4
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

More than 5 years have passed since last update.

WAFの文字列一致条件を設定するCloudFormation

4
Last updated at Posted at 2019-10-23

概要

WAFの文字列一致条件をCloudFormationで設定する機会があったので
書き方とポイントについてまとめておきます。

CloudFormationにおけるWAFの文字列一致条件については
以下のAWSドキュメントで情報が公開されています。

文字列一致条件に関するAWSのドキュメント

文字列一致条件とは

ウェブリクエストに表示される文字列に基づいて、リクエストを許可または拒否するかどうかを設定するもの。
文字列一致条件が識別するのは、

  • 検索する文字列
  • AWS WAF で文字列を検査する先のウェブリクエスト部分 (指定されたヘッダーやクエリ文字列など)

 例: デフォルトは拒否で、URIが/public/で始まるリクエストは許可したい。

最終的なCloudFormation

最終的には以下の内容になりました。

<このテンプレートで作成できるAWSリソース>

  • WAF
  • WAFRule
  • WAFByteMatchSet(文字列一致条件)
AWSTemplateFormatVersion: 2010-09-09
Description: template for waf checking String and regex matching
Parameters: 
  Prefix:
    Type: 'String'
    Default: 'test'
Resources:
  WAFWebACLTEST:
    Type: 'AWS::WAF::WebACL'
    Properties:
      DefaultAction:
        Type: BLOCK ←WAFのデフォルトアクションを拒否
      MetricName: !Sub {Prefix}waf
      Name: !Sub ${Prefix}-waf
      Rules:
          - Action:
              Type: ALLOW ←WAFRuleStringMatchに当てはまるときは許可
            Priority: 0
            RuleId: !Ref WAFRuleStringMatch

  WAFRuleStringMatch:
    Type: 'AWS::WAF::Rule'
    Properties:
      MetricName: !Sub ${Prefix}stringmatch
      Name: !Sub ${Prefix}-stringmatch
      Predicates:
        - DataId: !Ref WAFByteMatchSetString
          Negated: false
          Type: ByteMatch

  WAFByteMatchSetString:
    Type: 'AWS::WAF::ByteMatchSet'
    Properties:
      ByteMatchTuples:
      # URIが/4/で始まるリクエスト
        - FieldToMatch:
            Type: URI
          PositionalConstraint: STARTS_WITH
          TargetString: /4/
          TextTransformation: LOWERCASE
      # URIが/public/で始まるリクエスト
        - FieldToMatch:
            Type: URI
          PositionalConstraint: STARTS_WITH
          TargetString: /public/
          TextTransformation: NONE
      Name: !Sub ${Prefix}-string

ポイント

  • (文字列一致条件に関するものではないですが)WAFのメトリック名に「-(ハイフン)」は使えない。
  • TextTransformationは攻撃者がWAFをバイパスするためにウェブリクエストで使用する異常なフォーマットの一部を削除する変換方法を指定するもの。必ずなんらかの変換方法を指定する必要があるので、変換しない場合はNONEと指定する。

参考

4
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
4
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?