Questions about the version of the CRS in Azure WAF

romero 85 Reputation points
2024-04-17T09:20:29.2833333+00:00

Hi, thanks for your interest in the topic.

I have a question about the CRS version of Azure WAF.

Is the latest 3.2 version of CRS in azure waf created based on the 3.2 version of OWASP?

The current version of OWASP is 4.1.

Compared to that, the Azure CRS 3.2 version is low.

Or is the Azure WAF CRS 3.2 not updated in version number, but the content is being updated by referencing the OWASP 4.1 version?

Thanks.

Azure Web Application Firewall
0 comments No comments
{count} votes

Accepted answer
  1. GitaraniSharma-MSFT 47,421 Reputation points Microsoft Employee
    2024-04-17T10:18:29.3+00:00

    Hello @romero ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you would like to know if the latest 3.2 version of CRS in Azure WAF is created based on the OWASP 3.2 version or newer.

    As mentioned in the Azure WAF documentation, CRS 3.2 ruleset is based off OWASP CRS 3.2.0 version.

    Refer: https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules?tabs=drs21#owasp-crs-32

    But the newly added default rule set DRS 2.1 is baselined off the OWASP Core Rule Set (CRS) 3.3.2 and extended to include additional proprietary protections rules developed by Microsoft Threat Intelligence team.

    Refer: https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules?tabs=drs21#drs-21

    https://azure.microsoft.com/en-us/updates/general-availability-default-rule-set-21-for-regional-waf-with-application-gateway/

    Since there have been quite a few false positives with the default OWASP rules, the Microsoft Threat Intelligence Collection rules were written in partnership with the Microsoft Threat Intelligence team to provide increased coverage, patches for specific vulnerabilities, and better false positive reduction.

    https://learn.microsoft.com/en-us/azure/web-application-firewall/ag/application-gateway-crs-rulegroups-rules?tabs=drs21#microsoft-threat-intelligence-collection-rules

    The team is refining/fine tuning the WAF rules to minimize false positives.

    The DRS 2.1 ruleset was introduced on October 31, 2023. Post which, there has been no changes so far.

    I will discuss with the Azure WAF Product Group team and update you on any future improvements which are in pipeline.

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful