[AAP] Update waf and add support for security_response_id#7807
[AAP] Update waf and add support for security_response_id#7807
Conversation
Snapshots difference summaryThe following differences have been observed in committed snapshots. It is meant to help the reviewer. 2 occurrences of : - "_dd.appsec.waf.version": "1.28.1",
+ "_dd.appsec.waf.version": "1.30.0",
6 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-110","name":"OS command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"cmdi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/bin/rebootCommand"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-110","name":"OS command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"cmdi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/bin/rebootCommand"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},
6 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-100","name":"Shell command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"shi_detector","operator_value":"","parameters":[{"address":null,"highlight":[";evilCommand"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-100","name":"Shell command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"shi_detector","operator_value":"","parameters":[{"address":null,"highlight":[";evilCommand"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},
7 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-001-001","name":"Path traversal attack","tags":{"category":"vulnerability_trigger","type":"lfi"}},"rule_matches":[{"operator":"lfi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/etc/password"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-001-001","name":"Path traversal attack","tags":{"category":"vulnerability_trigger","type":"lfi"}},"rule_matches":[{"operator":"lfi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/etc/password"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},
10 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-002-001","name":"Server-side request forgery","tags":{"category":"vulnerability_trigger","type":"ssrf"}},"rule_matches":[{"operator":"ssrf_detector","operator_value":"","parameters":[{"address":null,"highlight":["127.0.0.1"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-002-001","name":"Server-side request forgery","tags":{"category":"vulnerability_trigger","type":"ssrf"}},"rule_matches":[{"operator":"ssrf_detector","operator_value":"","parameters":[{"address":null,"highlight":["127.0.0.1"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},
6 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-942-100","name":"SQL injection exploit","tags":{"category":"vulnerability_trigger","type":"sql_injection"}},"rule_matches":[{"operator":"sqli_detector","operator_value":"","parameters":[{"address":null,"highlight":["' or '1'='1"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-942-100","name":"SQL injection exploit","tags":{"category":"vulnerability_trigger","type":"sql_injection"}},"rule_matches":[{"operator":"sqli_detector","operator_value":"","parameters":[{"address":null,"highlight":["' or '1'='1"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-001-001","name":"Path traversal attack","tags":{"category":"vulnerability_trigger","type":"lfi"}},"rule_matches":[{"operator":"lfi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/etc/password"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-001-001","name":"Path traversal attack","tags":{"category":"vulnerability_trigger","type":"lfi"}},"rule_matches":[{"operator":"lfi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/etc/password"],"key_path":null,"value":null}]}],"security_response_id":"Guid_3","span_id": XXX}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"crs-932-160","name":"Remote Command Execution: Unix Shell Code Found","tags":{"category":"attack_attempt","type":"command_injection"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dev/zero"],"key_path":["Property"],"value":"dev/zero"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"crs-932-160","name":"Remote Command Execution: Unix Shell Code Found","tags":{"category":"attack_attempt","type":"command_injection"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dev/zero"],"key_path":["Property"],"value":"dev/zero"}]}],"security_response_id":"Guid_2"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}],"security_response_id":"Guid_2"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/Home/Privacy?q=fun"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/Home/Privacy?q=fun"}]}],"security_response_id":"Guid_2"}]},
