Remove warning whenever we receive an unknown WAF address#7482
Merged
Conversation
These happens whenever we receive rules for an address that is not supported by the current version, which is bound to happen for previously released tracers. This has proved to be non-helpful so far, and confusing to customers. Other tracers are not logging this either.
jandro996
approved these changes
Aug 21, 2024
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 49 metrics, 14 unstable metrics. Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.047 s) : 0, 1046595
Total [baseline] (8.529 s) : 0, 8529382
Agent [candidate] (1.046 s) : 0, 1045688
Total [candidate] (8.491 s) : 0, 8491235
section iast
Agent [baseline] (1.194 s) : 0, 1194383
Total [baseline] (9.023 s) : 0, 9023378
Agent [candidate] (1.173 s) : 0, 1173373
Total [candidate] (8.967 s) : 0, 8966887
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.186 s) : 0, 1185678
Total [baseline] (8.992 s) : 0, 8992227
Agent [candidate] (1.177 s) : 0, 1177417
Total [candidate] (8.96 s) : 0, 8960450
section iast_TELEMETRY_OFF
Agent [baseline] (1.181 s) : 0, 1181380
Total [baseline] (8.986 s) : 0, 8986411
Agent [candidate] (1.172 s) : 0, 1172430
Total [candidate] (8.967 s) : 0, 8966970
gantt
title insecure-bank - break down per module: candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (667.539 ms) : 0, 667539
BytebuddyAgent [candidate] (667.229 ms) : 0, 667229
GlobalTracer [baseline] (306.251 ms) : 0, 306251
GlobalTracer [candidate] (306.185 ms) : 0, 306185
AppSec [baseline] (51.247 ms) : 0, 51247
AppSec [candidate] (50.764 ms) : 0, 50764
Remote Config [baseline] (690.393 µs) : 0, 690
Remote Config [candidate] (678.433 µs) : 0, 678
Telemetry [baseline] (7.48 ms) : 0, 7480
Telemetry [candidate] (7.419 ms) : 0, 7419
section iast
BytebuddyAgent [baseline] (795.175 ms) : 0, 795175
BytebuddyAgent [candidate] (780.809 ms) : 0, 780809
GlobalTracer [baseline] (300.197 ms) : 0, 300197
GlobalTracer [candidate] (295.605 ms) : 0, 295605
AppSec [baseline] (50.542 ms) : 0, 50542
AppSec [candidate] (49.966 ms) : 0, 49966
IAST [baseline] (24.645 ms) : 0, 24645
IAST [candidate] (24.254 ms) : 0, 24254
Remote Config [baseline] (585.687 µs) : 0, 586
Remote Config [candidate] (581.175 µs) : 0, 581
Telemetry [baseline] (9.581 ms) : 0, 9581
Telemetry [candidate] (8.706 ms) : 0, 8706
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (788.362 ms) : 0, 788362
BytebuddyAgent [candidate] (782.781 ms) : 0, 782781
GlobalTracer [baseline] (298.379 ms) : 0, 298379
GlobalTracer [candidate] (297.138 ms) : 0, 297138
AppSec [baseline] (49.044 ms) : 0, 49044
AppSec [candidate] (48.63 ms) : 0, 48630
IAST [baseline] (23.734 ms) : 0, 23734
IAST [candidate] (23.561 ms) : 0, 23561
Remote Config [baseline] (598.998 µs) : 0, 599
Remote Config [candidate] (583.222 µs) : 0, 583
Telemetry [baseline] (11.989 ms) : 0, 11989
Telemetry [candidate] (11.188 ms) : 0, 11188
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (786.488 ms) : 0, 786488
BytebuddyAgent [candidate] (779.448 ms) : 0, 779448
GlobalTracer [baseline] (298.809 ms) : 0, 298809
GlobalTracer [candidate] (296.665 ms) : 0, 296665
AppSec [baseline] (53.304 ms) : 0, 53304
AppSec [candidate] (52.224 ms) : 0, 52224
IAST [baseline] (21.443 ms) : 0, 21443
IAST [candidate] (22.196 ms) : 0, 22196
Remote Config [baseline] (611.331 µs) : 0, 611
Remote Config [candidate] (619.652 µs) : 0, 620
Telemetry [baseline] (7.129 ms) : 0, 7129
Telemetry [candidate] (7.754 ms) : 0, 7754
Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.059 s) : 0, 1058980
