OWASP CRD を使用して OWASP Top 10 保護ポリシーを構成する

最終公開日 : Oct 02, 2026
OWASP Top 10:2025 は、Webアプリケーションにとって最も重大なセキュリティリスクを表します。OWASP CRD (owasppolicy) を使用すると、単一のKubernetesカスタムリソースで、OWASP Top 10カテゴリに沿った包括的なWAFおよびボット管理保護を構成できます。
OWASP Top 10:2025 のカテゴリは次のとおりです。
  1. A01:2025 - 破損したアクセス制御
  2. A02:2025 - セキュリティの誤設定
  3. A03:2025 - ソフトウェアサプライチェーンの障害
  4. A04:2025 - 暗号化の障害
  5. A05:2025 - インジェクション
  6. A06:2025 - 安全でない設計
  7. A07:2025 - 認証の障害
  8. A08:2025 - ソフトウェアまたはデータの整合性の障害
  9. A09:2025 - セキュリティログとアラートの障害
  10. A10:2025 - 例外条件の不適切な処理
OWASP Top 10 に従って、次のルールが owasppolicy CRD によってサポートされています。CRD は主に2つのセクションで構成されています。
  • ボット保護
  • WAF (ウェブアプリケーションファイアウォール) 保護。
注記:
既存の Bot および Waf CRD を使用したい場合は、Owasppolicy CRD で同じフィールドを有効にしないようにしてください。

OWASP CRD 定義

OWASP CRD の定義は owasp-crd.yaml で入手できます。次のコマンドを実行してデプロイします。
kubectl create -f owasp-crd.yaml
この CRD は apiVersion: citrix.com/v1 および kind: owasppolicy を使用します。

OWASP CRD 構造

トップレベルの仕様には以下が含まれます。
CRD 属性 説明
ingressclass どの Ingress コントローラーがこのリソースを処理するかをスコープする Ingress クラス。
servicenames OWASP ポリシーが適用されるサービスの一覧。
bot ボット管理保護設定。
waf Webアプリケーションファイアウォール保護設定。
NetScalerのトップレベルエンティティマッピング:
CRDセクション NetScalerエンティティ NetScaler属性
bot botprofile すべてのボット保護設定を含むプロファイル
bot botpolicy rule、profilename — LB仮想サーバーにバインドされたポリシー
bot lbvserver_botpolicy_binding policyname, bindpoint=REQUEST
waf appfwprofile すべてのWAF保護設定を含むプロファイル
waf appfwpolicy rule, profilename — LB仮想サーバーにバインドされたポリシー
waf lbvserver_appfwpolicy_binding policyname, bindpoint=REQUEST

ボット保護

許可リストとブロックリスト

トラフィックを許可またはブロックするためのルール式を追加します。
属性 説明
action allow または block
expression トラフィックを照合するためのADCポリシー式。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
action: allow botprofile bot_enable_white_list ON
action: allow, expression botprofile_whitelist_binding bot_whitelist_type, bot_whitelist_value, bot_whitelist_enabled EXPRESSION, HTTP.REQ.URL.PATH.EQ("apache.com"), ON
action: block botprofile bot_enable_black_list ON
action: block, expression botprofile_blacklist_binding bot_blacklist_type, bot_blacklist_value, bot_blacklist_action, bot_blacklist_enabled EXPRESSION, HTTP.REQ.URL.PATH.EQ("nginx.com"), [LOG, DROP], ON

地域ブロック

ISO 3166-1 alpha-2 国コードを使用して、ブロックする国のリストを追加します。
属性 説明
blocked-countries 国コードのリスト(例:CN、RU)。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
blocked-countries policypatset name <profile_name>
blocked-countries[*] policypatset_pattern_binding String, index CN, 1
blocked-countries botprofile_blacklist_binding bot_blacklist_type, bot_blacklist_value, bot_blacklist_action EXPRESSION, CLIENT.IP.SRC.MATCHES_LOCATION("<patset_name>"), [LOG, DROP]