7 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}],"security_response_id":"Guid_2"}]},
7 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}],"security_response_id":"Guid_3"}]},
7 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}],"security_response_id":"Guid_4"}]},
7 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}],"security_response_id":"Guid_5"}]},
7 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ublock","name":"Hello","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"hello","parameters":[{"address":"server.request.headers.no_cookies","highlight":["hello"],"key_path":["user-agent"],"value":"mistake not... hello/v"}]}],"security_response_id":"Guid_6"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}],"security_response_id":"Guid_2"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}],"security_response_id":"Guid_3"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}],"security_response_id":"Guid_4"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}],"security_response_id":"Guid_5"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property2"],"value":"dummy_rule"}]}],"security_response_id":"Guid_6"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}],"security_response_id":"Guid_3"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}],"security_response_id":"Guid_4"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}],"security_response_id":"Guid_5"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dummy_rule"],"key_path":["Property"],"value":"dummy_rule"}]}],"security_response_id":"Guid_6"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}],"security_response_id":"Guid_3"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}],"security_response_id":"Guid_4"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}],"security_response_id":"Guid_5"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-011","name":"No fun","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"fun","parameters":[{"address":"server.request.uri.raw","highlight":["fun"],"key_path":[],"value":"/health?q=fun"}]}],"security_response_id":"Guid_6"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}],"security_response_id":"Guid_2"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}],"security_response_id":"Guid_3"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}],"security_response_id":"Guid_4"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}],"security_response_id":"Guid_5"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-009","name":"Test block on response header","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"en-us|krypton","parameters":[{"address":"server.response.headers.no_cookies","highlight":["krypton"],"key_path":["content-language"],"value":"krypton"}]}],"security_response_id":"Guid_6"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}],"security_response_id":"Guid_2"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}],"security_response_id":"Guid_3"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}],"security_response_id":"Guid_4"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}],"security_response_id":"Guid_5"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"tst-037-010","name":"No teapot","tags":{"category":"attack_attempt","type":"lfi"}},"rule_matches":[{"operator":"match_regex","operator_value":"418","parameters":[{"address":"server.response.status","highlight":["418"],"key_path":[],"value":"418"}]}],"security_response_id":"Guid_6"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule-custom-block","name":"Dummy rule to test blocking with a custom action","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_custom_action"],"key_path":["arg","0"],"value":"dummy_custom_action"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule-custom-block","name":"Dummy