收集 Akamai WAF 記錄

剖析器版本:32.0

支援的國家/地區:

本文說明如何使用 Akamai CEF 連接器和 Bindplane,將 Akamai WAF 記錄檔擷取至 Google Security Operations。Akamai WAF 是一種雲端網頁應用程式防火牆,可保護網頁應用程式和 API 免受 SQL 注入、跨網站指令碼攻擊 (XSS) 和 DDoS 攻擊等威脅。Akamai CEF 連接器會近乎即時地從 Akamai SIEM API 提取安全事件,並將這些事件從 JSON 轉換為通用事件格式 (CEF),然後透過 Syslog 轉送至 Bindplane。

事前準備

請確認您已完成下列事前準備事項:

  • Google SecOps 執行個體。
  • Windows 2016 以上版本或 Linux 主機,且系統具備 systemd,可安裝 Bindplane 代理程式。
  • Linux 伺服器 (建議使用 CentOS、RHEL 或 Ubuntu),至少有 2 個 CPU 核心、6 GB RAM 和 2 GB 可用磁碟空間,供 Akamai CEF 連接器使用。
  • 在 CEF 連接器主機上安裝 Java 8 (JRE 1.8) 以上版本。
  • 如果透過 Proxy 執行,請確認防火牆通訊埠已根據 Bindplane 代理程式需求開啟,且 Proxy 許可清單包含 *.cloudsecurity.akamaiapis.net*.luna.akamaiapis.net
  • Akamai Control Center 的特殊存取權。
  • 啟用 App & API Protector、Kona Site Defender、Web Application Protector、Bot Manager 或 Account Protector 的 Akamai 安全性設定。

取得 Google SecOps 擷取驗證檔案

  1. 登入 Google SecOps 控制台。
  2. 依序前往「SIEM 設定」>「收集代理程式」
  3. 下載擷取驗證檔案
    • 將檔案安全地儲存在要安裝 Bindplane 的系統上。

取得 Google SecOps 客戶 ID

  1. 登入 Google SecOps 控制台。
  2. 依序前往「SIEM 設定」>「設定檔」
  3. 複製並儲存「機構詳細資料」部分中的客戶 ID

在 Akamai Control Center 中啟用 SIEM 整合

  1. 登入 Akamai Control Center
  2. 依序前往「WEB & DATA CENTER SECURITY」>「Security Configuration」
  3. 開啟安全設定,以及要收集 SIEM 資料的適當版本。
  4. 按一下「進階設定」,然後展開「SIEM 整合的資料收集」
  5. 按一下「開啟」即可啟用 SIEM。
  6. 選擇要匯出資料的安全政策:
    • 所有安全性政策:傳送違反安全性設定中任何安全性政策的事件 SIEM 資料。
    • 特定安全性政策:傳送一或多項特定安全性政策的資料。從下拉式清單中選取適當的政策。
  7. 複製「網站安全設定 ID」欄位中的值。請儲存這組 ID,稍後會用到。
  8. 按一下「啟用」,將安全性設定變更推送至正式網路。在「聯播網」下方,依序點選「正式環境」和「啟用」

設定使用者,在 Akamai Control Center 中管理 SIEM

  1. Akamai Control Center 中,依序前往「ACCOUNT ADMIN」(帳戶管理員) >「Identity & access」(身分與存取權)
  2. 在「使用者和 API 用戶端」分頁中,找出要指派角色的使用者,或按一下「建立使用者」
  3. 如要將 SIEM 角色指派給現有使用者:
    1. 開啟使用者的帳戶,然後按一下「編輯角色」分頁標籤。
    2. 找到適當的群組,按一下「角色」下拉式選單,然後選取「管理 SIEM」角色。
    3. 按一下「提交」
  4. 如要將 SIEM 角色指派給新使用者,請按照下列步驟操作:

    1. 按一下「建立使用者」
    2. 輸入使用者的基本資訊,然後向下捲動至「指派角色」部分。
    3. 找到適當的群組,按一下「角色」下拉式選單,然後選取「管理 SIEM」角色。
    4. 按一下 [儲存]

在 Akamai Control Center 中佈建 SIEM API 憑證

  1. 請參閱 Akamai 說明文件中的「建立驗證憑證」頁面。
  2. 按照步驟,為指派管理 SIEM 的使用者佈建 SIEM API。
  3. 複製並妥善儲存下列憑證:

    • 存取權杖
    • 用戶端憑證
    • 用戶端密碼
    • 基準網址 (主機)

