Find the top sources of WAF threats
List the countries, attack families, and IP addresses that send the most WAF threats to your applications, in Azion Console or with the GraphQL API.
You can find the countries, attack families, and IP addresses that send the most WAF threats in Azion Console or with the GraphQL API. For what each chart on the WAF dashboards measures, refer to Secure dashboards. For the log of each request WAF flagged, refer to Real-Time Events.
Real-Time Metrics reads these numbers from two datasets. The httpMetrics dataset groups the threats by country and by attack family. The httpBreakdownMetrics dataset groups them by the IP address that sent them. Every example on this page covers the last 7 days.
Select your interface once. The prerequisites and each task below show only that path.
Prerequisites
- An Azion account. To create one, refer to Create an account.
- An application served by a workload, with requests in the last 7 days.
- A firewall that runs a WAF rule set on the requests to your application, in Blocking or Logging mode. To set one up, refer to Create and apply a WAF rule set.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Find the countries
Real-Time Metrics counts the threats by the country each request came from. The WAF dashboard and the httpMetrics dataset both carry this count.
To find the countries with the GraphQL API, send a POST request to https://api.azion.com/v4/metrics/graphql. The query groups the httpMetrics dataset by geolocCountryName and selects three WAF counts for each country.
Replace [TOKEN VALUE] with your personal token, and the begin and end values with the 7 days you want to read:
The API answers 200 with one row per country, at most 10:
Each row holds three counts for one country:
wafRequestsBlocked: threats WAF blocked.wafRequestsThreat: threats WAF logged without blocking.wafRequestsAllowed: requests WAF allowed.
The rows run from the highest wafRequestsThreat down. To rank the countries by blocked threats, replace wafRequestsThreat_DESC with wafRequestsBlocked_DESC. A row whose three counts are 0 means WAF reported no request from that country in the range.
For every WAF field of the dataset, refer to Real-Time Metrics GraphQL fields.
Find the attack families
WAF assigns each threat to an attack family, such as SQL injection or cross-site scripting. Real-Time Metrics counts the threats in each family, on the WAF dashboard and in the httpMetrics dataset.
To find the attack families with the GraphQL API, send a POST request to https://api.azion.com/v4/metrics/graphql. The query groups the httpMetrics dataset by wafAttackFamily.
Replace [TOKEN VALUE] with your personal token, and the begin and end values with the 7 days you want to read:
The API answers 200 with one row per attack family, at most 10:
Each row counts, for one family, the threats WAF logged without blocking in wafRequestsThreat and the threats it blocked in wafRequestsBlocked. When WAF identifies no threat in the range, the response holds one row, "wafAttackFamily": "-", with 0 in both counts.
Find the IP addresses
The IP address of a threat is the remote address that sent the request. Only the Threats Breakdown dashboard and the httpBreakdownMetrics dataset carry it.
To find the IP addresses with the GraphQL API, send a POST request to https://api.azion.com/v4/metrics/graphql. The query sums wafThreatRequests from the httpBreakdownMetrics dataset, grouped by remoteAddress. The wafThreatRequestsGt: 0 filter keeps only the addresses that sent threats.
Replace [TOKEN VALUE] with your personal token, and the begin and end values with the 7 days you want to read:
The API answers 200 with one row per address, at most 10:
Each row holds one address in remoteAddress and its threat requests in sum, from the highest down. An empty array means that no address sent a request WAF identified as a threat in the range. Keep the wafThreatRequestsGt: 0 filter: without it, the query also returns the busiest addresses with a sum of 0.
For every field of the dataset, refer to Real-Time Metrics GraphQL fields.
To act on the sources you found, block the addresses or countries with a network list, or adjust the WAF rule set against the top attack families.