Skip to content

Auto Apply WAF Attack Signature menggunakan Bash Script

Untuk memastikan bahwa semua policy pada WAF telah melakukan Enforcement Attack Signature terbaru, script berikut dapat digunakan.

!!! warn “Catatan”

Script ini akan menggunakan CPU yang cukup tinggi. Direkomendasikan untuk menjalankan command ini pada periode low-traffic. Walau tidak ada risiko downtime, risiko false positive masih cukup tinggi. Pastikan untuk reminder kepada user untuk melakukan pengetesan aplikasi setelah menjalankan command ini.

Command

cat > /shared/tmp/enforce-attack-signature <<'EOF'  
#!/bin/bash  
#  
# Bulk-enforce staged attack signatures on ALL F5 ASM/AWAF policies.  
# One PATCH per policy (collection-level with $filter) - no per-signature loop.  
#  
# Usage:  
#   ./enforce-attack-signature ready    # enforce only "Ready To Be Enforced" signatures (recommended)  
#   ./enforce-attack-signature all      # enforce EVERY staged signature (ignores readiness - risky)  
#  
# Requirements: curl, jq  

#HOST="https://10.15.35.235"    # or https://localhost if run on the BIG-IP itself  
read -rp "BIG IP Host \[https://localhost\]: " HOST  
MODE="${1:-ready}"  

# Prompt for credentials (password hidden, not echoed to screen)  
read -rp "BIG-IP username \[admin\]: " USER  
USER="${USER:-admin}"  
read -rsp "BIG-IP password: " PASS  
echo  
\[\[ -z "$PASS" \]\] && { echo "Password cannot be empty."; exit 1; }  

if \[\[ "$MODE" == "ready" \]\]; then  
  FILTER='hasSuggestions+eq+false+AND+wasUpdatedWithinEnforcementReadinessPeriod+eq+false+AND+performStaging+eq+true'  
  printf 'Enforcing ready to be enforced signatures.\\n'  
  printf '\\033\[33m-== Information ==-\\n'  
  printf 'This mode is only enforcing "Ready to be Enforced" signatures.\\n'  
  printf 'To enforce ALL signatures, run this script with parameter "all"\\n'  
  printf '(e.g: ./enforce-attack-signature all).\\033\[0m\\n\\n'  
elif \[\[ "$MODE" == "all" \]\]; then  
  FILTER='performStaging+eq+true'  
  printf 'Enforcing ALL staged signatures.\\n'  
  printf '\\033\[1;31m-== Warning! ==-\\n'  
  printf 'High potential for false positives!\\n'  
  printf 'Do a comprehensive test of all applications to prevent unexpected blockings.\\033\[0m\\n\\n'  
else  
  echo "Usage: $0 \[ready|all\]"  
  exit 1  
fi  

AUTH=(-sk -u "${USER}:${PASS}")  

# All ASM policy hashes + names  
POLICIES=$(curl "${AUTH\[@\]}" "$HOST/mgmt/tm/asm/policies?\\$select=id,fullPath" \\  
  | jq -r '.items\[\] | "\\(.id) \\(.fullPath)"')  

\[\[ -z "$POLICIES" \]\] && { echo "No policies found (or auth failed)."; exit 1; }  

# Gives a progress using current WAF policy / number of policies.  
TOTAL=$(echo "$POLICIES" | wc -l)  
CURRENT=0  

while read -r ID NAME; do  
  ((CURRENT++))  
  PERCENT=$((CURRENT \* 100 / TOTAL))  

  echo "=== $NAME ==="  
  printf '\\033\[36mProgress %d/%d (%d%%)\\033\[0m\\n' "$CURRENT" "$TOTAL" "$PERCENT"  

  # Single bulk PATCH: enforce all matching signatures in this policy  
  RESULT=$(curl "${AUTH\[@\]}" -X PATCH -H "Content-Type: application/json" \\  
    -d '{"performStaging":false}' \\  
    "$HOST/mgmt/tm/asm/policies/$ID/signatures?\\$filter=$FILTER")  

  COUNT=$(echo "$RESULT" | jq -r '.totalItems // 0')  
  echo "  Enforced: $COUNT signatures"  

  if ((COUNT == 0)); then  
    printf '\\033\[32m   Nothing to apply. Skipping... \\033\[0m\\n'  
    continue  
  fi  

  # Apply the policy so the change takes effect  
  curl "${AUTH\[@\]}" -X POST -H "Content-Type: application/json" \\  
    -d "{\\"policyReference\\":{\\"link\\":\\"https://localhost/mgmt/tm/asm/policies/$ID\\"}}" \\  
    "$HOST/mgmt/tm/asm/tasks/apply-policy" -o /dev/null  

  printf '\\033\[32m  Policy apply task submitted.\\033\[0m\\n'  

  echo "  5 second buffering..."  
  sleep 5   # avoid hammering the apply-policy queue on boxes with many policies  
done <<< "$POLICIES"  
EOF  

chmod +x /shared/tmp/enforce-attack-signature

Untuk menjalankan script tersebut:

/shared/tmp/enforce-attack-signature ready # (1)!
  1. [ready | all] Menentukan opsi enforcement.
  2. ready (default): Hanya enforce policy yang sudah dapat di enforce (Ready to be Enforced signature). Direkomendasikan untuk meminimalisir false positive, tetapi tidak seluruh policy akan di enforce.

  3. all: Enforce seluruh attack signature. Memastikan bahwa tidak ada attack signature yang staging lagi, tetapi ada kemungkinan false positive.

Pastikan untuk terus memonitor penggunaan CPU, karena apply policy ASM menggunakan CPU yang tinggi.