rule to test blocking with a custom action","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_custom_action"],"key_path":["arg","0"],"value":"dummy_custom_action"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule-custom-block","name":"Dummy rule to test blocking with a custom action","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_custom_action"],"key_path":["arg","0"],"value":"dummy_custom_action"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule-custom-block","name":"Dummy rule to test blocking with a custom action","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_custom_action"],"key_path":["arg","0"],"value":"dummy_custom_action"}]}],"security_response_id":"Guid_3"}]},
6 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_rule"],"key_path":["arg","0"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_rule"],"key_path":["arg","0"],"value":"dummy_rule"}]}],"security_response_id":"Guid_2"}]},
6 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_rule"],"key_path":["arg","0"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.query","highlight":["dummy_rule"],"key_path":["arg","0"],"value":"dummy_rule"}]}],"security_response_id":"Guid_3"}]},
8 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-001","name":"Block IP Addresses","tags":{"category":"security_response","type":"block_ip"}},"rule_matches":[{"operator":"ip_match","operator_value":"","parameters":[{"address":"http.client_ip","highlight":["86.242.244.246"],"key_path":[],"value":"86.242.244.246"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-001","name":"Block IP Addresses","tags":{"category":"security_response","type":"block_ip"}},"rule_matches":[{"operator":"ip_match","operator_value":"","parameters":[{"address":"http.client_ip","highlight":["86.242.244.246"],"key_path":[],"value":"86.242.244.246"}]}],"security_response_id":"Guid_2"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-001","name":"Block IP Addresses","tags":{"category":"security_response","type":"block_ip"}},"rule_matches":[{"operator":"ip_match","operator_value":"","parameters":[{"address":"http.client_ip","highlight":["86.242.244.246"],"key_path":[],"value":"86.242.244.246"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-001","name":"Block IP Addresses","tags":{"category":"security_response","type":"block_ip"}},"rule_matches":[{"operator":"ip_match","operator_value":"","parameters":[{"address":"http.client_ip","highlight":["86.242.244.246"],"key_path":[],"value":"86.242.244.246"}]}],"security_response_id":"Guid_3"}]},
7 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["user3"],"key_path":[],"value":"user3"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["user3"],"key_path":[],"value":"user3"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.waf.version: 1.28.1,
+ _dd.appsec.waf.version: 1.30.0,
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ua0-600-56x","name":"Datadog test scanner - blocking version: user-agent","tags":{"category":"attack_attempt","type":"attack_tool"}},"rule_matches":[{"operator":"match_regex","operator_value":"^dd-test-scanner-log-block(?:$|/|\\s)","parameters":[{"address":"server.request.headers.no_cookies","highlight":["dd-test-scanner-log-block"],"key_path":["user-agent"],"value":"dd-test-scanner-log-block"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ua0-600-56x","name":"Datadog test scanner - blocking version: user-agent","tags":{"category":"attack_attempt","type":"attack_tool"}},"rule_matches":[{"operator":"match_regex","operator_value":"^dd-test-scanner-log-block(?:$|/|\\s)","parameters":[{"address":"server.request.headers.no_cookies","highlight":["dd-test-scanner-log-block"],"key_path":["user-agent"],"value":"dd-test-scanner-log-block"}]}],"security_response_id":"Guid_2"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ua0-600-56x","name":"Datadog test scanner - blocking version: user-agent","tags":{"category":"attack_attempt","type":"attack_tool"}},"rule_matches":[{"operator":"match_regex","operator_value":"^dd-test-scanner-log-block(?:$|/|\\s)","parameters":[{"address":"server.request.headers.no_cookies","highlight":["dd-test-scanner-log-block"],"key_path":["user-agent"],"value":"dd-test-scanner-log-block"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ua0-600-56x","name":"Datadog