Apply a WAF rule set to a specific cookie
Run two WAF rule sets on one firewall, and score requests carrying a chosen cookie against the rule set that holds an exception.
You can score requests that carry a chosen cookie against a different Web Application Firewall (WAF) rule set, from Azion Console. Use it when authenticated users, or an integrated third-party tool, need a policy the rest of your traffic does not.
The setup holds three objects:
- A primary rule set scores every request the firewall receives.
- A secondary rule set carries an exception for one internal rule on the
Cookieheader. - Two Rules Engine for Firewall rules select between them.
For the scoring model behind them, refer to Scoring and modes.
Prerequisites
- A firewall with the WAF module turned on. Refer to Set a firewall’s main settings.
- A workload bound to that firewall. Refer to Bind a firewall to a workload.
- Access to Azion Console. Refer to How to access Azion Console.
- The name and value of the cookie your application issues.
Create the primary rule set
This rule set scores the traffic that does not carry the cookie. To create it:
Access Azion Console > Edge Libraries > WAF Rules.
In the General section, enter a Name. For example: storefront-primary.
In the Threat Type Configuration section, set the Sensitivity of each threat family.
The rule set appears in WAF Rules. It scores nothing yet: a rule set inspects requests only after a Rules Engine rule names it.
Create the secondary rule set
This rule set scores the traffic that carries the cookie, so give it the same policy as the primary one. To create it:
Still on the WAF Rules page, start a second rule set.
In the General section, enter a Name. For example: storefront-cookie.
In the Threat Type Configuration section, set each Sensitivity to the value you gave the primary rule set.
The two rule sets now carry the same policy. The exception in the next section is what makes them differ.
Add the cookie exception
An exception stops one internal rule from firing in one place, and leaves it firing everywhere else. Azion Console calls an exception an allowed rule. To add one to the secondary rule set:
In WAF Rules, select the rule set you created in the previous section.
In Rule ID, select the internal rule your cookie trips. This example uses 1005, Possible SQL Injection attack: MySQL keyword (|) found in Body, Path, Query String or Cookies.
In Description, state why this rule is allowed.
In Path, enter / to cover the whole site, or a narrower path to limit the exception.
In Condition, select Specific HTTP Header Name, then enter cookie in Name.
Operator defaults to contains, which reads Name as a literal string rather than as a regular expression.
The allowed rule appears in Allowed Rules, which lists its Rule ID, Description, Path, Conditions, and Status.
This exception relaxes one internal rule for the requests the secondary rule set scores. Every other rule in that rule set still scores them.
A cookie is supplied by the client and can be forged. Anyone who learns the cookie name and value sends the same header and reaches the secondary rule set. Hold the exception to one Rule ID and to the narrowest Path your application allows.
Apply the primary rule set to every request
A Rules Engine rule selects requests by its criteria, and its Set WAF behavior names one rule set and one mode. A rule carries at most one Set WAF behavior, which is why this setup takes two rules.
To create the first rule:
In Azion Console, go to Firewalls and select that firewall.
Enter a name for the rule. For example: Apply storefront-primary.
In the Criteria section, select the Request Uri variable, the starts with comparison operator, and / as the argument.
In the Behaviors section, select Set WAF, then select the primary rule set.
The firewall now scores every request it receives against the primary rule set.
Apply the secondary rule set to requests with the cookie
This rule reads the Cookie header and sends the requests that carry your cookie to the secondary rule set.
A firewall processes its Rules Engine rules in the order they are arranged, so arrange this rule after the one you created in the previous section. To create it:
Still on the Rules Engine tab, start a second rule.
Enter a name for the rule. For example: Apply storefront-cookie.
In the Criteria section, select the Header Cookie variable, the matches comparison operator, and partner-access=b7c1f2e4 as the argument.
Replace partner-access=b7c1f2e4 with the cookie your application issues. The matches operator reads the argument as a regular expression.
In the Behaviors section, select Set WAF, then select the secondary rule set.
A request that carries the cookie is scored against the secondary rule set, so the allowed rule does not fire on its Cookie header, and every other rule in that rule set still scores it. A request without the cookie is scored against the primary rule set.