مود سيكيوريتي

ModSecurity ، أو Modsec كما يُعرف أحيانًا ، هو جدار حماية مفتوح المصدر لتطبيقات الويب (WAF). صُمم في الأصل كوحدة نمطية لخادم Apache HTTP ، ثم تطور ليُوفر مجموعة من إمكانيات تصفية طلبات واستجابات بروتوكول نقل النص التشعبي (HTTP)، بالإضافة إلى ميزات أمان أخرى، عبر عدد من المنصات المختلفة، بما في ذلك خادم Apache HTTP ، [ 2 ] [ 3 ] و Microsoft IIS و Nginx . [ 4 ] وهو برنامج مجاني مُرخص بموجب رخصة Apache 2.0.

توفر المنصة لغة تكوين قواعد تُعرف باسم "SecRules" للمراقبة والتسجيل والتصفية في الوقت الفعلي لاتصالات بروتوكول نقل النص التشعبي بناءً على قواعد محددة من قبل المستخدم.

على الرغم من أن ModSecurity ليس تكوينه الوحيد، إلا أنه يُستخدم غالبًا لتوفير الحماية ضد فئات عامة من الثغرات الأمنية باستخدام مجموعة قواعد OWASP ModSecurity الأساسية (CRS). [ 5 ] هذه مجموعة قواعد مفتوحة المصدر مكتوبة بلغة SecRules الخاصة بـ ModSecurity. يُعد المشروع جزءًا من OWASP ، مشروع أمان تطبيقات الويب المفتوحة. تتوفر أيضًا العديد من مجموعات القواعد الأخرى.

للكشف عن التهديدات، يتم نشر محرك ModSecurity مُدمجًا داخل خادم الويب أو كخادم وكيل أمام تطبيق الويب. يُمكّن هذا المحرك من فحص اتصالات HTTP الواردة والصادرة إلى نقطة النهاية. وبناءً على إعدادات القواعد، يُحدد المحرك كيفية التعامل مع الاتصالات، بما في ذلك إمكانية تمريرها، أو رفضها، أو إعادة توجيهها، أو إرجاع رمز حالة مُحدد، أو تنفيذ برنامج نصي، وغير ذلك.

تاريخ

طُوِّر برنامج ModSecurity لأول مرة على يد إيفان ريستيتش ، الذي كتب الوحدة بهدف مراقبة حركة مرور التطبيقات على خادم Apache HTTP . صدرت النسخة الأولى في نوفمبر 2002، وكانت تدعم خادم Apache HTTP 1.3.x. في عام 2004، أنشأ إيفان شركة Thinking Stone لمواصلة العمل على المشروع بدوام كامل. أثناء عمله على إعادة كتابة النسخة 2.0، استحوذت شركة Breach Security، وهي شركة أمنية أمريكية إسرائيلية، على Thinking Stone في سبتمبر 2006. استمر إيفان في تطوير النسخة 2.0 التي صدرت لاحقًا في أكتوبر 2006 في مؤتمر OWASP AppSec في سياتل.

Ristić and Breach Security released another major rewrite, version 2.5, with major syntactic changes in February 2008. In December 2008 Ivan left Breach to found SSL Labs. Shortly after Ivan's departure from Breach Security, Trustwave Holdings acquired Breach in June 2010 and relicensed ModSecurity under the Apache license. Development continued and the new license allowed easier integration of ModSecurity into other products. As a result of this there was steady adoption of ModSecurity by various commercial products. The license change also precipitated easier porting of the software. Hence, Microsoft contributed an IIS port in August 2012 and the port for Nginx was released at Black Hat Briefings in 2012.

2017 saw the second edition of the handbook released,[6] written by Christian Folini and Ivan Ristić. It covers ModSecurity up to version 2.9.2.

Being originally an Apache module, porting ModSecurity to other platforms was time-consuming and had high maintenance costs. As a result of this, a complete rewrite was started in December 2015. This new iteration, libmodsecurity, changes the underlying architecture, separating ModSecurity into a standalone engine that communicates with the web server via an API. This modular architecture-based WAF, which was announced for public use in January 2018,[7] became libmodsecurity (ModSecurity version 3.0) and has supported connectors for Nginx and Apache.

In 2021, Trustwave Holdings, announce the End-of-Sale (EOS) of Trustwave support for ModSecurity effective August 1, 2021 and the End-of-Life (EOL) of support effective July 1, 2024. The maintenance of the ModSecurity code is given to the open-source community.[8]

References

  1. "Release v3.0.14". Retrieved 19 May 2025.
  2. "How to secure your Apache 2 server in four steps". Techrepublic.com. 18 November 2016. Retrieved 7 January 2018.
  3. Shah, Shreeraj. "Securing Web Services with mod_security - O'Reilly Media". Onlamp.com. Archived from the original on 7 January 2018. Retrieved 7 January 2018.
  4. Lardinois, Frederic (23 August 2016). "NGINX Plus's latest release puts the focus on security". Techcrunch.com. Retrieved 7 January 2018.
  5. "مجموعة قواعد OWASP ModSecurity الأساسية - خط الدفاع الأول ضد هجمات تطبيقات الويب" . Coreruleset.org . تم الاطلاع عليه بتاريخ 7 يناير 2018 .
  6. دليل ModSecurity . تم الاطلاع عليه بتاريخ 7 يناير 2018 .{{cite book}}تم |website=تجاهله ( مساعدة )
  7. "إعلان ModSecurity الإصدار 3.0" . www.trustwave.com . تم الاطلاع عليه بتاريخ 12 سبتمبر 2019 .
  8. "نهاية البيع ودعم Trustwave لجدار حماية تطبيقات الويب ModSecurity" . trustwave.com . تم الاطلاع عليه بتاريخ 14 أكتوبر 2021 .