test scanner - blocking version: user-agent","tags":{"category":"attack_attempt","type":"attack_tool"}},"rule_matches":[{"operator":"match_regex","operator_value":"^dd-test-scanner-log-block(?:$|/|\\s)","parameters":[{"address":"server.request.headers.no_cookies","highlight":["dd-test-scanner-log-block"],"key_path":["user-agent"],"value":"dd-test-scanner-log-block"}]}],"security_response_id":"Guid_3"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"crs-942-290","name":"Finds basic MongoDB SQL injection attempts","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[?\\$(?:(?:s(?:lic|iz)|wher)e|e(?:lemMatch|xists|q)|n(?:o[rt]|in?|e)|l(?:ike|te?)|t(?:ext|ype)|a(?:ll|nd)|jsonSchema|between|regex|x?or|div|mod)\\]?)\\b)","parameters":[{"address":"server.request.query","highlight":["[$slice"],"key_path":["[$slice]"],"value":"[$slice]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"crs-942-290","name":"Finds basic MongoDB SQL injection attempts","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[?\\$(?:(?:s(?:lic|iz)|wher)e|e(?:lemMatch|xists|q)|n(?:o[rt]|in?|e)|l(?:ike|te?)|t(?:ext|ype)|a(?:ll|nd)|jsonSchema|between|regex|x?or|div|mod)\\]?)\\b)","parameters":[{"address":"server.request.query","highlight":["[$slice"],"key_path":["[$slice]"],"value":"[$slice]"}]}],"security_response_id":"Guid_2"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["blocked-user"],"key_path":[],"value":"blocked-user"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["blocked-user"],"key_path":[],"value":"blocked-user"}]}],"security_response_id":"Guid_2"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["Guid_2"],"key_path":[],"value":"Guid_2"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["Guid_2"],"key_path":[],"value":"Guid_2"}]}],"security_response_id":"Guid_3"}]},
3 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["blocked-user"],"key_path":[],"value":"blocked-user"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"blk-001-002","name":"Block User Addresses","tags":{"category":"security_response","type":"block_user"}},"rule_matches":[{"operator":"exact_match","operator_value":"","parameters":[{"address":"usr.id","highlight":["blocked-user"],"key_path":[],"value":"blocked-user"}]}],"security_response_id":"Guid_3"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"canary_rule_redirect_200","name":"Canary rule redirect 200","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"Canary\\/v3_200","parameters":[{"address":"server.request.headers.no_cookies","highlight":["Canary/v3_200"],"key_path":["user-agent"],"value":"Mistake Not... Canary/v3_200"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"canary_rule_redirect_200","name":"Canary rule redirect 200","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"Canary\\/v3_200","parameters":[{"address":"server.request.headers.no_cookies","highlight":["Canary/v3_200"],"key_path":["user-agent"],"value":"Mistake Not... Canary/v3_200"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"canary_rule_redirect_302","name":"Canary rule redirect 302","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"Canary\\/v3_302","parameters":[{"address":"server.request.headers.no_cookies","highlight":["Canary/v3_302"],"key_path":["user-agent"],"value":"Mistake Not... Canary/v3_302"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"canary_rule_redirect_302","name":"Canary rule redirect 302","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"match_regex","operator_value":"Canary\\/v3_302","parameters":[{"address":"server.request.headers.no_cookies","highlight":["Canary/v3_302"],"key_path":["user-agent"],"value":"Mistake Not... Canary/v3_302"}]}],"security_response_id":"Guid_2"}]},
8 occurrences of : - http.response.headers.content-length: 167,
+ http.response.headers.content-length: 225,
