Cloudflare L7 DDoS


Description

Layer 7 Distributed Denial of Service (DDoS) detected

Query · python

from panther_cloudflare_helpers import cloudflare_fw_alert_context


def rule(event):

    return event.get("Source", "") == "l7ddos"


def title(_):
    return "Cloudflare: Detected L7 DDoS"


def alert_context(event):
    return cloudflare_fw_alert_context(event)


def severity(event):
    if event.get("Action", "") == "block":
        return "Info"
    return "Medium"

Analyst notes

Inspect and monitor internet-facing services for potential outages

Raw source Cloudflare L7 DDoS · Panther Python
Esc
Published by panther-labs/panther-analysis ↗, licensed under Apache 2.0 ↗. Reproduced here unmodified.
AnalysisType: rule
Filename: cloudflare_firewall_ddos.py
RuleID: "Cloudflare.Firewall.L7DDoS"
DisplayName: "Cloudflare L7 DDoS"
Enabled: true
LogTypes:
  - Cloudflare.Firewall
Tags:
  - Cloudflare
  - Variable Severity
Severity: Medium
Description: Layer 7 Distributed Denial of Service (DDoS) detected
Runbook: Inspect and monitor internet-facing services for potential outages
Reference: https://www.cloudflare.com/en-gb/learning/ddos/application-layer-ddos-attack/
DedupPeriodMinutes: 60 # 1 hour
Threshold: 100
SummaryAttributes:
  - Action
  - ClientCountry
  - ClientIP
  - ClientRequestUserAgent
Tests:
  - Name: Traffic Marked as L7DDoS
    ExpectedResult: true
    Log:
      {
        "Action": "skip",
        "ClientASN": 55836,
        "ClientASNDescription": "RELIANCEJIO-IN Reliance Jio Infocomm Limited",
        "ClientCountry": "in",
        "ClientIP": "127.0.0.1",
        "ClientRequestHost": "example.com",
        "ClientRequestMethod": "GET",
        "ClientRequestPath": "/main.php",
        "ClientRequestProtocol": "HTTP/1.1",
        "ClientRequestQuery": "",
        "ClientRequestScheme": "http",
        "ClientRequestUserAgent": "Fuzz Faster U Fool v1.3.1-dev",
        "Datetime": "2022-05-10 06:36:57",
        "EdgeColoCode": "DEL",
        "EdgeResponseStatus": 403,
        "Kind": "firewall",
        "MatchIndex": 0,
        "Metadata": { "dos-source": "dosd-edge" },
        "OriginResponseStatus": 0,
        "OriginatorRayID": "00",
        "RayID": "7090a9da88e333d8",
        "RuleID": "ed651449c4a54f4b99c6e3bf863134d5",
        "Source": "l7ddos",
      }
  - Name: Traffic Marked as L7DDoS but blocked ( INFO level alert )
    ExpectedResult: true
    Log:
      {
        "Action": "block",
        "ClientASN": 55836,
        "ClientASNDescription": "RELIANCEJIO-IN Reliance Jio Infocomm Limited",
        "ClientCountry": "in",
        "ClientIP": "127.0.0.1",
        "ClientRequestHost": "example.com",
        "ClientRequestMethod": "GET",
        "ClientRequestPath": "/main.php",
        "ClientRequestProtocol": "HTTP/1.1",
        "ClientRequestQuery": "",
        "ClientRequestScheme": "http",
        "ClientRequestUserAgent": "Fuzz Faster U Fool v1.3.1-dev",
        "Datetime": "2022-05-10 06:36:57",
        "EdgeColoCode": "DEL",
        "EdgeResponseStatus": 403,
        "Kind": "firewall",
        "MatchIndex": 0,
        "Metadata": { "dos-source": "dosd-edge" },
        "OriginResponseStatus": 0,
        "OriginatorRayID": "00",
        "RayID": "7090a9da88e333d8",
        "RuleID": "ed651449c4a54f4b99c6e3bf863134d5",
        "Source": "l7ddos",
      }
  - Name: Traffic Not Marked as L7DDoS
    ExpectedResult: false
    Log:
      {
        "Action": "block",
        "ClientASN": 55836,
        "ClientASNDescription": "RELIANCEJIO-IN Reliance Jio Infocomm Limited",
        "ClientCountry": "in",
        "ClientIP": "127.0.0.1",
        "ClientRequestHost": "example.com",
        "ClientRequestMethod": "GET",
        "ClientRequestPath": "/main.php",
        "ClientRequestProtocol": "HTTP/1.1",
        "ClientRequestQuery": "",
        "ClientRequestScheme": "http",
        "ClientRequestUserAgent": "Mozilla/5.0 (Windows NT 6.4; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36",
        "Datetime": "2022-05-10 06:36:57",
        "EdgeColoCode": "DEL",
        "EdgeResponseStatus": 403,
        "Kind": "firewall",
        "MatchIndex": 0,
        "Metadata": { "dos-source": "dosd-edge" },
        "OriginResponseStatus": 0,
        "OriginatorRayID": "00",
        "RayID": "708174c00f61faa8",
        "RuleID": "e35c9a670b864a3ba0203ffb1bc977d1",
        "Source": "firewallmanaged",
      }


# ------ paired body: cloudflare_firewall_ddos.py ------

from panther_cloudflare_helpers import cloudflare_fw_alert_context


def rule(event):

    return event.get("Source", "") == "l7ddos"


def title(_):
    return "Cloudflare: Detected L7 DDoS"


def alert_context(event):
    return cloudflare_fw_alert_context(event)


def severity(event):
    if event.get("Action", "") == "block":
        return "Info"
    return "Medium"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.