Total [baseline] (10.505 s) : 0, 10504607
Agent [candidate] (1.056 s) : 0, 1055831
Total [candidate] (10.433 s) : 0, 10433004
section appsec
Agent [baseline] (1.174 s) : 0, 1173561
Total [baseline] (10.501 s) : 0, 10501292
Agent [candidate] (1.167 s) : 0, 1167361
Total [candidate] (10.488 s) : 0, 10487841
section iast
Agent [baseline] (1.177 s) : 0, 1176696
Total [baseline] (10.84 s) : 0, 10840414
Agent [candidate] (1.174 s) : 0, 1173516
Total [candidate] (10.845 s) : 0, 10844681
section profiling
Agent [baseline] (1.245 s) : 0, 1245182
Total [baseline] (10.651 s) : 0, 10651401
Agent [candidate] (1.244 s) : 0, 1244481
Total [candidate] (10.595 s) : 0, 10595450
gantt
title petclinic - break down per module: candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (674.651 ms) : 0, 674651
BytebuddyAgent [candidate] (673.616 ms) : 0, 673616
GlobalTracer [baseline] (310.544 ms) : 0, 310544
GlobalTracer [candidate] (308.888 ms) : 0, 308888
AppSec [baseline] (51.894 ms) : 0, 51894
AppSec [candidate] (51.494 ms) : 0, 51494
Remote Config [baseline] (705.275 µs) : 0, 705
Remote Config [candidate] (696.535 µs) : 0, 697
Telemetry [baseline] (7.669 ms) : 0, 7669
Telemetry [candidate] (7.595 ms) : 0, 7595
section appsec
BytebuddyAgent [baseline] (680.846 ms) : 0, 680846
BytebuddyAgent [candidate] (677.666 ms) : 0, 677666
GlobalTracer [baseline] (300.751 ms) : 0, 300751
GlobalTracer [candidate] (299.319 ms) : 0, 299319
AppSec [baseline] (157.843 ms) : 0, 157843
AppSec [candidate] (156.59 ms) : 0, 156590
IAST [baseline] (20.807 ms) : 0, 20807
IAST [candidate] (19.557 ms) : 0, 19557
Remote Config [baseline] (605.726 µs) : 0, 606
Remote Config [candidate] (603.15 µs) : 0, 603
Telemetry [baseline] (9.639 ms) : 0, 9639
Telemetry [candidate] (9.942 ms) : 0, 9942
section iast
BytebuddyAgent [baseline] (782.513 ms) : 0, 782513
BytebuddyAgent [candidate] (780.451 ms) : 0, 780451
GlobalTracer [baseline] (296.862 ms) : 0, 296862
GlobalTracer [candidate] (295.848 ms) : 0, 295848
AppSec [baseline] (51.473 ms) : 0, 51473
AppSec [candidate] (51.345 ms) : 0, 51345
IAST [baseline] (23.995 ms) : 0, 23995
IAST [candidate] (22.477 ms) : 0, 22477
Remote Config [baseline] (559.989 µs) : 0, 560
Remote Config [candidate] (578.819 µs) : 0, 579
Telemetry [baseline] (7.791 ms) : 0, 7791
Telemetry [candidate] (9.327 ms) : 0, 9327
section profiling
BytebuddyAgent [baseline] (663.738 ms) : 0, 663738
BytebuddyAgent [candidate] (663.154 ms) : 0, 663154
GlobalTracer [baseline] (388.723 ms) : 0, 388723
GlobalTracer [candidate] (389.868 ms) : 0, 389868
AppSec [baseline] (52.347 ms) : 0, 52347
AppSec [candidate] (51.945 ms) : 0, 51945
Remote Config [baseline] (686.745 µs) : 0, 687
Remote Config [candidate] (671.394 µs) : 0, 671
Telemetry [baseline] (7.429 ms) : 0, 7429
Telemetry [candidate] (7.325 ms) : 0, 7325
ProfilingAgent [baseline] (95.068 ms) : 0, 95068
ProfilingAgent [candidate] (94.347 ms) : 0, 94347
Profiling [baseline] (95.092 ms) : 0, 95092
Profiling [candidate] (94.372 ms) : 0, 94372
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 17 unstable metrics. Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section baseline
no_agent (1.339 ms) : 1319, 1358
. : milestone, 1339,
appsec (1.719 ms) : 1696, 1742
. : milestone, 1719,
appsec_no_iast (1.711 ms) : 1686, 1737
. : milestone, 1711,
iast (1.466 ms) : 1444, 1488
. : milestone, 1466,
profiling (1.523 ms) : 1497, 1549
. : milestone, 1523,
tracing (1.462 ms) : 1438, 1487
. : milestone, 1462,
section candidate
no_agent (1.328 ms) : 1309, 1347
. : milestone, 1328,
appsec (1.694 ms) : 1669, 1718
. : milestone, 1694,
