Install the Request Variation Controller integration
Install the Request Variation Controller from Azion Marketplace and run it on an application to count how often a user changes request arguments.
Request Variation Controller counts how many different requests a user makes in succession to an application, and flags the user who exceeds the maximum you allow. It is two integrations that run on the same application, and both are among the Marketplace integrations. In the response phase, the Hash Generator creates or updates a signed cookie that tracks the arguments the user, or the origin, sends across requests. In the request phase, the Hash Validator reads that cookie, checks the number of variations, and marks the request when the user exceeds the maximum.
Seven objects must exist before a request is checked: the two installed functions, an application with the Functions and Application Accelerator modules turned on, one function instance per integration, and one Rules Engine rule per instance.
Prerequisites
- An Azion account. To sign in, refer to How to access Azion Console.
- An application served by a workload. To create one, refer to Applications quickstart.
- Turning on a product or a module can generate usage costs. For more information, refer to Pricing.
Install the integrations
Each install adds one function to your account. To install both from Azion Console:
Access Azion Console > Marketplace.
Enter variation in the Search on Marketplace field, then select the Request Variation Controller - Hash Generator card. Browsing the cards reaches the same page.
Return to Marketplace, select the Request Variation Controller - Hash Validator card, then select Install.
Each card shows Successfully installed! and Latest version installed!, and both functions appear in the Function list of the Create Instance drawer.
Turn on the Functions module
An application runs an installed function only when its Functions module is on. The rule that runs the Hash Validator also uses the Forward Cookies behavior, which requires the Application Accelerator module. To turn on both modules:
Access Azion Console > Applications > your application.
In the Main Settings tab, go to the Modules section.
Azion Console confirms that the application was updated.
Create the function instances
Each integration needs its own function instance with its own arguments. The Hash Generator runs in the response phase and the Hash Validator in the request phase. To create the two instances in your application:
In Applications, select your application, then select the Functions Instances tab.
An application with no instance yet offers the same action as Function Instance. The Create Instance drawer opens.
In Name, enter a unique name that identifies the instance. For example: variation-generator.
In Function, select the Variation Request - Hash Generator function. The Arguments editor fills with the default arguments of the integration.
In Arguments, enter the Hash Generator arguments described below.
Repeat these steps with a name such as variation-validator, the Variation Request - Hash Validator function, and the Hash Validator arguments.
Both instances appear in the Functions Instances tab with the names you entered.
Hash Generator arguments
The Hash Generator runs in the response phase and takes these arguments:
| Key | Description |
|---|---|
cookie_name | The name of the cookie. The default value is azn |
cookie_secret | The key that encrypts the signed cookie. The encryption algorithm is AES-128, so the key must have exactly 16 characters |
cookie_max_age | The time until the cookie expires. Without a value, null or none, the cookie is a session cookie. The default value is 45 |
args_list | The nginx variables analyzed on the user’s request. Each change increases the count of changes, and the count decides whether access is blocked or allowed |
Hash Validator arguments
The Hash Validator runs in the request phase and takes these arguments:
| Key | Description |
|---|---|
cookie_name | The name of the cookie. It must be the same as in the Hash Generator arguments |
cookie_secret | The secret key of the cookie. It must be the same as in the Hash Generator arguments |
max_variation | The maximum number of variations of any kind in the parameters |
max_unique_variation | The maximum number of unique variations in the parameters |
The Hash Validator decrypts the signed cookie and checks whether a variation limit was reached. If it was, the function appends a request header named [COOKIE_ NAME]-[VIOLATION TYPE]-[TRUE].
Violation types
A violation takes one of three types. The examples use a cookie that changes from no value to A in the first request, A to B in the second, C in the third, B to C in the fourth, B to A in the fifth, and A in the sixth.
- All variations: counts every time the cookie value changed, repeated values included. The example has 5 variations. With the default cookie name, the violation adds the
http_cookie_name_any_variation_violationheader to the request. - Unique variations: counts the distinct values assigned to the cookie since it was created. The example has 3, because the cookie held only
A,B, andC. With the default cookie name, the violation adds thehttp_cookie_name_unique_variation_violationheader to the request. - Signature violation: occurs when the function cannot decrypt the signed cookie, because it was signed with a different key or altered on the client side. With the default cookie name, the violation adds the
http_cookie_name_signature_violationheader to the request.
Create the rules
Each instance runs only when a Rules Engine rule calls it. The Hash Generator rule runs in the response phase. The Hash Validator rule runs in the request phase and adds the Forward Cookies behavior, which requires the Application Accelerator module. Both rules below match every request. To create the rules:
In Applications, select your application, then select the Rules Engine tab.
In Name, enter a name for the rule. For example: Track request variations. A Description is optional.
In the Phase section, select Response Phase.
In the Criteria section, keep the ${uri} variable and the starts with operator, then enter / as the argument.
In the Behaviors section, select Run Function, then select the Hash Generator instance by its name.
Select + Rule again. Enter a name, select Request Phase, and set the same criterion.
In the Behaviors section, select Run Function, then select the Hash Validator instance by its name.
Select Add Behavior, then select Forward Cookies.
The Rules Engine tab lists one rule under the response phase and one under the request phase. A request that exceeds a variation limit reaches your application with the violation header.
For every criterion and behavior a rule accepts, refer to Rules Engine.