安裝 Akamai CEF 連接器

  1. 在 Linux 伺服器上,從 Akamai SIEM Integration Connector Packages GitHub 存放區下載最新版 CEF 連接器發布套件。
  2. 視需要將套件轉移至伺服器。
  3. 驗證下載檔案的 SHA256 雜湊,確保檔案完整性。
  4. 解壓縮發布套件:

    unzip CEFConnector-<version>.zip
    
  5. 前往解壓縮的目錄:

    cd CEFConnector-<version>
    
  6. 建立開機指令碼的符號連結,安裝服務:

    sudo ln -s /path/to/CEFConnector-<version>/bin/AkamaiCEFConnector.sh /etc/init.d/AkamaiCEFConnector
    

設定 Akamai CEF 連接器

  1. 前往 CEF 連接器安裝目錄中的 config 目錄:

    cd /path/to/CEFConnector-<version>/config
    
  2. 使用文字編輯器開啟 CEFConnector.properties 檔案:

    sudo nano CEFConnector.properties
    
  3. 設定下列必要參數:

    # Pull rate from Akamai source (in seconds, positive integer)
    connector.pull.interval=60
    
    # Security Configuration IDs (semicolon-separated for multiple)
    akamai.data.configs=<YOUR_SECURITY_CONFIG_ID>
    
    # API Credentials
    akamai.data.accesstoken=<YOUR_ACCESS_TOKEN>
    akamai.data.clienttoken=<YOUR_CLIENT_TOKEN>
    akamai.data.clientsecret=<YOUR_CLIENT_SECRET>
    akamai.data.baseurl=<YOUR_BASE_URL>
    
    # Offset-based mode (recommended for continuous collection)
    akamai.data.timebased=false
    
    # Maximum number of events per API call
    akamai.data.limit=200000
    
    # Proxy Configuration (leave blank if no proxy)
    # connector.proxy.host=
    # connector.proxy.port=
    
  4. 將下列預留位置替換為實際值:

    • <YOUR_SECURITY_CONFIG_ID>:您在「啟用 SIEM」一節中複製的 Web Security Configuration ID。如有多個設定,請以半形分號分隔 ID (例如 12345;67890)。
    • <YOUR_ACCESS_TOKEN>:Akamai API 憑證的存取權杖。
    • <YOUR_CLIENT_TOKEN>:Akamai API 憑證中的用戶端權杖。
    • <YOUR_CLIENT_SECRET>:Akamai API 憑證中的用戶端密鑰。
    • <YOUR_BASE_URL>:Akamai API 憑證中的基本網址 (主機),例如 akab-xxxxxxxxxxxxxxxx-xxxxxxxxxxxxxxxx.luna.akamaiapis.net
  5. 儲存並關閉檔案。

設定 CEF 連接器記錄,將系統記錄檔轉送至 Bindplane

  1. 前往 CEF 連接器安裝目錄中的 config 目錄。
  2. 使用文字編輯器開啟 log4j2.xml 檔案:

    sudo nano /path/to/CEFConnector-<version>/config/log4j2.xml
    
  3. 在檔案頂端附近的「屬性」部分,設定遠端系統記錄伺服器參數,指向 Bindplane 代理程式:

    <!-- Syslog Appender Configuration -->
    <Syslog name="SyslogAppender" 
            host="<BINDPLANE_IP_ADDRESS>" 
            port="<BINDPLANE_PORT>" 
            protocol="<PROTOCOL>" 
            facility="LOCAL0"
            format="RFC 5424">
        <PatternLayout pattern="%m%n"/>
    </Syslog>
    
  4. 替換下列預留位置:

    • <BINDPLANE_IP_ADDRESS>:安裝 Bindplane 代理程式的伺服器 IP 位址 (例如 192.168.1.100)。
    • <BINDPLANE_PORT>:Bindplane 代理程式接聽的通訊埠號碼 (例如 UDP 的 514 或 TCP 的 601)。
    • CEFProtocol 設為 UDPTCP,與 Bindplane 接收器設定相符。
  5. 儲存並關閉檔案。

啟動 Akamai CEF 連接器

  1. 啟動 CEF 連接器服務:

    sudo /etc/init.d/AkamaiCEFConnector start
    
  2. 確認服務正在執行:

    sudo /etc/init.d/AkamaiCEFConnector status
    
  3. 監控記錄,確保連接器從 Akamai 擷取事件並轉送:

    tail -f /path/to/CEFConnector-<version>/bin/logs/cefconnector.log
    

安裝 Bindplane 代理程式

請按照下列操作說明,在 Windows 或 Linux 作業系統上安裝 Bindplane 代理程式。

Windows 安裝

  1. 以管理員身分開啟「命令提示字元」或「PowerShell」
  2. 執行下列指令:

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux 安裝

  1. 開啟具有根層級或 sudo 權限的終端機。
  2. 執行下列指令:

