teler-waf は、Go ベースの Web アプリケーション向けの包括的なセキュリティソリューションです。HTTP ミドルウェアとして機能し、既存の Go アプリケーションに teler IDS の IDS 機能を統合するための使いやすいインターフェースを提供します。teler-waf を使用することで、クロスサイトスクリプティング(XSS)や SQL インジェクションなど、さまざまな Web ベースの攻撃から保護することができます。
このパッケージには標準の net/http.Handler が付属しており、アプリケーションのルーティングに簡単に統合できます。クライアントが teler-waf で保護されたルートにリクエストを行うと、最初に teler IDS に対してリクエストがチェックされ、既知の悪意のあるパターンが検出されます。悪意のあるパターンが検出されなかった場合、リクエストはさらに処理されるために渡されます。
Web ベースの攻撃に対する保護に加えて、teler-waf はアプリケーションの全体的なセキュリティと整合性を向上させるのにも役立ちます。高度に構成可能であり、アプリケーションの特定のニーズに合わせて調整することができます。
関連項目:
teler-waf は、Go Web アプリケーションのセキュリティを強化するために設計された、さまざまな強力な機能を提供します。
全体として、teler-waf は Go ベースの Web アプリケーションに包括的なセキュリティソリューションを提供し、Web ベースの攻撃から保護し、アプリケーションの全体的なセキュリティと整合性を向上させるのに役立ちます。
依存関係:
Go アプリケーションに teler-waf をインストールするには、次のコマンドを実行して teler-waf パッケージをダウンロードおよびインストールします。```console go get github.com/teler-sh/teler-waf
## 使用方法
> [!WARNING]
> **非推奨のお知らせ**: 脅威の除外 (`Excludes`) は、今後のリリース (**v2**) で非推奨になります。 [#73](https://github.com/teler-sh/teler-waf/discussions/73) および [#64](https://github.com/teler-sh/teler-waf/issues/64) を参照してください。
以下は、Goアプリケーションでteler-wafを使用する例です:
1. teler-wafパッケージをGoコードにインポートします:```go
import "github.com/teler-sh/teler-waf"
New 関数を使用して Teler 型の新しいインスタンスを作成します。この関数は、アプリケーションの特定のニーズに合わせて teler-waf を設定するために使用できる様々なオプションのパラメータを受け取ります。```go
waf := teler.New()3. `Teler`インスタンスの`Handler`メソッドを使用して、`net/http.Handler`を作成します。このハンドラは、アプリケーションのHTTPルーティングで使用して、特定のルートにteler-wafのセキュリティ対策を適用できます。```go
handler := waf.Handler(http.HandlerFunc(yourHandlerFunc))
handler を使用して、特定のルートにteler-wafのセキュリティ対策を適用します。```go
http.Handle("/path", handler)これで完了です!Goアプリケーションにteler-wafを設定しました。
**オプション:**
teler-wafをカスタマイズするために利用可能なオプションの一覧については、[`teler.Options`](https://pkg.go.dev/github.com/teler-sh/teler-waf#Options) 構造体を参照してください。
### 例
以下は、teler-wafのオプションとルールをカスタマイズする方法の例です。```go
// main.go
package main
import (
"net/http"
"github.com/teler-sh/teler-waf"
"github.com/teler-sh/teler-waf/request"
"github.com/teler-sh/teler-waf/threat"
)
var myHandler = http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// This is the handler function for the route that we want to protect
// with teler-waf's security measures.
w.Write([]byte("hello world"))
})
var rejectHandler = http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// This is the handler function for the route that we want to be rejected
// if the teler-waf's security measures are triggered.
http.Error(w, "Sorry, your request has been denied for security reasons.", http.StatusForbidden)
})
func main() {
// Create a new instance of the Teler type using the New function
// and configure it using the Options struct.
telerMiddleware := teler.New(teler.Options{
// Exclude specific threats from being checked by the teler-waf.
Excludes: []threat.Threat{
threat.BadReferrer,
threat.BadCrawler,
},
// Specify whitelisted URIs (path & query parameters), headers,
// or IP addresses that will always be allowed by the teler-waf
// with DSL expressions.
Whitelists: []string{
`request.Headers matches "(curl|Go-http-client|okhttp)/*" && threat == BadCrawler`,
`request.URI startsWith "/wp-login.php"`,
`request.IP in ["127.0.0.1", "::1", "0.0.0.0"]`,
`request.Headers contains "authorization" && request.Method == "POST"`
},
// Specify file path or glob pattern of custom rule files.
CustomsFromRule: "/path/to/custom/rules/**/*.yaml",
// Specify custom rules for the teler-waf to follow.
Customs: []teler.Rule{
{
// Give the rule a name for easy identification.
Name: "Log4j Attack",
// Specify the logical operator to use when evaluating the rule's conditions.
Condition: "or",
// Specify the conditions that must be met for the rule to trigger.
Rules: []teler.Condition{
{
// Specify the HTTP method that the rule applies to.
Method: request.GET,
// Specify the element of the request that the rule applies to
// (e.g. URI, headers, body).
Element: request.URI,
// Specify the pattern to match against the element of the request.
Pattern: `\$\{.*:\/\/.*\/?\w+?\}`,
},
},
},
{
// Give the rule a name for easy identification.
Name: `Headers Contains "curl" String`,
// Specify the conditions that must be met for the rule to trigger.
Rules: []teler.Condition{
{
// Specify the DSL expression that the rule applies to.
DSL: `request.Headers contains "curl"`,
},
},
},
},
// Specify the file path to use for logging.
LogFile: "/tmp/teler.log",
})
// Set the rejectHandler as the handler for the telerMiddleware.
telerMiddleware.SetHandler(rejectHandler)
// Create a new handler using the handler method of the Teler instance
// and pass in the myHandler function for the route we want to protect.
app := telerMiddleware.Handler(myHandler)
// Use the app handler as the handler for the route.
http.ListenAndServe("127.0.0.1:3000", app)
}
For more examples of how to use teler-waf or integrate it with any framework, take a look at examples/ directory.
[!TIP] 設定を探索したり、カスタムルールの作成やDSL式の構成を深く学びたい場合は、このteler WAF playgroundを使用して練習し、実践的な経験を得ることができます。ここでは、アプリケーションの特定のニーズを満たすようにカスタマイズされたリクエストをシミュレートすることもできます。
カスタムルールをteler-wafミドルウェアに統合するには、CustomsとCustomsFromFileの2つの選択肢があります。これらのオプションは、独自のセキュリティチェックを作成したり、teler-wafが提供するデフォルトのチェックを上書きする柔軟性を提供します。
Customs オプション上記の例に示すように、Customsオプションを使用してカスタムルールを直接定義できます。