Auto Apply WAF Attack Signature menggunakan Bash Script
Untuk memastikan bahwa semua policy pada WAF telah melakukan Enforcement Attack Signature terbaru, script berikut dapat digunakan.
!!! warn “Catatan”
Script ini akan menggunakan CPU yang cukup tinggi. Direkomendasikan untuk menjalankan command ini pada periode low-traffic. Walau tidak ada risiko downtime, risiko false positive masih cukup tinggi. Pastikan untuk reminder kepada user untuk melakukan pengetesan aplikasi setelah menjalankan command ini.
Command
cat > /shared/tmp/enforce-attack-signature <<'EOF'
#!/bin/bash
#
# Bulk-enforce staged attack signatures on ALL F5 ASM/AWAF policies.
# One PATCH per policy (collection-level with $filter) - no per-signature loop.
#
# Usage:
# ./enforce-attack-signature ready # enforce only "Ready To Be Enforced" signatures (recommended)
# ./enforce-attack-signature all # enforce EVERY staged signature (ignores readiness - risky)
#
# Requirements: curl, jq
#HOST="https://10.15.35.235" # or https://localhost if run on the BIG-IP itself
read -rp "BIG IP Host \[https://localhost\]: " HOST
MODE="${1:-ready}"
# Prompt for credentials (password hidden, not echoed to screen)
read -rp "BIG-IP username \[admin\]: " USER
USER="${USER:-admin}"
read -rsp "BIG-IP password: " PASS
echo
\[\[ -z "$PASS" \]\] && { echo "Password cannot be empty."; exit 1; }
if \[\[ "$MODE" == "ready" \]\]; then
FILTER='hasSuggestions+eq+false+AND+wasUpdatedWithinEnforcementReadinessPeriod+eq+false+AND+performStaging+eq+true'
printf 'Enforcing ready to be enforced signatures.\\n'
printf '\\033\[33m-== Information ==-\\n'
printf 'This mode is only enforcing "Ready to be Enforced" signatures.\\n'
printf 'To enforce ALL signatures, run this script with parameter "all"\\n'
printf '(e.g: ./enforce-attack-signature all).\\033\[0m\\n\\n'
elif \[\[ "$MODE" == "all" \]\]; then
FILTER='performStaging+eq+true'
printf 'Enforcing ALL staged signatures.\\n'
printf '\\033\[1;31m-== Warning! ==-\\n'
printf 'High potential for false positives!\\n'
printf 'Do a comprehensive test of all applications to prevent unexpected blockings.\\033\[0m\\n\\n'
else
echo "Usage: $0 \[ready|all\]"
exit 1
fi
AUTH=(-sk -u "${USER}:${PASS}")
# All ASM policy hashes + names
POLICIES=$(curl "${AUTH\[@\]}" "$HOST/mgmt/tm/asm/policies?\\$select=id,fullPath" \\
| jq -r '.items\[\] | "\\(.id) \\(.fullPath)"')
\[\[ -z "$POLICIES" \]\] && { echo "No policies found (or auth failed)."; exit 1; }
# Gives a progress using current WAF policy / number of policies.
TOTAL=$(echo "$POLICIES" | wc -l)
CURRENT=0
while read -r ID NAME; do
((CURRENT++))
PERCENT=$((CURRENT \* 100 / TOTAL))
echo "=== $NAME ==="
printf '\\033\[36mProgress %d/%d (%d%%)\\033\[0m\\n' "$CURRENT" "$TOTAL" "$PERCENT"
# Single bulk PATCH: enforce all matching signatures in this policy
RESULT=$(curl "${AUTH\[@\]}" -X PATCH -H "Content-Type: application/json" \\
-d '{"performStaging":false}' \\
"$HOST/mgmt/tm/asm/policies/$ID/signatures?\\$filter=$FILTER")
COUNT=$(echo "$RESULT" | jq -r '.totalItems // 0')
echo " Enforced: $COUNT signatures"
if ((COUNT == 0)); then
printf '\\033\[32m Nothing to apply. Skipping... \\033\[0m\\n'
continue
fi
# Apply the policy so the change takes effect
curl "${AUTH\[@\]}" -X POST -H "Content-Type: application/json" \\
-d "{\\"policyReference\\":{\\"link\\":\\"https://localhost/mgmt/tm/asm/policies/$ID\\"}}" \\
"$HOST/mgmt/tm/asm/tasks/apply-policy" -o /dev/null
printf '\\033\[32m Policy apply task submitted.\\033\[0m\\n'
echo " 5 second buffering..."
sleep 5 # avoid hammering the apply-policy queue on boxes with many policies
done <<< "$POLICIES"
EOF
chmod +x /shared/tmp/enforce-attack-signature
Untuk menjalankan script tersebut:
- [ready | all] Menentukan opsi enforcement.
-
ready (default): Hanya enforce policy yang sudah dapat di enforce (Ready to be Enforced signature). Direkomendasikan untuk meminimalisir false positive, tetapi tidak seluruh policy akan di enforce.
-
all: Enforce seluruh attack signature. Memastikan bahwa tidak ada attack signature yang staging lagi, tetapi ada kemungkinan false positive.
Pastikan untuk terus memonitor penggunaan CPU, karena apply policy ASM menggunakan CPU yang tinggi.