4 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"crs-932-160","name":"Remote Command Execution: Unix Shell Code Found","tags":{"category":"attack_attempt","type":"command_injection"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dev/zero"],"key_path":["model","Dog2"],"value":"dev/zero"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"crs-932-160","name":"Remote Command Execution: Unix Shell Code Found","tags":{"category":"attack_attempt","type":"command_injection"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.request.body","highlight":["dev/zero"],"key_path":["model","Dog2"],"value":"dev/zero"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"ua0-600-16x","name":"SQL power injector","tags":{"category":"attack_attempt","type":"attack_tool"}},"rule_matches":[{"operator":"match_regex","operator_value":"sql power injector","parameters":[{"address":"server.request.headers.no_cookies","highlight":["sql power injector"],"key_path":["user-agent"],"value":"Mistake Not... (sql power injector)"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"ua0-600-16x","name":"SQL power injector","tags":{"category":"attack_attempt","type":"attack_tool"}},"rule_matches":[{"operator":"match_regex","operator_value":"sql power injector","parameters":[{"address":"server.request.headers.no_cookies","highlight":["sql power injector"],"key_path":["user-agent"],"value":"Mistake Not... (sql power injector)"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_3"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_4"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_5"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.body","highlight":["[blocking_test]"],"key_path":["miscModel","Property1"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_6"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_2"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_3"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_4"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_5"}]},
2 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"block-on-path-params","name":"Block on path params","tags":{"category":"attack_attempt","type":"nosql_injection"}},"rule_matches":[{"operator":"match_regex","operator_value":"(?i:(?:\\[blocking_test\\]))","parameters":[{"address":"server.request.query","highlight":["[blocking_test]"],"key_path":["arg","0"],"value":"[blocking_test]"}]}],"security_response_id":"Guid_6"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}],"security_response_id":"Guid_2"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}],"security_response_id":"Guid_3"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}],"security_response_id":"Guid_4"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}],"security_response_id":"Guid_5"}]},
1 occurrences of : - _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}]}]},
+ _dd.appsec.json: {"triggers":[{"rule":{"id":"test-dummy-rule","name":"Dummy rule to test blocking","tags":{"category":"attack_attempt","type":"security_scanner"}},"rule_matches":[{"operator":"phrase_match","operator_value":"","parameters":[{"address":"server.response.headers.no_cookies","highlight":["dummy_rule"],"key_path":["x-test"],"value":"dummy_rule"}]}],"security_response_id":"Guid_6"}]},
|
BenchmarksBenchmarks Report for benchmark platform 🐌Benchmarks for #7807 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.ActivityBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AgentWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecBodyBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecEncoderBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecWafBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AspNetCoreBenchmark - Unknown 🤷 Same allocations ✔️Raw results
Benchmarks.Trace.CharSliceBenchmark - Slower
|
| Benchmark | diff/base | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.CharSliceBenchmark.OptimizedCharSlice‑netcoreapp3.1 | 1.682 | 1,657,900.00 | 2,788,050.00 | |
| Benchmarks.Trace.CharSliceBenchmark.OptimizedCharSlice‑net6.0 | 1.126 | 1,362,200.00 | 1,534,300.00 |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | OriginalCharSlice |
net6.0 | 2.03ms | 1.16μs | 4.18μs | 0 | 0 | 0 | 640 KB |
| master | OriginalCharSlice |
netcoreapp3.1 | 3.89ms | 1.77μs | 6.63μs | 0 | 0 | 0 | 640.05 KB |
| master | OriginalCharSlice |
net472 | 2.62ms | 603ns | 2.26μs | 0 | 0 | 0 | 638.98 KB |
| master | OptimizedCharSlice |
