-
Notifications
You must be signed in to change notification settings - Fork 324
Updated ASM rules to 1.13.1 #7536
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
manuel-alvarez-alvarez
approved these changes
Aug 30, 2024
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 49 metrics, 14 unstable metrics. Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.061 s) : 0, 1061423
Total [baseline] (8.558 s) : 0, 8558329
Agent [candidate] (1.058 s) : 0, 1058117
Total [candidate] (8.524 s) : 0, 8524382
section iast
Agent [baseline] (1.173 s) : 0, 1173151
Total [baseline] (9.014 s) : 0, 9014482
Agent [candidate] (1.181 s) : 0, 1180717
Total [candidate] (8.971 s) : 0, 8971215
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.176 s) : 0, 1175586
Total [baseline] (8.942 s) : 0, 8942422
Agent [candidate] (1.183 s) : 0, 1182894
Total [candidate] (8.966 s) : 0, 8966264
section iast_TELEMETRY_OFF
Agent [baseline] (1.172 s) : 0, 1171956
Total [baseline] (8.956 s) : 0, 8956255
Agent [candidate] (1.173 s) : 0, 1173212
Total [candidate] (9.004 s) : 0, 9004259
gantt
title insecure-bank - break down per module: candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (678.664 ms) : 0, 678664
BytebuddyAgent [candidate] (674.028 ms) : 0, 674028
GlobalTracer [baseline] (308.763 ms) : 0, 308763
GlobalTracer [candidate] (309.024 ms) : 0, 309024
AppSec [baseline] (51.998 ms) : 0, 51998
AppSec [candidate] (53.047 ms) : 0, 53047
Remote Config [baseline] (674.716 µs) : 0, 675
Remote Config [candidate] (692.049 µs) : 0, 692
Telemetry [baseline] (7.57 ms) : 0, 7570
Telemetry [candidate] (7.626 ms) : 0, 7626
section iast
BytebuddyAgent [baseline] (779.856 ms) : 0, 779856
BytebuddyAgent [candidate] (785.025 ms) : 0, 785025
GlobalTracer [baseline] (295.844 ms) : 0, 295844
GlobalTracer [candidate] (297.463 ms) : 0, 297463
AppSec [baseline] (52.924 ms) : 0, 52924
AppSec [candidate] (55.606 ms) : 0, 55606
IAST [baseline] (22.167 ms) : 0, 22167
IAST [candidate] (21.103 ms) : 0, 21103
Remote Config [baseline] (590.865 µs) : 0, 591
Remote Config [candidate] (573.108 µs) : 0, 573
Telemetry [baseline] (8.179 ms) : 0, 8179
Telemetry [candidate] (7.265 ms) : 0, 7265
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (780.885 ms) : 0, 780885
BytebuddyAgent [candidate] (786.034 ms) : 0, 786034
GlobalTracer [baseline] (296.567 ms) : 0, 296567
GlobalTracer [candidate] (298.237 ms) : 0, 298237
AppSec [baseline] (53.061 ms) : 0, 53061
AppSec [candidate] (52.647 ms) : 0, 52647
IAST [baseline] (22.738 ms) : 0, 22738
IAST [candidate] (24.214 ms) : 0, 24214
Remote Config [baseline] (583.971 µs) : 0, 584
Remote Config [candidate] (594.443 µs) : 0, 594
Telemetry [baseline] (8.083 ms) : 0, 8083
Telemetry [candidate] (7.416 ms) : 0, 7416
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (778.458 ms) : 0, 778458
BytebuddyAgent [candidate] (778.358 ms) : 0, 778358
GlobalTracer [baseline] (296.252 ms) : 0, 296252
GlobalTracer [candidate] (296.621 ms) : 0, 296621
AppSec [baseline] (52.232 ms) : 0, 52232
AppSec [candidate] (54.158 ms) : 0, 54158
IAST [baseline] (23.619 ms) : 0, 23619
IAST [candidate] (21.776 ms) : 0, 21776
Remote Config [baseline] (575.077 µs) : 0, 575
Remote Config [candidate] (587.422 µs) : 0, 587
Telemetry [baseline] (7.174 ms) : 0, 7174
Telemetry [candidate] (8.062 ms) : 0, 8062
Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.048 s) : 0, 1047722
Total [baseline] (10.304 s) : 0, 10303584
Agent [candidate] (1.065 s) : 0, 1064918
Total [candidate] (10.408 s) : 0, 10408466