IPレピュテーション

以下のカテゴリから選択します(デフォルト:すべて有効):
  • スパムソース
  • Windowsエクスプロイト
  • Webエクスプロイト
  • ボットネットランサムウェアC&C
  • スキャナー
  • フィッシング
  • 匿名または不審なプロキシ
  • モバイルの脅威
  • Torプロキシ
  • DoS
  • クラウド
  • クラウド (AWS)
  • クラウド (Azure)
  • クラウド (IBM)
  • クラウド (Oracle)
  • クラウド (Salesforce)
  • IP
  • ネットワーク
  • レピュテーション
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
ip-reputation botprofile bot_enable_ip_reputation ON
spam-sources botprofile_ipreputation_binding category, bot_iprep_enabled, bot_iprep_action SPAM_SOURCES, ON, [LOG, DROP]
windows-exploits botprofile_ipreputation_binding category WINDOWS_EXPLOITS
web-exploits botprofile_ipreputation_binding category WEB_ATTACKS
botnets-ransomware-ccs botprofile_ipreputation_binding category BOTNETS
scanners botprofile_ipreputation_binding category SCANNERS
phishing botprofile_ipreputation_binding category PHISHING
anonymous-or-suspicious-proxies botprofile_ipreputation_binding category PROXY
tor-proxies botprofile_ipreputation_binding category TOR_PROXY
dos botprofile_ipreputation_binding category DOS
cloud botprofile_ipreputation_binding category CLOUD
cloud-aws botprofile_ipreputation_binding category CLOUD_AWS
cloud-azure botprofile_ipreputation_binding category CLOUD_AZURE
cloud-ibm botprofile_ipreputation_binding category CLOUD_IBM
cloud-oracle botprofile_ipreputation_binding category CLOUD_ORACLE
cloud-salesforce botprofile_ipreputation_binding category CLOUD_SALESFORCE
ip botprofile_ipreputation_binding category IP
network botprofile_ipreputation_binding category NETWORK
reputation botprofile_ipreputation_binding category REPUTATION

レート制限

URL、セッションクッキー、または送信元IPアドレスごとにレート制限ポリシーを追加します。
属性 説明
url-pattern レート制限するURLパターン。
session-cookie レート制限するセッションクッキー名。
sourceip 送信元IPアドレスでレート制限するには、trueに設定します。
requests-per-second 1秒あたりの最大リクエスト数。
action 実行するアクション: drop、log、reset。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
rate-limit botprofile bot_enable_rate_limit ON
url-pattern botprofile_ratelimit_binding bot_rate_limit_type, bot_rate_limit_url URL, /api/v1/*
session-cookie botprofile_ratelimit_binding bot_rate_limit_type, bot_rate_limit_url SESSION, JSESSIONID
sourceip botprofile_ratelimit_binding bot_rate_limit_type SOURCE_IP
requests-per-second botprofile_ratelimit_binding rate, bot_rate_limit_time_slice 100, 1000
action botprofile_ratelimit_binding bot_rate_limit_action, bot_rate_limit_enabled [LOG, DROP], ON

ボットシグネチャ

シグネチャファイルへのURLを提供することで、ボットシグネチャ検出を有効または無効にします。
属性 説明
bot-signature 外部ボット署名JSONファイルへのURL。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
bot-signature botprofile signature <signature_object_name>

ボットトラップ

自動ボットを検出するための隠しトラップURLとして機能する適用URLを追加します。
属性 説明
enforcement-url トラップとして挿入するURL。
action アクション: block、log、redirect。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
enforcement-url botprofile_trapinsertionurl_binding bot_trap_url、bot_trap_url_insertion_enabled apache.com、ON

ボットTPS

Transactions Per Second (TPS) しきい値を使用して、レートベースのボット検出を適用します。設定されたTPS制限を超えるリクエストは、ボットトラフィックとして扱われます。
属性 説明
action 実行するアクション: drop、reset、none。デフォルト: drop。
enforcement-type TPSベースの適用タイプ: ClientIP、GeoLocation、Host、SourceUrl。デフォルト: ClientIP。
minimum-tps 適用するための最小ボットTPSしきい値。
maximum-tps-percentage 最大TPS増加率 (30分間隔あたり)。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
bot-tps botprofile bot_enable_tps ON
action botprofile_tps_binding bot_tps_action [LOG, DROP]
enforcement-type botprofile_tps_binding bot_tps_type SOURCE_IP
minimum-tps botprofile_tps_binding threshold 4
maximum-tps-percentage botprofile_tps_binding percentage 10000

デバイスフィンガープリント

ブラウザとデバイスの属性を収集することで、ボットと人間を区別するために、デバイスフィンガープリントを有効または無効にします。
属性 説明
action アクション: log、drop、redirect、reset。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
device-fingerprint botprofile devicefingerprint ON
action botprofile devicefingerprintaction [LOG]

WAF保護

SQLインジェクション

SQLインジェクション攻撃 (OWASP A05: インジェクション) から保護し、例外を追加するオプションを提供します。
属性 説明
action アクション: block。
exceptions 例外のリスト。
type 例外コンテンツタイプ: JSON または HTML。
url-pattern 除外するURLパターン。
form-field-name 除外するフォームフィールド名。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
sql-injection appfwprofile SQLInjectionAction [block, log, stats]
exceptions appfwprofile_sqlinjection_binding sqlinjection, formactionurl_sql, isregex_sql .*, .*, REGEX