net6.0 | 1.36ms | 633ns | 2.37μs | 0 | 0 | 0 | 0 b |
| master | OptimizedCharSlice |
netcoreapp3.1 | 1.66ms | 5.17μs | 33.9μs | 0 | 0 | 0 | 0 b |
| master | OptimizedCharSlice |
net472 | 1.89ms | 759ns | 2.94μs | 0 | 0 | 0 | 0 b |
| master | OptimizedCharSliceWithPool |
net6.0 | 1.06ms | 979ns | 3.79μs | 0 | 0 | 0 | 0 b |
| master | OptimizedCharSliceWithPool |
netcoreapp3.1 | 1.86ms | 1.67μs | 6.46μs | 0 | 0 | 0 | 0 b |
| master | OptimizedCharSliceWithPool |
net472 | 1.14ms | 977ns | 3.78μs | 0 | 0 | 0 | 0 b |
| #7807 | OriginalCharSlice |
net6.0 | 2.13ms | 3.09μs | 12μs | 0 | 0 | 0 | 640 KB |
| #7807 | OriginalCharSlice |
netcoreapp3.1 | 3.89ms | 978ns | 3.52μs | 0 | 0 | 0 | 640.05 KB |
| #7807 | OriginalCharSlice |
net472 | 2.62ms | 519ns | 1.87μs | 0 | 0 | 0 | 638.98 KB |
| #7807 | OptimizedCharSlice |
net6.0 | 1.54ms | 2.01μs | 7.78μs | 0 | 0 | 0 | 0 b |
| #7807 | OptimizedCharSlice |
netcoreapp3.1 | 2.79ms | 619ns | 2.32μs | 0 | 0 | 0 | 0 b |
| #7807 | OptimizedCharSlice |
net472 | 2ms | 787ns | 3.05μs | 0 | 0 | 0 | 0 b |
| #7807 | OptimizedCharSliceWithPool |
net6.0 | 1.05ms | 467ns | 1.75μs | 0 | 0 | 0 | 0 b |
| #7807 | OptimizedCharSliceWithPool |
netcoreapp3.1 | 1.88ms | 876ns | 3.39μs | 0 | 0 | 0 | 0 b |
| #7807 | OptimizedCharSliceWithPool |
net472 | 1.17ms | 903ns | 3.5μs | 0 | 0 | 0 | 0 b |
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark - Same speed ✔️ More allocations ⚠️
More allocations ⚠️ in #7807
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces‑net6.0
41.62 KB
42.18 KB
560 B
1.35%
Fewer allocations 🎉 in #7807
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces‑netcoreapp3.1
43.27 KB
41.98 KB
-1.3 KB
-3.00%
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces‑net6.0 | 41.62 KB | 42.18 KB | 560 B | 1.35% |
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces‑netcoreapp3.1 | 43.27 KB | 41.98 KB | -1.3 KB | -3.00% |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | WriteAndFlushEnrichedTraces |
net6.0 | 727μs | 3.51μs | 14.5μs | 0 | 0 | 0 | 41.62 KB |
| master | WriteAndFlushEnrichedTraces |
netcoreapp3.1 | 801μs | 3.49μs | 12.6μs | 0 | 0 | 0 | 43.27 KB |
| master | WriteAndFlushEnrichedTraces |
net472 | 960μs | 4.53μs | 17.5μs | 5.21 | 0 | 0 | 55.55 KB |
| #7807 | WriteAndFlushEnrichedTraces |
net6.0 | 673μs | 3.26μs | 17.9μs | 0 | 0 | 0 | 42.18 KB |
| #7807 | WriteAndFlushEnrichedTraces |
netcoreapp3.1 | 762μs | 4.32μs | 30.9μs | 0 | 0 | 0 | 41.98 KB |
| #7807 | WriteAndFlushEnrichedTraces |
net472 | 880μs | 3.71μs | 13.9μs | 4.46 | 0 | 0 | 55.78 KB |
Benchmarks.Trace.DbCommandBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | ExecuteNonQuery |
net6.0 | 1.93μs | 2.12ns | 7.92ns | 0 | 0 | 0 | 968 B |
| master | ExecuteNonQuery |
netcoreapp3.1 | 2.54μs | 7.12ns | 27.6ns | 0 | 0 | 0 | 960 B |
| master | ExecuteNonQuery |
net472 | 2.85μs | 1.57ns | 5.86ns | 0.143 | 0 | 0 | 931 B |
| #7807 | ExecuteNonQuery |
net6.0 | 1.9μs | 7.22ns | 27.9ns | 0 | 0 | 0 | 968 B |
| #7807 | ExecuteNonQuery |
netcoreapp3.1 | 2.53μs | 8.37ns | 31.3ns | 0 | 0 | 0 | 960 B |
| #7807 | ExecuteNonQuery |
net472 | 2.84μs | 1.72ns | 6.42ns | 0.141 | 0 | 0 | 931 B |
Benchmarks.Trace.ElasticsearchBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | CallElasticsearch |
net6.0 | 1.71μs | 8.21ns | 32.8ns | 0 | 0 | 0 | 952 B |
| master | CallElasticsearch |
netcoreapp3.1 | 2.21μs | 9.66ns | 37.4ns | 0 | 0 | 0 | 968 B |
| master | CallElasticsearch |
net472 | 3.4μs | 3.84ns | 14.9ns | 0.136 | 0 | 0 | 955 B |
| master | CallElasticsearchAsync |
net6.0 | 1.69μs | 8.7ns | 38.9ns | 0 | 0 | 0 | 928 B |
| master | CallElasticsearchAsync |
netcoreapp3.1 | 2.49μs | 9.09ns | 32.8ns | 0 | 0 | 0 | 1.02 KB |
| master | CallElasticsearchAsync |
net472 | 3.54μs | 5.85ns | 22.7ns | 0.159 | 0 | 0 | 1.01 KB |
| #7807 | CallElasticsearch |
net6.0 | 1.74μs | 5.76ns | 20.8ns | 0 | 0 | 0 | 952 B |
| #7807 | CallElasticsearch |
netcoreapp3.1 | 2.31μs | 11.4ns | 49.7ns | 0 | 0 | 0 | 968 B |
| #7807 | CallElasticsearch |
net472 | 3.38μs | 3.01ns | 11.6ns | 0.151 | 0 | 0 | 955 B |
| #7807 | CallElasticsearchAsync |
net6.0 | 1.83μs | 1.91ns | 6.88ns | 0 | 0 | 0 | 928 B |
| #7807 | CallElasticsearchAsync |
