Application overview 编辑

Application overview

The Application Overview page displays applications with full visibility into the threat details associated in both security insight and bot insight. You can also view information such as total violations, total WAF and Bot violations, violation by country, and so on.

Application overview

1 – Displays the total affected applications, total violations, total WAF violations, and total Bot violations for the selected duration.

2 – Displays the WAF and Bot violation details. Click the WAF and Bot tab to view the top 5 custom or discrete applications based on the total violations occurred. Click View All to view all application details.

3 – Displays the top violations based on the occurrences and the actions applied.

4 – Displays a geo map view that provides visibility from which locations the violations have occurred.

5 – Provides information based on the violations.

For more information on bot and security insights, see:

Violation categories

WAFBot
Unusually High Upload TransactionsExcessive Client Connections
Unusually High Download TransactionsAccount Takeover
Excessive Unique IPsUnusually High Upload Volume
Excessive Unique IPs Per GeoUnusually High Request Rate
Cookie HijackUnusually High Download Volume
Infer Content Type XMLWebsite Scanners
Buffer OverflowAccount Takeover for Citrix Gateway
Content TypeAPI Abuse
Cookie ConsistencyContent Scrapers
CSRF Form TaggingKeystroke and mouse dynamics based bot detection
Deny URLScraper
Form Field ConsistencyScreenshot Creator
Field FormatsSearch Engine
Maximum UploadsService Agent
Referrer HeaderSite Monitor
Safe CommerceSpeed Tester
Safe ObjectTool
HTML SQL InjectUncategorized
Start URLVirus Scanner
Cross-site scriptingVulnerability Scanner
XML DoSDeviceFP Wait Exceeded
XML FormatInvalid DeviceFP
XML WSIInvalid Captcha Response
XML SSLCaptcha Attempts Exceeded
XML AttachmentValid Captcha Response
XML SOAP FaultCaptcha Client Muted
XML ValidationCaptcha Wait Time Exceeded
OthersRequest Size Limit Exceeded
IP ReputationRate Limit Exceeded
HTTP DOSBlock list (IP, subnet, policy expression)
TCP Small WindowAllow list (IP, subnet, policy expression)
Signature ViolationZero Pixel Request
File Upload TypeSource IP
JSON cross-site scriptingHost
JSON SQLGeo Location
JSON DOSURL
Command InjectionCrawler
Block KeywordFeed Fetcher
JSON Block KeywordLink Checker
Command Injection GrammarMarketing

View WAF violation details

Click an application from the Top Applications or from the View All option to view the WAF details.

WAF

Note

If you select a custom app, you can view the consolidated applications details in the Security Overview page. From the list, select an application to view details for the selected application.

The Security Overview page for the selected application is displayed. Under WAF, you can view:

  • A graph view that indicates the total violations, threat index score, safety index score for the application.

    WAF graph

    Click View Details to see the Application Firewall and Citrix ADC System Security configuration details.

    View details

  • The violations based on types, severity, and actions applied.

    WAF graph details

    Click Logs to view details based on the severity or action taken. You can also view the client IP address.

    Logs

  • The violations affected on the application. Under Violation Details, you can view the affected violation details.

    Note

    For a custom app, violations that are applicable for all applications are displayed. You can click an application from the list to view the violations affected for the selected application.

    Click each violation to view details such as:

    • What Happened – Indicates the total occurrences and the last occurred date and time.

    • Event Details – Displays a geo map that indicates the client IP and other violation details such as violation type, client IP, location, and so on.

      WAF violation details

View bot violation details

From the Bot tab, click an application from the Top Applications or from the View All option to view the bot details.

Bot details

Note

If you select a custom app, you can view the consolidated applications details in the Security Overview page. From the list, select an application to view details for the selected application.

The Security Overview page for the selected application is displayed. Under Bot, you can view:

  • A graph indicating total bots, total bad bots, total good bots, and total ratio between human users and bots accessing the application.

    Bot graph

  • The violations based on the bot types, severity, and actions applied.

    Bot violation types

    Click Logs to view details based on severity or actions taken. If a detected bot is a Signature type bot, you can view more details such as Bot developer and Signature ID. The Signature ID enables you to identify if the detected bot is a good bot or a bad bot.

    Bot logs

    Note

    If a detected bot is any other bot type apart from Signature bot, the Signature ID and Bot developer are displayed as N/A.

    NA type

  • The violations affected on the application. Under Violation Details, you can view the affected violation details.

    Note

    For a custom app, violations that are applicable for all applications are displayed. You can click an application from the list to view the violations affected for the selected application.

    Click each violation to view details such as:

    • What Happened – Indicates the total occurrences and the last occurred date and time.

    • Event Details – Displays a geo map that indicates the client IP and other violation details such as violation type, client IP, location, and so on.

      Bot violation details

Note

Under WAF and Bot, you can view analytics for content switching virtual server that is bound with load balancing virtual servers. Click the content switching virtual server and under Bound Load Balancing Server, you can view the list of load balancing servers bound to the content switching virtual server.

Content Switching server with Load Balancing server

View events history

Click the Events tab to view the bot and WAF events.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据

词条统计

浏览:99 次

字数:13766

最后编辑:6年前

编辑次数:0 次

    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文