OWASP TOP 10

Source: Internet
Author: User
Tags http cookie


And how big-IP ASM mitigates the vulnerabilities.


Vulnerability

Big-IP ASM Controls

A1

Injection Flaws

attack signatures

meta character restrictions

parameter value Length restrictions

A2

Broken authentication and Session Management

brute Force protection

credentials stuffing protection

session tracking

http Cookie tampering protection

P style= "Box-sizing:border-box;" >session Hijacking protection

a3

Sensitive Data Exposure

data Guard

A4

XML External entities (XXE)

attack signatures ("Other application Attacks"-XXE)

a5

Broken Access Control

file types

login enforcement

session tracking

attack signatures ("Directory traversal")

a6

Security misconfiguration

attack Signatures

dast integration

allowed Methods

a7

Cross-site Scripting (XSS)

attack signatures ("Cross Site Scripting (XSS)")

httponly cookie attribute Enforcement

A8

Insecure deserialization

Attack Signatures ("Server Side Code Injection")

A9

Using components with known vulnerabilities

Attack Signatures

DAST Integration

A10

Insufficient Logging and monitoring

Request/response Logging

Attack Alarm/block Logging

On-device logging and external logging to SIEM system

Event Correlation

Specifically, we have attack signatures for "A4:2017-xml External entities (XXE)":

    • 200018018 External Entity Injection attempt

    • 200018030 XML External Entity (XXE) injection attempt (Content)

Also, XXE attack could be mitigated by XML profiles, by disabling DTDs (and of course enabling the "Malformed XML data" vio Lation):



OWASP TOP 10

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.