Lewati ke konten

Model Keamanan

Target utama: bot/scanner otomatis, pengintaian (recon), percobaan kredensial, path traversal, percobaan exploit, dan penyalahgunaan request.

Threat Contoh Respons default
Sensitive file probing /.env, /.git/config, /.aws/credentials High/Critical: blok + ban sementara
Credential probing .git-credentials, wp-config.php Critical: blok + ban
RCE probing php://input, auto_prepend_file Critical: blok + ban lebih lama
Path traversal ../, %2e%2e, encode ganda Skor berbasis confidence
Enumeration banyak URI unik/404 singkat Behavior score + challenge/ban
SQLi / XSS / LFI union select, <script, file:// di body/query Pack injection: challenge/ban
Scanner tool sqlmap/nikto/gobuster Sinyal tool UA + behavior
Fake crawler User-Agent: Googlebot dari IP tak terverifikasi Verifikasi IP → challenge
Fake browser bot UA normal tapi pola otomatis Behavior engine + challenge
Abuse login/form burst pada endpoint valid Rate limit per-path + skor

Asumsi penting: bot modern bisa memalsukan User-Agent & header → UA tidak pernah menjadi sinyal tunggal untuk memblokir. Crawler hanya dipercaya setelah IP-nya terverifikasi.

Internet → Cloudflare/Edge WAF → Hosting WAF/ModSecurity → Ganadev Shield → Router → Controller

Ganadev Shield bekerja setelah request masuk runtime PHP. Bukan pengganti CDN/WAF, malware scanner filesystem, antivirus host, network firewall, atau proteksi logic flaw bisnis.

  • Tidak ada eval, unsafe unserialize, atau dynamic code execution.
  • SQL di-parameterisasi via ORM/query builder.
  • Admin default nonaktif + wajib authorization gate.
  • Verifikasi challenge server-side + rate-limit + CSRF.
  • Redirect challenge dibatasi same-origin (anti open-redirect).
  • Secret query di-mask (***) sebelum disimpan di security_events.
  • Rule regex di-guard terhadap ReDoS.
  • Cookie trusted: encrypted, HttpOnly, Secure, SameSite=Lax, terikat UA+prefix IP, tidak bypass rule critical.
  • Body request diperiksa (maks 64KB, multipart/* di-skip) tapi tidak pernah di-log.
  • fail_mode konfigurabel (open/closed).
  • Signature tidak menangkap 0-day: pola baru lolos sampai rule ditambahkan. Gunakan observe + shield:replay
    • corpus untuk validasi sebelum enforce.
  • Verifikasi crawler butuh IP asli: di belakang proxy/LB/CDN tanpa trusted proxies, IP yang terlihat adalah IP proxy → crawler sah bisa gagal verifikasi. Setel trusted proxies; fallback via bots.verification.ip_ranges.
  • Injection pack bisa FP pada teks bebas: aplikasi dengan editor kode/forum sebaiknya matikan rules.packs.injection / inspection.body.enabled, atau biarkan rule di band challenge (user sah masih lolos).
  • Ban cache bisa tertunda: ban yang kedaluwarsa alami masih terlihat di cache ≤ TTL (default 30s).
  • Unique-URI burst diperkirakan dari jumlah request per window (bukan dedup set URI).
  • Trusted proxy wajib dikonfigurasi di produksi (lihat Instalasi).
  • Rule baru diuji lewat replay corpus sebelum dipromosikan.
  • Sinyal lemah tidak langsung ban; eskalasi butuh pelanggaran nyata.
  • Mode observe untuk rule baru; threshold bisa dinaikkan.
  • Allowlist host/path/IP tersedia; bypass rule critical harus eksplisit.
  • Manual release & challenge pass rate menjadi sinyal FP.

Powered by PT Ganadev Multi Solusi