Key Concepts:
- GraphQL Inspection
- F5 Distributed Cloud WAAP (Web App and API Protection)
- BIG-IP Advanced WAF (Web Application Firewall)
- Batch Query Attacks
- Deep Recursion Query Attacks
- Introspection (GraphQL)
- Security Analytics
- Content Profile
- Allowed HTTP URLs
- Information Leakage
- Parser Attack
- SQL Injection
- Cross-Site Scripting (XSS)
GraphQL Inspection on F5 Distributed Cloud WAAP
- Configuration Access: Access the load balancer configuration by clicking the three dots next to the load balancer and selecting "Manage Configuration," then "Edit Configuration."
- WAAP Navigation: Navigate to the "Web Application Firewall" section in the menu.
- GraphQL Inspection Policy Creation: Click "GraphQL Inspection" and then "Configure" to create a new policy.
- Rule Definition: Click "Add Item" to define a new rule with the following options:
- Domain: Specify the domain to enable inspection (default is used in the example).
- Path: Specify the endpoint path (default is
/graphql). - HTTP Method: Set to "POST."
- Settings Configuration: Configure the following settings:
- Maximum Length for Query: Set to 5,000 bytes (default).
- Maximum Query Structure Depth: Set to 5.
- Maximum Number of Batched Queries: Set to 5.
- Introspection: Disabled to block introspection queries, preventing unauthorized access to the API schema.
- Saving Changes: Save the changes to apply the GraphQL inspection policy.
GraphQL Inspection on BIG-IP Advanced WAF
- Security Policy Creation: Navigate to "Security" -> "Application Security" -> "Security Policies" and click the "+" button to create a new policy.
- Policy Template Selection: Select "GraphQL Policy" from the policy template dropdown.
- Virtual Server Selection: Select the virtual server (VIP) to protect using the dropdown.
- Content Profile Creation: Navigate to "Security" -> "Application Security" -> "Content Profiles" -> "GraphQL Profile" and click the "+" button to create a new profile.
- Profile Configuration: Configure the following settings:
- Maximum Total Length: Set to 5,000.
- Maximum Value Length: Set to 5,000.
- Maximum Structure Depth: Set to 5.
- Maximum Batched Queries: Set to 5.
- Allow Introspection: Disabled.
- Maximum Query Cost: Allows uploading a specification file for fine-tuning.
- Signatures: Fine-tune signatures, mask sensitive values, and block error responses.
- Allowed URL Configuration: Navigate to "Security" -> "Application Security" -> "URLs" -> "Allowed HTTP URLs" and click the "+" button.
- Advanced View: Switch to the advanced view.
- URL Specification: Specify the URL and enable the "GraphQL Endpoint" option.
- Header-Based Content Profile Selection: Select the created content profile under "Header-Based Content Profiles."
- Policy Application: Apply all changes to the policy by clicking the "Apply Policy" button.
Security Analytics and Logging
- Distributed Cloud Security Analytics:
- Blocked Introspection Query: Classified as an "Information Leakage" attack.
- Deep Recursion Attack: Identified as a "Parser Attack" exceeding the maximum depth of 5.
- Batch Query Attack: Detected as exceeding the limit of 5 batched queries (6 were sent).
- WAF-Caught Attacks: Includes SQL injection and cross-site scripting (XSS) attacks with relevant data such as signature ID, attack type, context, and matching information.
- BIG-IP Advanced WAF Security Events Logs:
- GraphQL Content Profile Attacks:
- Introspection query violation flagged as an "Information Leakage" attack.
- GraphQL parser attack exceeding the maximum structure depth of 5.
- Signature-Caught Attacks: SQL injection and cross-site scripting (XSS) attacks.
- GraphQL Content Profile Attacks:
Notable Quotes/Statements:
- "Introspection is a feature of graphql that allows clients to query the schema of the api at runtime if not properly protected unauthorized users or malicious actors could abuse this feature to gain insights into the api's internals potentially exposing security vulnerabilities or sensitive data."
Technical Terms and Concepts:
- GraphQL Inspection: The process of analyzing GraphQL queries to identify and prevent malicious attacks.
- Batch Query Attacks: Attacks that involve sending multiple GraphQL queries in a single request to overwhelm the server.
- Deep Recursion Query Attacks: Attacks that involve creating deeply nested GraphQL queries to exhaust server resources.
- Introspection (GraphQL): A feature that allows clients to query the schema of a GraphQL API.
- Content Profile: A configuration object in BIG-IP Advanced WAF that defines the security settings for a specific type of content, such as GraphQL.
- Allowed HTTP URLs: A list of URLs that are allowed to be accessed by the application.
- Information Leakage: A type of attack that involves exposing sensitive information about the application or its data.
- Parser Attack: A type of attack that exploits vulnerabilities in the GraphQL parser.
- SQL Injection: A type of attack that involves injecting malicious SQL code into a database query.
- Cross-Site Scripting (XSS): A type of attack that involves injecting malicious JavaScript code into a website.
Logical Connections:
The video demonstrates how to configure GraphQL inspection on both the F5 Distributed Cloud WAAP and BIG-IP Advanced WAF platforms. It then shows how these configurations protect against common GraphQL attacks, such as batch query attacks, deep recursion attacks, and introspection attacks. Finally, it shows how to view the logs to see the attacks that have been prevented.
Synthesis/Conclusion:
The video provides a practical guide to implementing GraphQL security using F5's Distributed Cloud WAAP and BIG-IP Advanced WAF. By configuring GraphQL inspection and setting appropriate limits on query complexity and introspection, organizations can effectively protect their GraphQL APIs from various attacks. The demonstration of attack detection and logging further highlights the importance of these security measures in maintaining a robust security posture. The increasing adoption of GraphQL necessitates these security investments to safeguard users and applications.
AI summaries can miss context or contain errors. Check important details against the original video.