appsec_no_iast (1.71 ms) : 1686, 1734
. : milestone, 1710,
iast (1.462 ms) : 1440, 1484
. : milestone, 1462,
profiling (1.501 ms) : 1475, 1528
. : milestone, 1501,
tracing (1.456 ms) : 1431, 1480
. : milestone, 1456,
Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section baseline
no_agent (362.05 µs) : 342, 382
. : milestone, 362,
iast (477.155 µs) : 456, 499
. : milestone, 477,
iast_FULL (542.961 µs) : 521, 565
. : milestone, 543,
iast_GLOBAL (501.908 µs) : 480, 524
. : milestone, 502,
iast_HARDCODED_SECRET_DISABLED (471.41 µs) : 450, 492
. : milestone, 471,
iast_INACTIVE (446.173 µs) : 424, 468
. : milestone, 446,
iast_TELEMETRY_OFF (465.012 µs) : 444, 486
. : milestone, 465,
tracing (437.715 µs) : 417, 458
. : milestone, 438,
section candidate
no_agent (368.893 µs) : 349, 389
. : milestone, 369,
iast (481.367 µs) : 460, 503
. : milestone, 481,
iast_FULL (550.422 µs) : 527, 573
. : milestone, 550,
iast_GLOBAL (500.498 µs) : 478, 523
. : milestone, 500,
iast_HARDCODED_SECRET_DISABLED (468.089 µs) : 447, 489
. : milestone, 468,
iast_INACTIVE (444.182 µs) : 422, 466
. : milestone, 444,
iast_TELEMETRY_OFF (470.289 µs) : 448, 492
. : milestone, 470,
tracing (443.819 µs) : 423, 465
. : milestone, 444,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section baseline
no_agent (15.051 s) : 15051000, 15051000
. : milestone, 15051000,
appsec (15.032 s) : 15032000, 15032000
. : milestone, 15032000,
iast (18.87 s) : 18870000, 18870000
. : milestone, 18870000,
iast_GLOBAL (17.783 s) : 17783000, 17783000
. : milestone, 17783000,
profiling (15.239 s) : 15239000, 15239000
. : milestone, 15239000,
tracing (15.225 s) : 15225000, 15225000
. : milestone, 15225000,
section candidate
no_agent (14.84 s) : 14840000, 14840000
. : milestone, 14840000,
appsec (15.02 s) : 15020000, 15020000
. : milestone, 15020000,
iast (18.897 s) : 18897000, 18897000
. : milestone, 18897000,
iast_GLOBAL (17.875 s) : 17875000, 17875000
. : milestone, 17875000,
profiling (15.39 s) : 15390000, 15390000
. : milestone, 15390000,
tracing (15.074 s) : 15074000, 15074000
. : milestone, 15074000,
Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~c35fcfe7e7, baseline=1.39.0-SNAPSHOT~63ccd4c8fc
dateFormat X
axisFormat %s
section baseline
no_agent (1.456 ms) : 1445, 1468
. : milestone, 1456,
appsec (2.227 ms) : 2191, 2263
. : milestone, 2227,
iast (1.953 ms) : 1911, 1995
. : milestone, 1953,
iast_GLOBAL (2.01 ms) : 1967, 2053
. : milestone, 2010,
profiling (1.854 ms) : 1819, 1890
. : milestone, 1854,
tracing (1.836 ms) : 1802, 1869
. : milestone, 1836,
section candidate
no_agent (1.452 ms) : 1440, 1463
. : milestone, 1452,
appsec (2.211 ms) : 2176, 2246
. : milestone, 2211,
iast (1.958 ms) : 1917, 2000
. : milestone, 1958,
iast_GLOBAL (1.998 ms) : 1955, 2041
. : milestone, 1998,
profiling (1.85 ms) : 1816, 1884
. : milestone, 1850,
tracing (1.819 ms) : 1787, 1852
. : milestone, 1819,
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Does This Do
Remove unknown WAF address warning. These happens whenever we receive rules for an address that is not supported by the current version, which is bound to happen for previously released tracers. This has proved to be non-helpful so far, and confusing to customers. Other tracers are not logging this either.
Contributor Checklist
type:and (comp:orinst:) labels in addition to any usefull labelsclose,fixor any linking keywords when referencing an issue.Use
solvesinstead, and assign the PR milestone to the issue[ ] Update the public documentation in case of new configuration flag or behaviorJira ticket: APPSEC-54587