Code Monkey home page Code Monkey logo

Comments (8)

jssolo avatar jssolo commented on June 16, 2024 1

支持,这个需求蛮需要的,因为有的请求并不是攻击请求,有的时候需要看请求url是否存在问题

from safeline.

5566dst avatar 5566dst commented on June 16, 2024 1

支持增加访问日志

from safeline.

Lorna0 avatar Lorna0 commented on June 16, 2024

访问 IP,不是攻击 IP 么?为啥需要看这个,具体是什么背景和什么问题呢?

from safeline.

Lorna0 avatar Lorna0 commented on June 16, 2024

@jssolo

支持,这个需求蛮需要的,因为有的请求并不是攻击请求,有的时候需要看请求url是否存在问题

这个场景完全不现实呀,网站每天成千上万个受访 url,其中 99%+ 都是完全正常的访问,难道管理员就每天过来从这几万条 url 里一个个翻着看有啥威胁吗。这样的话还不如直接翻服务器日志呢,上 waf 就没用了啊。

from safeline.

jssolo avatar jssolo commented on June 16, 2024

@jssolo

支持,这个需求蛮需要的,因为有的请求并不是攻击请求,有的时候需要看请求url是否存在问题

这个场景完全不现实呀,网站每天成千上万个受访 url,其中 99%+ 都是完全正常的访问,难道管理员就每天过来从这几万条 url 里一个个翻着看有啥威胁吗。这样的话还不如直接翻服务器日志呢,上 waf 就没用了啊。

这个需求主要是适用于流量不大的场景,如果在访问日志里发现恶意请求,可以直接就做相应的处理,比较方便,如果担心访问数据量大,可以设置哪些请求忽略写入日志,或者仅保留几天内或者指定条数

from safeline.

Lorna0 avatar Lorna0 commented on June 16, 2024

@jssolo

这个需求主要是适用于流量不大的场景,如果在访问日志里发现恶意请求,可以直接就做相应的处理,比较方便,如果担心访问数据量大,可以设置哪些请求忽略写入日志,或者仅保留几天内或者指定条数

具体啥流量不大的场景呢。体感来说可能只有 1% 左右的流量是恶意的,哪怕每天只有 100 个请求,就找那 1 个请求也够麻烦的呀。

from safeline.

Lorna0 avatar Lorna0 commented on June 16, 2024

@5566dst

支持增加访问日志

建议集中讨论:

from safeline.

Lorna0 avatar Lorna0 commented on June 16, 2024

时间有点久,没有更多信息,先关闭。有需要可以补充一下更多信息,我们再 reopen。

from safeline.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.