Files
EdgeNode/internal/waf/rule_set_test.go

184 lines
3.9 KiB
Go
Raw Normal View History

package waf_test
2020-10-08 15:06:42 +08:00
import (
"bytes"
"github.com/TeaOSLab/EdgeNode/internal/waf"
2020-10-08 15:06:42 +08:00
"github.com/TeaOSLab/EdgeNode/internal/waf/requests"
2020-11-21 22:29:57 +08:00
"github.com/cespare/xxhash"
2020-10-08 15:06:42 +08:00
"github.com/iwind/TeaGo/assert"
"net/http"
"regexp"
"runtime"
"testing"
)
func TestRuleSet_MatchRequest(t *testing.T) {
var set = waf.NewRuleSet()
set.Connector = waf.RuleConnectorAnd
2020-10-08 15:06:42 +08:00
set.Rules = []*waf.Rule{
2020-10-08 15:06:42 +08:00
{
Param: "${arg.name}",
Operator: waf.RuleOperatorEqString,
2020-10-08 15:06:42 +08:00
Value: "lu",
},
{
Param: "${arg.age}",
Operator: waf.RuleOperatorEq,
2020-10-08 15:06:42 +08:00
Value: "20",
},
}
2021-07-18 15:51:49 +08:00
err := set.Init(nil)
2020-10-08 15:06:42 +08:00
if err != nil {
t.Fatal(err)
}
rawReq, err := http.NewRequest(http.MethodGet, "http://teaos.cn/hello?name=lu&age=20", nil)
if err != nil {
t.Fatal(err)
}
2021-07-18 15:51:49 +08:00
req := requests.NewTestRequest(rawReq)
2020-10-08 15:06:42 +08:00
t.Log(set.MatchRequest(req))
}
func TestRuleSet_MatchRequest2(t *testing.T) {
var a = assert.NewAssertion(t)
2020-10-08 15:06:42 +08:00
var set = waf.NewRuleSet()
set.Connector = waf.RuleConnectorOr
2020-10-08 15:06:42 +08:00
set.Rules = []*waf.Rule{
2020-10-08 15:06:42 +08:00
{
Param: "${arg.name}",
Operator: waf.RuleOperatorEqString,
2020-10-08 15:06:42 +08:00
Value: "lu",
},
{
Param: "${arg.age}",
Operator: waf.RuleOperatorEq,
2020-10-08 15:06:42 +08:00
Value: "21",
},
}
2021-07-18 15:51:49 +08:00
err := set.Init(nil)
2020-10-08 15:06:42 +08:00
if err != nil {
t.Fatal(err)
}
rawReq, err := http.NewRequest(http.MethodGet, "http://teaos.cn/hello?name=lu&age=20", nil)
if err != nil {
t.Fatal(err)
}
2021-07-18 15:51:49 +08:00
req := requests.NewTestRequest(rawReq)
2020-10-08 15:06:42 +08:00
a.IsTrue(set.MatchRequest(req))
}
func BenchmarkRuleSet_MatchRequest(b *testing.B) {
runtime.GOMAXPROCS(1)
var set = waf.NewRuleSet()
set.Connector = waf.RuleConnectorOr
2020-10-08 15:06:42 +08:00
set.Rules = []*waf.Rule{
2020-10-08 15:06:42 +08:00
{
Param: "${requestAll}",
Operator: waf.RuleOperatorMatch,
2020-10-08 15:06:42 +08:00
Value: `(onmouseover|onmousemove|onmousedown|onmouseup|onerror|onload|onclick|ondblclick|onkeydown|onkeyup|onkeypress)\s*=`,
},
{
Param: "${requestAll}",
Operator: waf.RuleOperatorMatch,
2020-10-08 15:06:42 +08:00
Value: `\b(eval|system|exec|execute|passthru|shell_exec|phpinfo)\s*\(`,
},
{
Param: "${arg.name}",
Operator: waf.RuleOperatorEqString,
2020-10-08 15:06:42 +08:00
Value: "lu",
},
{
Param: "${arg.age}",
Operator: waf.RuleOperatorEq,
2020-10-08 15:06:42 +08:00
Value: "21",
},
}
2021-07-18 15:51:49 +08:00
err := set.Init(nil)
2020-10-08 15:06:42 +08:00
if err != nil {
b.Fatal(err)
}
rawReq, err := http.NewRequest(http.MethodPost, "http://teaos.cn/hello?name=lu&age=20", bytes.NewBuffer(bytes.Repeat([]byte("HELLO"), 1024)))
if err != nil {
b.Fatal(err)
}
2021-07-18 15:51:49 +08:00
req := requests.NewTestRequest(rawReq)
2020-10-08 15:06:42 +08:00
for i := 0; i < b.N; i++ {
2022-07-16 17:05:37 +08:00
_, _, _ = set.MatchRequest(req)
2020-10-08 15:06:42 +08:00
}
}
func BenchmarkRuleSet_MatchRequest_Regexp(b *testing.B) {
runtime.GOMAXPROCS(1)
var set = waf.NewRuleSet()
set.Connector = waf.RuleConnectorOr
2020-10-08 15:06:42 +08:00
set.Rules = []*waf.Rule{
2020-10-08 15:06:42 +08:00
{
Param: "${requestBody}",
Operator: waf.RuleOperatorMatch,
2020-10-08 15:06:42 +08:00
Value: `\b(eval|system|exec|execute|passthru|shell_exec|phpinfo)\s*\(`,
IsCaseInsensitive: false,
},
}
2021-07-18 15:51:49 +08:00
err := set.Init(nil)
2020-10-08 15:06:42 +08:00
if err != nil {
b.Fatal(err)
}
rawReq, err := http.NewRequest(http.MethodPost, "http://teaos.cn/hello?name=lu&age=20", bytes.NewBuffer(bytes.Repeat([]byte("HELLO"), 2048)))
if err != nil {
b.Fatal(err)
}
2021-07-18 15:51:49 +08:00
req := requests.NewTestRequest(rawReq)
2020-10-08 15:06:42 +08:00
for i := 0; i < b.N; i++ {
2022-07-16 17:05:37 +08:00
_, _, _ = set.MatchRequest(req)
2020-10-08 15:06:42 +08:00
}
}
func BenchmarkRuleSet_MatchRequest_Regexp2(b *testing.B) {
reg, err := regexp.Compile(`(?iU)\b(eval|system|exec|execute|passthru|shell_exec|phpinfo)\b`)
if err != nil {
b.Fatal(err)
}
buf := bytes.Repeat([]byte(" HELLO "), 10240)
for i := 0; i < b.N; i++ {
_ = reg.Match(buf)
}
}
func BenchmarkRuleSet_MatchRequest_Regexp3(b *testing.B) {
reg, err := regexp.Compile(`(?iU)^(eval|system|exec|execute|passthru|shell_exec|phpinfo)`)
if err != nil {
b.Fatal(err)
}
buf := bytes.Repeat([]byte(" HELLO "), 1024)
for i := 0; i < b.N; i++ {
_ = reg.Match(buf)
}
}
func BenchmarkHash(b *testing.B) {
2020-11-21 22:29:57 +08:00
runtime.GOMAXPROCS(1)
2020-10-08 15:06:42 +08:00
for i := 0; i < b.N; i++ {
2020-11-21 22:29:57 +08:00
_ = xxhash.Sum64(bytes.Repeat([]byte("HELLO"), 10240))
2020-10-08 15:06:42 +08:00
}
}