Karpuzikov, menaxher p\u00ebr zhvillimin e produkteve t\u00eb siguris\u00eb kibernetike t\u00eb ofruesit t\u00eb cloud #CloudMTS.<\/i><br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ru_mts\/blog\/485220\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043d\u0430\u0448\u0435\u043c \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0435 \u043f\u043e \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u0442\u0435\u043c\u0430\u0442\u0438\u043a\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0418\u0422-\u0440\u0435\u0441\u0443\u0440\u0441\u044b \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u043c \u043e\u0431\u043b\u0430\u043a\u0435 \u0438 \u043f\u043e\u0447\u0435\u043c\u0443 \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u044b \u043d\u0435 \u0441\u043e\u0432\u0441\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0442 \u0434\u043b\u044f \u044d\u0442\u0438\u0445 \u0446\u0435\u043b\u0435\u0439.\u00a0\u0412 \u044d\u0442\u043e\u043c \u043f\u043e\u0441\u0442\u0435 \u043c\u044b \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u043c \u0442\u0435\u043c\u0443 \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438 \u043f\u043e\u0433\u043e\u0432\u043e\u0440\u0438\u043c \u043e\u0431 \u044d\u0432\u043e\u043b\u044e\u0446\u0438\u0438 WAF \u0438 \u043e \u0442\u043e\u043c, \u0447\u0442\u043e \u043b\u0443\u0447\u0448\u0435 \u0432\u044b\u0431\u0440\u0430\u0442\u044c: \u0436\u0435\u043b\u0435\u0437\u043e, \u041f\u041e \u0438\u043b\u0438 \u043e\u0431\u043b\u0430\u043a\u043e.\u00a0 \u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 WAF \u0411\u043e\u043b\u0435\u0435 75% \u0430\u0442\u0430\u043a \u0445\u0430\u043a\u0435\u0440\u043e\u0432 \u043d\u0430\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u044b [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-55733","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043d\u0430\u0448\u0435\u043c \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0435 \u043f\u043e \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u0442\u0435\u043c\u0430\u0442\u0438\u043a\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0418\u0422-\u0440\u0435\u0441\u0443\u0440\u0441\u044b \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u043c \u043e\u0431\u043b\u0430\u043a\u0435 \u0438 \u043f\u043e\u0447\u0435\u043c\u0443.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/evolyutsiya-web-application-firewall-ot-setevyh-ekranov-do-oblachnyh-sistem-zashhity-s-mashinnym-obucheniem\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u042d\u0432\u043e\u043b\u044e\u0446\u0438\u044f Web Application Firewall: \u043e\u0442 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432 \u0434\u043e \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u0437\u0430\u0449\u0438\u0442\u044b \u0441 \u043c\u0430\u0448\u0438\u043d\u043d\u044b\u043c \u043e\u0431\u0443\u0447\u0435\u043d\u0438\u0435\u043c | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043d\u0430\u0448\u0435\u043c \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0435 \u043f\u043e \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u0442\u0435\u043c\u0430\u0442\u0438\u043a\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0418\u0422-\u0440\u0435\u0441\u0443\u0440\u0441\u044b \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u043c \u043e\u0431\u043b\u0430\u043a\u0435 \u0438 \u043f\u043e\u0447\u0435\u043c\u0443.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/evolyutsiya-web-application-firewall-ot-setevyh-ekranov-do-oblachnyh-sistem-zashhity-s-mashinnym-obucheniem\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-01-26T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:03:52+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Evolucioni i Firewall-it t\u00eb Aplikacioneve Web: nga firewall-et e rrjetit n\u00eb sistemet e mbrojtjes cloud me m\u00ebsim makinerie | ProHoster","description":"N\u00eb materialin ton\u00eb t\u00eb kaluar mbi tematin e cloud-it, ne treguam se si t\u00eb mbrojm\u00eb burimet IT n\u00eb cloud-in publik dhe pse.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/evolyutsiya-web-application-firewall-ot-setevyh-ekranov-do-oblachnyh-sistem-zashhity-s-mashinnym-obucheniem","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u042d\u0432\u043e\u043b\u044e\u0446\u0438\u044f Web Application Firewall: \u043e\u0442 \u0441\u0435\u0442\u0435\u0432\u044b\u0445 \u044d\u043a\u0440\u0430\u043d\u043e\u0432 \u0434\u043e \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c \u0437\u0430\u0449\u0438\u0442\u044b \u0441 \u043c\u0430\u0448\u0438\u043d\u043d\u044b\u043c \u043e\u0431\u0443\u0447\u0435\u043d\u0438\u0435\u043c | ProHoster","og:description":"\u0412 \u043d\u0430\u0448\u0435\u043c \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u0435 \u043f\u043e \u043e\u0431\u043b\u0430\u0447\u043d\u043e\u0439 \u0442\u0435\u043c\u0430\u0442\u0438\u043a\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u044b\u0432\u0430\u043b\u0438, \u043a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0418\u0422-\u0440\u0435\u0441\u0443\u0440\u0441\u044b \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u043c \u043e\u0431\u043b\u0430\u043a\u0435 \u0438 \u043f\u043e\u0447\u0435\u043c\u0443.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/evolyutsiya-web-application-firewall-ot-setevyh-ekranov-do-oblachnyh-sistem-zashhity-s-mashinnym-obucheniem","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-01-26T21:00:00+00:00","article:modified_time":"2020-02-18T11:03:52+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"55733","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 19:37:39","updated":"2022-09-28 16:21:54","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=55733"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/55733\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=55733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=55733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=55733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}