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

其他安裝資源

如需其他安裝選項,請參閱這份安裝指南

設定 Bindplane 代理程式,擷取系統記錄檔並傳送至 Google SecOps

  1. 存取設定檔:

    • 找出 config.yaml 檔案。通常位於 Linux 的 /status observiq-otel-collector/ 目錄,或 Windows 的安裝目錄。
    • 使用文字編輯器 (例如 nanovi 或記事本) 開啟檔案。
  2. 按照下列方式編輯 config.yaml 檔案:

    receivers:
      udplog:
        # Replace the port and IP address as required
        listen_address: "0.0.0.0:514"
    
    exporters:
      chronicle/chronicle_w_labels:
        compression: gzip
        # Adjust the path to the credentials file you downloaded in the Get ingestion authentication file section
        creds_file_path: '/path/to/ingestion-authentication-file.json'
        # Replace with your actual customer ID from the Get customer ID section
        customer_id: <PLACEHOLDER_CUSTOMER_ID>
        endpoint: malachiteingestion-pa.googleapis.com
        # Add optional ingestion labels for better organization
        log_type: 'AKAMAI_WAF'
        raw_log_field: body
        ingestion_labels:
    
    service:
      pipelines:
        logs/source0__chronicle_w_labels-0:
          receivers:
            - udplog
          exporters:
            - chronicle/chronicle_w_labels
    
  • 視基礎架構需求,替換通訊埠和 IP 位址。
  • <PLACEHOLDER_CUSTOMER_ID> 替換為實際的客戶 ID。
  • /path/to/ingestion-authentication-file.json 更新為「取得 Google SecOps 擷取驗證檔案」一節中儲存驗證檔案的檔案路徑。

重新啟動 Bindplane 代理程式,以套用變更

如要在 Linux 中重新啟動 Bindplane 代理程式,請執行下列步驟:

  1. 執行下列指令:

    sudo systemctl restart observiq-otel-collector
    
  2. 確認服務正在執行:

    sudo systemctl status observiq-otel-collector
    
  3. 檢查記錄中是否有錯誤:

    sudo journalctl -u observiq-otel-collector -f
    

如要在 Windows 中重新啟動 Bindplane 代理程式,請按照下列步驟操作:

  1. 您可以選擇下列其中一個選項:

    • 以管理員身分開啟命令提示字元或 PowerShell:
    net stop observiq-otel-collector && net start observiq-otel-collector
    
    • 服務控制台:
      1. 按下 Win+R,輸入 services.msc,然後按下 Enter 鍵。
      2. 找出 observIQ OpenTelemetry Collector
      3. 按一下滑鼠右鍵,然後選取「重新啟動」
  2. 確認服務正在執行:

    sc query observiq-otel-collector
    
  3. 檢查記錄中是否有錯誤:

    type "C:\Program Files\observIQ OpenTelemetry Collector\log\collector.log"
    

UDM 對應表

記錄欄位 UDM 對應 邏輯
src (attackData.clientIP) principal.ip 傳送要求的用戶端來源 IP 位址
c6a2 (ipv6src) principal.ip 如果 attackData.clientIP 採用 IPv6 格式,則為來源 IPv6 位址
dhost (httpMessage.host) target.hostname HTTP HOST 標頭中的主機名稱
dpt (httpMessage.port) target.port 傳入要求使用的連接埠號碼
requestMethod (httpMessage.method) network.http.method 傳入要求的 HTTP 方法 (GET、POST 等)
request (requestURL) target.url 根據 httpMessage 欄位計算完整網址
cs1 (attackData.rules) security_result.rule_id 這項要求觸發的規則 ID
cs2 (attackData.ruleMessages) security_result.rule_name 觸發規則的訊息
act (appliedAction) security_result.action 採取行動 (警示、拒絕、中止等)
severity security_result.severity 計算出的嚴重性 (偵測為 5,緩解為 10)
cs5 (attackData.clientReputation) security_result.threat_name 用戶端信譽的用戶端 IP 分數
cs6 (attackData.apiId) security_result.detection_fields API 防護的 API ID
start (httpMessage.start) metadata.event_timestamp Edge 伺服器啟動連線的時間 (epoch 格式)
devicePayloadId (httpMessage.requestId) metadata.product_log_id 訊息的全域不重複 ID
flexString1 (attackData.configId) security_result.detection_fields 套用至這項要求的安全設定 ID
flexString2 (attackData.policyId) security_result.detection_fields 套用至這項要求的防火牆政策 ID
AkamaiSiemJA4 (identity.ja4) network.tls.client.ja3 JA4 用戶端 TLS 指紋

變更記錄

查看這個剖析器的變更記錄

還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。