バッファオーバーフロー

サイズ制限を適用することで、バッファオーバーフロー攻撃から保護します。
属性 説明
action アクション: block。
max-url-length URLの最大長。
max-cookie-length Cookieの最大長。
max-header-length ヘッダーの最大長。
JSON保護:
属性 説明
max-container-depth JSONの最大コンテナ深度。
max-document-length JSONの最大ドキュメント長。
max-object-key-count JSONの最大オブジェクトキー数。
max-object-key-length JSONの最大オブジェクトキー長。
max-array-length JSONの最大配列長。
max-string-length JSONの最大文字列長。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
buffer-overflow appfwprofile bufferOverflowAction [block, log, stats]
max-url-length appfwprofile bufferOverflowMaxURLLength 1024
max-cookie-length appfwprofile bufferOverflowMaxCookieLength 4096
max-header-length appfwprofile bufferOverflowMaxHeaderLength 4096
max-container-depth appfwprofile JSONMaxContainerDepth 1
max-document-length appfwprofile JSONMaxDocumentLength 200000000
max-object-key-count appfwprofile JSONMaxObjectKeyCount 10000
max-object-key-length appfwprofile JSONMaxObjectKeyLength 10000
max-array-length appfwprofile JSONMaxArrayLength 10000
max-string-length appfwprofile JSONMaxStringLength 10000000

Cookieの一貫性

Cookieの一貫性適用を有効または無効にします。
属性 説明
action アクション: block。
exceptions 除外するCookie名のリスト。
cookie-name 例外として追加する新しいCookie名。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
cookie-consistency appfwprofile cookieConsistencyAction [block, log, stats]
exceptions[*].cookie-name appfwprofile_cookieconsistency_binding cookieconsistency session_tracker

クロスサイトスクリプティング

クロスサイトスクリプティング攻撃 (OWASP A05: インジェクション) から保護します。
属性 説明
action アクション: block。
content-type HTML、JSON、またはall。
exceptions 例外のリスト。
type 例外コンテンツタイプ: JSON または HTML。
url-pattern 除外するURLパターン。
form-field-name 除外するフォームフィールド名。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
cross-site-scripting appfwprofile crossSiteScriptingAction [block, log, stats]
exceptions appfwprofile_crosssitescripting_binding crosssitescripting, formactionurl_xss, isregex_xss .*, /admin/editor, REGEX

コマンドインジェクション

OSコマンドインジェクション攻撃 (OWASP A05: Injection) から保護します。
属性 説明
action アクション: block。
content-type HTML、JSON、またはall。
exceptions 例外のリスト。
type 例外コンテンツタイプ: JSON または HTML。
url-pattern 除外するURLパターン。
form-field-name 除外するフォームフィールド名。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
command-injection appfwprofile cmdInjectionAction [block, log, stats]
exceptions appfwprofile_cmdinjection_binding cmdInjection, formactionurl_cmd, isregex_cmd .*, /admin/cmd-tool, REGEX

CSRF

クロスサイトリクエストフォージェリ (OWASP A01: 破損したアクセス制御) から保護します。
属性 説明
action アクション: block。
content-type HTML。
exceptions 除外するURLパターンのリスト。
url-pattern 除外するURLパターン。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
csrf appfwprofile CSRFtagAction [block, log, stats]
exceptions[*].url-pattern appfwprofile_csrftag_binding csrftag, csrfformactionurl .*, apache.com

フィールド形式

入力制約を適用するために、フィールド形式の検証を有効にします。
属性 説明
action アクション: block。
field-name フィールド名。
format フォーマットタイプ: Integer, Alphabets, Alphanumeric, No HTML, Any, SSN, Credit Card, Custom。
customregex フォーマットが Custom の場合のカスタム正規表現。
min-length 最小フィールド長。
max-length 最大フィールド長。
url-pattern 適用するURLパターン範囲。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
field-format appfwprofile fieldFormatAction [block, log, stats]
enforcements[*] appfwprofile_fieldformat_binding fieldformat, formactionurl_ff, fieldtype age, .*, integer
min-length, max-length appfwprofile_fieldformat_binding fieldformatminlength, fieldformatmaxlength 1, 3
customregex appfwfieldtype name, regex, priority <fieldtype_name>, <regex>, 2

フィールドの整合性

フォームフィールドの改ざんから保護します。
属性 説明
action アクション: block.
content-type HTML.
exceptions 例外のリスト。
url-pattern 除外するURLパターン。
field-name 除外するフィールド名。
NetScaler エンティティマッピング:
CRD フィールド NetScaler エンティティ NetScaler 属性 例の値
field-consistency appfwprofile fieldConsistencyAction [block, log, stats]
exceptions[*] appfwprofile_fieldconsistency_binding fieldconsistency, formactionurl_ffc .*, /form/dynamic

WAF シグネチャ

シグネチャベースの検出を有効にするには、WAFシグネチャファイルへのURLを提供します。
属性 説明
waf-signature WAFシグネチャXMLファイルのURL。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler属性 例の値
waf-signature appfwprofile signatures <signature_object_name>

