Thibault Koechlin’s Post

A few weeks ago, we shared that we were working on bot detection and browser fingerprinting for CrowdSec WAF/Security Engine. We've been cooking, and now have something functional (though it needs some polish before shipping) that will enable bot detection & browser fingerprinting for all of our web bouncers that support appsec / waf (nginx, openresty, haproxy, traefik, envoy and hopefully others by then!). We’ve been collaborating with Antoine Vastel, PhD to integrate his fpscanner library into CrowdSec’s WAF/Security Engine. We’re getting ready to ship (like we do with scenarios, waf-rules etc.) collections and rules that will enable users to block common bot frameworks out-of-the-box, while leaving room for more advanced users to craft their own detection rules based on all the signals that can be collected by fpscanner. I’m really excited about this specific feature in CrowdSec, as it’s been something we have been thinking about for a while and will enhance not only the open-source software itself but also the network's strength, allowing us to flag residential proxies, shady shared infrastructure and bot frameworks at scale. let's go!

  • graphical user interface, text
Romain D.

Enix France957 followers

3w

Nice! Hâte de tester ça :-)

To view or add a comment, sign in

Explore content categories