How to Block OWASP Top 10 Attacks (Without Breaking Legitimate Traffic)
Most developers turn off Web Application Firewalls (WAFs) after getting flooded with false positives. Traditional rule engines often trigger immediate 403 Forbidden errors whenever a user uploads normal text containing
Most developers turn off Web Application Firewalls (WAFs) after getting flooded with false positives.
Traditional rule engines often trigger immediate 403 Forbidden errors whenever a user uploads normal text containing single quotes, HTML snippets, or complex search filters.
Aegis integrates the Go-native Coraza WAF engine with the OWASP Core Rule Set (CRS v4), using an intelligent cumulative anomaly scoring model rather than crude regex matching.
Here is how to set it up and protect against SQLi, XSS, and RCE without breaking your application.
What is Cumulative Anomaly Scoring?
Instead of blocking on the very first pattern match, Aegis evaluates incoming requests across multiple detection vectors:
- A slightly unusual parameter might score
2 points(low anomaly). - A known SQL injection signature (like
' OR 1=1--) scores5 points(critical anomaly). - Aegis tallies the total threat score. Only when the score breaches the Inbound Anomaly Threshold (default: 5) does the request get blocked with a
403 Forbidden.
This design separates casual anomalies from targeted exploits, cutting false positives drastically.
1. Test Real-World Exploit Mitigation
Aegis enforces OWASP CRS protection out of the box on its public ingress port (8080).
Test 1: SQL Injection (SQLi)
Send an injection attempt in the query string:
curl -i "http://localhost:8080/?id=1%27%20OR%201=1--"
Response:
HTTP/1.1 403 Forbidden
X-WAF-Rule-ID: 942100
Access denied: This request was rejected by the application security layer.
Test 2: Cross-Site Scripting (XSS)
Send a reflected script tag in a POST body:
curl -i -X POST http://localhost:8080/submit \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "comment=<script>alert('xss')</script>"
Response:
HTTP/1.1 403 Forbidden
X-WAF-Rule-ID: 941100
Both attacks are blocked before reaching your origin application servers.
2. Tuning Paranoia Levels in the Dashboard
Open the Aegis Admin Console (http://localhost:8081) and navigate to WAF Core > CRS Settings:
- Paranoia Level 1 (Default): Best for public web apps. High detection rate with near-zero false positives.
- Paranoia Level 2: Adds stricter validation on headers and payloads. Recommended for sensitive banking or payment portals.
- Paranoia Level 3 & 4: Extremely strict inspection for high-security endpoints.
If a legitimate API payload triggers a specific rule (e.g., Rule ID 942100), you can whitelist the rule or add an exception directly from the Threat Inspection Log in the dashboard with one click.
Resources
The Community Edition is free to self-host:
- GitHub: https://github.com/divinelabio/aegis
- Documentation: https://divinelab.io/products/aegis/docs/waf-core/overview
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ full credit and traffic to the original publisher.
