
teler-waf는 OWASP Top 10 위협, 알려진 취약점, 악의적인 공격자, 봇넷, 원치 않는 크롤러 및 무차별 대입 공격으로부터 로컬 웹 서비스를 보호하는 Go HTTP 미들웨어입니다.
teler-waf는 Go 기반 웹 애플리케이션을 위한 종합적인 보안 솔루션입니다. 이는 HTTP 미들웨어 역할을 하며, 기존 Go 애플리케이션에 teler IDS의 침입 탐지 기능을 통합할 수 있는 간편한 인터페이스를 제공합니다. teler-waf를 사용하면 사이트 간 스크립팅(XSS) 및 SQL 인젝션과 같은 다양한 웹 기반 공격으로부터 보호할 수 있습니다.
이 패키지는 표준 net/http.Handler와 함께 제공되므로 애플리케이션의 라우팅에 쉽게 통합할 수 있습니다. 클라이언트가 teler-waf로 보호되는 경로에 요청을 보내면, 먼저 teler IDS를 통해 알려진 악성 패턴이 있는지 요청을 검사합니다. 악성 패턴이 감지되지 않으면 요청은 추가 처리를 위해 전달됩니다.
웹 기반 공격에 대한 보호 기능 외에도 teler-waf는 애플리케이션의 전반적인 보안과 무결성을 향상시키는 데 도움이 됩니다. 고도로 구성 가능하여 애플리케이션의 특정 요구 사항에 맞게 조정할 수 있습니다.
참고:
teler-waf는 Go 웹 애플리케이션의 보안을 강화하기 위해 설계된 다양한 강력한 기능을 제공합니다:
전반적으로 teler-waf는 Go 기반 웹 애플리케이션을 위한 종합적인 보안 솔루션을 제공하여 웹 기반 공격으로부터 보호하고 애플리케이션의 전반적인 보안과 무결성을 향상시키는 데 도움이 됩니다.
의존성:
Go 애플리케이션에 teler-waf를 설치하려면 다음 명령을 실행하여 teler-waf 패키지를 다운로드하고 설치합니다:```console go get github.com/teler-sh/teler-waf
## Usage
> [!WARNING]
> **지원 중단 알림**: 위협 제외 항목(`Excludes`)은 다음 릴리스(**v2**)에서 지원이 중단됩니다. 자세한 내용은 [#73](https://github.com/teler-sh/teler-waf/discussions/73) 및 [#64](https://github.com/teler-sh/teler-waf/issues/64)를 참조하세요.
다음은 Go 애플리케이션에서 teler-waf를 사용하는 예제입니다:
1. Go 코드에서 teler-waf 패키지를 가져옵니다:```go
import "github.com/teler-sh/teler-waf"
New 함수를 사용하여 Teler 타입의 새 인스턴스를 생성합니다. 이 함수는 애플리케이션의 특정 요구에 맞게 teler-waf를 구성하는 데 사용할 수 있는 다양한 선택적 매개변수를 받습니다.```go
waf := teler.New()3. `Teler` 인스턴스의 `Handler` 메서드를 사용하여 `net/http.Handler`를 생성합니다. 이 핸들러는 애플리케이션의 HTTP 라우팅에서 사용되어 특정 경로에 teler-waf의 보안 조치를 적용할 수 있습니다.```go
handler := waf.Handler(http.HandlerFunc(yourHandlerFunc))
handler를 사용하여 특정 라우트에 teler-waf의 보안 조치를 적용하십시오.```go
http.Handle("/path", handler)됐습니다! teler-waf를 Go 애플리케이션에 구성했습니다.
**옵션:**
teler-waf에서 사용자 정의할 수 있는 옵션 목록은 [`teler.Options`](https://pkg.go.dev/github.com/teler-sh/teler-waf#Options) 구조체를 참조하세요.
### 예제
다음은 teler-waf의 옵션과 규칙을 사용자 정의하는 예제입니다.```go
// main.go
package main
import (
"net/http"
"github.com/teler-sh/teler-waf"
"github.com/teler-sh/teler-waf/request"
"github.com/teler-sh/teler-waf/threat"
)
var myHandler = http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// This is the handler function for the route that we want to protect
// with teler-waf's security measures.
w.Write([]byte("hello world"))
})
var rejectHandler = http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// This is the handler function for the route that we want to be rejected
// if the teler-waf's security measures are triggered.
http.Error(w, "Sorry, your request has been denied for security reasons.", http.StatusForbidden)
})
func main() {
// Create a new instance of the Teler type using the New function
// and configure it using the Options struct.
telerMiddleware := teler.New(teler.Options{
// Exclude specific threats from being checked by the teler-waf.
Excludes: []threat.Threat{
threat.BadReferrer,
threat.BadCrawler,
},
// Specify whitelisted URIs (path & query parameters), headers,
// or IP addresses that will always be allowed by the teler-waf
// with DSL expressions.
Whitelists: []string{
`request.Headers matches "(curl|Go-http-client|okhttp)/*" && threat == BadCrawler`,
`request.URI startsWith "/wp-login.php"`,
`request.IP in ["127.0.0.1", "::1", "0.0.0.0"]`,
`request.Headers contains "authorization" && request.Method == "POST"`
},
// Specify file path or glob pattern of custom rule files.
CustomsFromRule: "/path/to/custom/rules/**/*.yaml",
// Specify custom rules for the teler-waf to follow.
Customs: []teler.Rule{
{
// Give the rule a name for easy identification.
Name: "Log4j Attack",
// Specify the logical operator to use when evaluating the rule's conditions.
Condition: "or",
// Specify the conditions that must be met for the rule to trigger.
Rules: []teler.Condition{
{
// Specify the HTTP method that the rule applies to.
Method: request.GET,
// Specify the element of the request that the rule applies to
// (e.g. URI, headers, body).
Element: request.URI,
// Specify the pattern to match against the element of the request.
Pattern: `\$\{.*:\/\/.*\/?\w+?\}`,
},
},
},
{
// Give the rule a name for easy identification.
Name: `Headers Contains "curl" String`,
// Specify the conditions that must be met for the rule to trigger.
Rules: []teler.Condition{
{
// Specify the DSL expression that the rule applies to.
DSL: `request.Headers contains "curl"`,
},
},
},
},
// Specify the file path to use for logging.
LogFile: "/tmp/teler.log",
})
// Set the rejectHandler as the handler for the telerMiddleware.
telerMiddleware.SetHandler(rejectHandler)
// Create a new handler using the handler method of the Teler instance
// and pass in the myHandler function for the route we want to protect.
app := telerMiddleware.Handler(myHandler)
// Use the app handler as the handler for the route.
http.ListenAndServe("127.0.0.1:3000", app)
}
For more examples of how to use teler-waf or integrate it with any framework, take a look at examples/ directory.
[!TIP] 설정을 탐구하고, 맞춤형 규칙을 제작하며 DSL 표현식을 구성하는 방법을 연습하고 실전 경험을 쌓고 싶다면, 이 teler WAF playground를 사용해 보세요. 여기서 애플리케이션의 특정 요구 사항을 충족하도록 맞춤화된 요청을 시뮬레이션할 수도 있습니다.
teler-waf 미들웨어에 사용자 정의 규칙을 통합하려면 Customs와 CustomsFromFile 두 가지 선택지가 있습니다. 이 옵션들은 자체 보안 검사를 생성하거나 teler-waf에서 제공하는 기본 검사를 재정의할 수 있는 유연성을 제공합니다.
Customs 옵션Customs 옵션을 사용하여 직접 사용자 정의 규칙을 정의할 수 있습니다. 위의 예제에서 확인할 수 있습니다.