section appsec
Agent [baseline] (1.186 s) : 0, 1186053
Total [baseline] (10.55 s) : 0, 10549856
Agent [candidate] (1.186 s) : 0, 1185532
Total [candidate] (10.554 s) : 0, 10553667
section iast
Agent [baseline] (1.175 s) : 0, 1175199
Total [baseline] (10.902 s) : 0, 10901910
Agent [candidate] (1.183 s) : 0, 1182583
Total [candidate] (10.966 s) : 0, 10966399
section profiling
Agent [baseline] (1.247 s) : 0, 1247452
Total [baseline] (10.58 s) : 0, 10579613
Agent [candidate] (1.251 s) : 0, 1250533
Total [candidate] (10.653 s) : 0, 10652918
gantt
title petclinic - break down per module: candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (668.194 ms) : 0, 668194
BytebuddyAgent [candidate] (678.993 ms) : 0, 678993
GlobalTracer [baseline] (306.119 ms) : 0, 306119
GlobalTracer [candidate] (311.03 ms) : 0, 311030
AppSec [baseline] (51.703 ms) : 0, 51703
AppSec [candidate] (52.875 ms) : 0, 52875
Remote Config [baseline] (663.309 µs) : 0, 663
Remote Config [candidate] (688.113 µs) : 0, 688
Telemetry [baseline] (7.484 ms) : 0, 7484
Telemetry [candidate] (7.55 ms) : 0, 7550
section appsec
BytebuddyAgent [baseline] (690.722 ms) : 0, 690722
BytebuddyAgent [candidate] (689.921 ms) : 0, 689921
GlobalTracer [baseline] (302.2 ms) : 0, 302200
GlobalTracer [candidate] (302.362 ms) : 0, 302362
AppSec [baseline] (159.861 ms) : 0, 159861
AppSec [candidate] (160.933 ms) : 0, 160933
Remote Config [baseline] (614.209 µs) : 0, 614
Remote Config [candidate] (612.674 µs) : 0, 613
Telemetry [baseline] (8.828 ms) : 0, 8828
Telemetry [candidate] (7.648 ms) : 0, 7648
IAST [baseline] (20.426 ms) : 0, 20426
IAST [candidate] (20.861 ms) : 0, 20861
section iast
BytebuddyAgent [baseline] (781.62 ms) : 0, 781620
BytebuddyAgent [candidate] (786.254 ms) : 0, 786254
GlobalTracer [baseline] (296.506 ms) : 0, 296506
GlobalTracer [candidate] (297.774 ms) : 0, 297774
AppSec [baseline] (50.531 ms) : 0, 50531
AppSec [candidate] (54.826 ms) : 0, 54826
Remote Config [baseline] (599.492 µs) : 0, 599
Remote Config [candidate] (602.604 µs) : 0, 603
Telemetry [baseline] (7.352 ms) : 0, 7352
Telemetry [candidate] (8.247 ms) : 0, 8247
IAST [baseline] (24.98 ms) : 0, 24980
IAST [candidate] (21.189 ms) : 0, 21189
section profiling
ProfilingAgent [baseline] (96.032 ms) : 0, 96032
ProfilingAgent [candidate] (97.202 ms) : 0, 97202
BytebuddyAgent [baseline] (664.159 ms) : 0, 664159
BytebuddyAgent [candidate] (664.481 ms) : 0, 664481
GlobalTracer [baseline] (389.249 ms) : 0, 389249
GlobalTracer [candidate] (389.823 ms) : 0, 389823
AppSec [baseline] (52.137 ms) : 0, 52137
AppSec [candidate] (53.016 ms) : 0, 53016
Remote Config [baseline] (684.758 µs) : 0, 685
Remote Config [candidate] (693.615 µs) : 0, 694
Telemetry [baseline] (7.33 ms) : 0, 7330
Telemetry [candidate] (7.371 ms) : 0, 7371
Profiling [baseline] (96.056 ms) : 0, 96056
Profiling [candidate] (97.226 ms) : 0, 97226
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 10 metrics, 18 unstable metrics. Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section baseline
no_agent (1.346 ms) : 1327, 1365
. : milestone, 1346,
appsec (1.72 ms) : 1695, 1745
. : milestone, 1720,
appsec_no_iast (1.732 ms) : 1708, 1755
. : milestone, 1732,
iast (1.472 ms) : 1449, 1494
. : milestone, 1472,
profiling (1.532 ms) : 1508, 1556
. : milestone, 1532,
tracing (1.47 ms) : 1446, 1494
. : milestone, 1470,
section candidate
no_agent (1.358 ms) : 1338, 1377
. : milestone, 1358,
appsec (1.747 ms) : 1723, 1771
. : milestone, 1747,
appsec_no_iast (1.728 ms) : 1703, 1753
. : milestone, 1728,