データ漏洩防止

レスポンスでの機密データ漏洩を防ぐために、SAFEオブジェクトを設定します。
既存のSAFEオブジェクトタイプ: SSN、CreditCard
カスタムSAFEオブジェクト:
属性 説明
type SSN、CreditCard、またはCustom。
action アクション: mask、block、log。
max-match-length パターンに対する最大一致長。
regex カスタム正規表現パターン (タイプがCustomの場合)。
NetScalerエンティティマッピング:
CRDフィールド NetScalerエンティティ NetScaler 属性 例の値
type: SSN appfwprofile_safeobject_binding safeobject, as_expression, maxmatchlength, action, state ssn, SSN, 15, [log], ENABLED
type: CreditCard appfwprofile_safeobject_binding safeobject, as_expression, maxmatchlength, action creditcard, CreditCard, 255, [block]
type: Custom appfwprofile_safeobject_binding safeobject, as_expression, maxmatchlength, action custom, \b[A-Z]{2}\d{6}\b, 8, [log]

OWASP CRD をデプロイする

  1. CRD定義をデプロイします。
    kubectl create -f owasp-crd.yaml
  2. OWASPポリシーをデプロイします。
    kubectl apply -f owasp_waf_bot.yaml

完全な例: 組み合わせたWAFおよびボットポリシー

以下は、サポートされているすべての保護を示す完全な例です (owasp_waf_bot.yaml):
apiVersion: citrix.com/v1
kind: owasppolicy
metadata:
  name: test-bm-owasp-policy
  namespace: default
spec:
  bot:
    bot-signature: "http://1.1.1.1/crd/bot_sig.json"
    allow-and-block-list:
      rules:
      - action: allow
        expression: HTTP.REQ.URL.PATH.EQ("apache.com")
      - action: block
        expression: HTTP.REQ.URL.PATH.EQ("nginx.com")
    bot-trap:
      enforcements:
      - action: block
        enforcement-url: apache.com
      - action: log
        enforcement-url: example.com
      - action: redirect
        enforcement-url: redirect.example.com
    bot-tps:
      enforcement-type: ClientIP
      minimum-tps: 4
      maximum-tps-percentage: 10000
      action: drop
    device-fingerprint:
      action: log
    geo-blocking:
      blocked-countries:
      - CN
      - RU
    ip-reputation:
      categories:
        anonymous-or-suspicious-proxies: true
        botnets-ransomware-ccs: true
        mobile-threats: true
        phishing: true
        scanners: true
        spam-sources: true
        tor-proxies: true
        web-exploits: true
        windows-exploits: true
    rate-limit:
      policies:
      - action: drop
        requests-per-second: 100
        url-pattern: /api/v1/*
      - action: drop
        requests-per-second: 5
        url-pattern: /login
      - action: drop
        requests-per-second: 50
        url-pattern: /search
      - action: log
        requests-per-second: 20
        session-cookie: JSESSIONID
      - action: reset
        requests-per-second: 200
        sourceip: true
  ingressclass: cic-vpx
  servicenames:
  - frontend
  waf:
    buffer-overflow:
      action: block
      json-protection:
        max-array-length: 10000
        max-container-depth: 1
        max-document-length: 200000000
        max-object-key-count: 10000
        max-object-key-length: 10000
        max-string-length: 10000000
      max-cookie-length: 4096
      max-header-length: 4096
      max-url-length: 1024
    command-injection:
      action: block
      content-type: all
      exceptions:
      - type: HTML
        url-pattern: /admin/cmd-tool
      - type: JSON
        url-pattern: /api/script-runner
    cookie-consistency:
      action: block
      exceptions:
      - cookie-name: session_tracker
    cross-site-scripting:
      action: block
      content-type: all
      exceptions:
      - type: HTML
        url-pattern: /admin/editor
      - type: JSON
        url-pattern: /api/render
    csrf:
      action: block
      content-type: HTML
      exceptions:
      - url-pattern: apache.com
    data-leak-prevention:
      safe-objects:
      - action: mask
        type: SSN
        max-match-length: 15
      - action: block
        type: CreditCard
      - action: log
        type: Custom
        regex: "\\b[A-Z]{2}\\d{6}\\b"
        max-match-length: 8
    field-consistency:
      action: block
      content-type: HTML
      exceptions:
      - url-pattern: /form/dynamic
    field-format:
      enforcements:
      - action: block
        format: Any
      - action: block
        field-name: "email"
        format: Custom
        customregex: "^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}$"
        max-length: 254
        min-length: 5
        url-pattern: /register
      - action: log
        field-name: "age"
        format: Integer
        max-length: 3
        min-length: 1
    sql-injection:
      action: block
      exceptions:
      - type: HTML
        url-pattern: .*
    waf-signature: "http://1.1.1.1/crd/sig.xml"