iast (1.483 ms) : 1460, 1506
. : milestone, 1483,
profiling (1.533 ms) : 1500, 1567
. : milestone, 1533,
tracing (1.453 ms) : 1428, 1478
. : milestone, 1453,
Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section baseline
no_agent (376.521 µs) : 357, 396
. : milestone, 377,
iast (486.28 µs) : 464, 509
. : milestone, 486,
iast_FULL (557.861 µs) : 537, 579
. : milestone, 558,
iast_GLOBAL (506.133 µs) : 484, 528
. : milestone, 506,
iast_HARDCODED_SECRET_DISABLED (480.653 µs) : 459, 503
. : milestone, 481,
iast_INACTIVE (443.8 µs) : 423, 464
. : milestone, 444,
iast_TELEMETRY_OFF (473.198 µs) : 450, 496
. : milestone, 473,
tracing (435.188 µs) : 415, 455
. : milestone, 435,
section candidate
no_agent (378.373 µs) : 358, 399
. : milestone, 378,
iast (493.557 µs) : 471, 516
. : milestone, 494,
iast_FULL (556.11 µs) : 535, 578
. : milestone, 556,
iast_GLOBAL (510.279 µs) : 488, 532
. : milestone, 510,
iast_HARDCODED_SECRET_DISABLED (481.383 µs) : 459, 503
. : milestone, 481,
iast_INACTIVE (450.244 µs) : 429, 472
. : milestone, 450,
iast_TELEMETRY_OFF (483.093 µs) : 460, 506
. : milestone, 483,
tracing (444.885 µs) : 424, 466
. : milestone, 445,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section baseline
no_agent (15.59 s) : 15590000, 15590000
. : milestone, 15590000,
appsec (15.007 s) : 15007000, 15007000
. : milestone, 15007000,
iast (18.966 s) : 18966000, 18966000
. : milestone, 18966000,
iast_GLOBAL (18.005 s) : 18005000, 18005000
. : milestone, 18005000,
profiling (15.178 s) : 15178000, 15178000
. : milestone, 15178000,
tracing (14.964 s) : 14964000, 14964000
. : milestone, 14964000,
section candidate
no_agent (15.013 s) : 15013000, 15013000
. : milestone, 15013000,
appsec (14.899 s) : 14899000, 14899000
. : milestone, 14899000,
iast (19.056 s) : 19056000, 19056000
. : milestone, 19056000,
iast_GLOBAL (17.91 s) : 17910000, 17910000
. : milestone, 17910000,
profiling (15.875 s) : 15875000, 15875000
. : milestone, 15875000,
tracing (15.177 s) : 15177000, 15177000
. : milestone, 15177000,
Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~515dc56091, baseline=1.39.0-SNAPSHOT~6025023dd6
dateFormat X
axisFormat %s
section baseline
no_agent (1.472 ms) : 1460, 1483
. : milestone, 1472,
appsec (2.235 ms) : 2200, 2271
. : milestone, 2235,
iast (1.991 ms) : 1948, 2034
. : milestone, 1991,
iast_GLOBAL (2.024 ms) : 1981, 2068
. : milestone, 2024,
profiling (1.861 ms) : 1826, 1896
. : milestone, 1861,
tracing (1.854 ms) : 1821, 1888
. : milestone, 1854,
section candidate
no_agent (1.463 ms) : 1452, 1475
. : milestone, 1463,
appsec (2.243 ms) : 2207, 2279
. : milestone, 2243,
iast (1.982 ms) : 1939, 2024
. : milestone, 1982,
iast_GLOBAL (2.037 ms) : 1993, 2081
. : milestone, 2037,
profiling (1.857 ms) : 1822, 1891
. : milestone, 1857,
tracing (1.847 ms) : 1814, 1880
. : milestone, 1847,
|
smola
approved these changes
Aug 30, 2024
4 tasks
smola
added a commit
that referenced
this pull request
Sep 2, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
comp: asm waf
Application Security Management (WAF)
tag: no release notes
Changes to exclude from release notes
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Does This Do
Updated ASM rules to version
1.13.1Motivation
Enabled Exploit Prevention rules
Additional Notes
Contributor Checklist
type:and (comp:orinst:) labels in addition to any usefull labelsclose,fixor any linking keywords when referencing an issue.Use
solvesinstead, and assign the PR milestone to the issueJira ticket: [PROJ-IDENT]