netcoreapp3.1 | 2.43μs | 7.03ns | 27.2ns | 0 | 0 | 0 | 1.02 KB |
| #7807 | CallElasticsearchAsync |
net472 | 3.5μs | 2.74ns | 10.6ns | 0.156 | 0 | 0 | 1.01 KB |
Benchmarks.Trace.GraphQLBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | ExecuteAsync |
net6.0 | 1.85μs | 1ns | 3.61ns | 0 | 0 | 0 | 896 B |
| master | ExecuteAsync |
netcoreapp3.1 | 2.45μs | 4.56ns | 17.7ns | 0 | 0 | 0 | 896 B |
| master | ExecuteAsync |
net472 | 2.53μs | 2.68ns | 10.4ns | 0.127 | 0 | 0 | 859 B |
| #7807 | ExecuteAsync |
net6.0 | 1.77μs | 8.3ns | 32.2ns | 0 | 0 | 0 | 896 B |
| #7807 | ExecuteAsync |
netcoreapp3.1 | 2.42μs | 4.08ns | 15.8ns | 0 | 0 | 0 | 896 B |
| #7807 | ExecuteAsync |
net472 | 2.62μs | 6.18ns | 24ns | 0.129 | 0 | 0 | 858 B |
Benchmarks.Trace.HttpClientBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | SendAsync |
net6.0 | 7.05μs | 12.6ns | 48.7ns | 0 | 0 | 0 | 2.29 KB |
| master | SendAsync |
netcoreapp3.1 | 8.29μs | 15.1ns | 58.3ns | 0 | 0 | 0 | 2.83 KB |
| master | SendAsync |
net472 | 12.3μs | 6.37ns | 24.7ns | 0.431 | 0 | 0 | 3.08 KB |
| #7807 | SendAsync |
net6.0 | 7.09μs | 14.9ns | 55.8ns | 0 | 0 | 0 | 2.29 KB |
| #7807 | SendAsync |
netcoreapp3.1 | 8.32μs | 34.4ns | 133ns | 0 | 0 | 0 | 2.83 KB |
| #7807 | SendAsync |
net472 | 12.2μs | 9.31ns | 36ns | 0.486 | 0 | 0 | 3.08 KB |
Benchmarks.Trace.Iast.StringAspectsBenchmark - Slower ⚠️ More allocations ⚠️
Slower ⚠️ in #7807
Benchmark
diff/base
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1
1.201
428,100.00
514,100.00
bimodal
More allocations ⚠️ in #7807
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1
248.25 KB
276.86 KB
28.61 KB
11.52%
Fewer allocations 🎉 in #7807
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0
272.65 KB
256.27 KB
-16.38 KB
-6.01%
| Benchmark | diff/base | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1 | 1.201 | 428,100.00 | 514,100.00 | bimodal |
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1 | 248.25 KB | 276.86 KB | 28.61 KB | 11.52% |
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0 | 272.65 KB | 256.27 KB | -16.38 KB | -6.01% |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StringConcatBenchmark |
net6.0 | 45.3μs | 235ns | 1.08μs | 0 | 0 | 0 | 42.51 KB |
| master | StringConcatBenchmark |
netcoreapp3.1 | 49.7μs | 282ns | 1.99μs | 0 | 0 | 0 | 42.54 KB |
| master | StringConcatBenchmark |
net472 | 57μs | 299ns | 1.49μs | 0 | 0 | 0 | 49.15 KB |
| master | StringConcatAspectBenchmark |
net6.0 | 476μs | 1.66μs | 8.8μs | 0 | 0 | 0 | 272.65 KB |
| master | StringConcatAspectBenchmark |
netcoreapp3.1 | 434μs | 6.43μs | 63.7μs | 0 | 0 | 0 | 248.25 KB |
| master | StringConcatAspectBenchmark |
net472 | 396μs | 1.31μs | 4.72μs | 0 | 0 | 0 | 270.34 KB |
| #7807 | StringConcatBenchmark |
net6.0 | 44.3μs | 240ns | 1.8μs | 0 | 0 | 0 | 42.51 KB |
| #7807 | StringConcatBenchmark |
netcoreapp3.1 | 50.3μs | 247ns | 1.08μs | 0 | 0 | 0 | 42.54 KB |
| #7807 | StringConcatBenchmark |
net472 | 58.1μs | 145ns | 523ns | 0 | 0 | 0 | 49.15 KB |
| #7807 | StringConcatAspectBenchmark |
net6.0 | 467μs | 1.23μs | 4.91μs | 0 | 0 | 0 | 256.27 KB |
| #7807 | StringConcatAspectBenchmark |
netcoreapp3.1 | 513μs | 1.04μs | 5.22μs | 0 | 0 | 0 | 276.86 KB |
| #7807 | StringConcatAspectBenchmark |
net472 | 413μs | 2.2μs | 11.4μs | 0 | 0 | 0 | 270.34 KB |
Benchmarks.Trace.ILoggerBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 2.64μs | 13.8ns | 64.9ns | 0 | 0 | 0 | 1.69 KB |
| master | EnrichedLog |
netcoreapp3.1 | 3.63μs | 1.96ns | 7.59ns | 0 | 0 | 0 | 1.7 KB |
| master | EnrichedLog |
net472 | 3.77μs | 4.73ns | 18.3ns | 0.245 | 0 | 0 | 1.6 KB |
| #7807 | EnrichedLog |
net6.0 | 2.72μs | 2.04ns | 7.62ns | 0 | 0 | 0 | 1.69 KB |
| #7807 | EnrichedLog |
netcoreapp3.1 | 3.52μs | 18.5ns | 90.6ns | 0 | 0 | 0 | 1.7 KB |
| #7807 | EnrichedLog |
net472 | 3.9μs | 6.97ns | 27ns | 0.252 | 0 | 0 | 1.6 KB |
Benchmarks.Trace.Log4netBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 134μs | 723ns | 3.96μs | 0 | 0 | 0 | 4.31 KB |
| master | EnrichedLog |
netcoreapp3.1 | 138μs | 704ns | 3.15μs | 0 | 0 | 0 | 4.31 KB |
| master | EnrichedLog |
net472 | 168μs | 779ns | 3.48μs | 0 | 0 | 0 | 4.51 KB |
| #7807 | EnrichedLog |
net6.0 | 124μs | 73.6ns | 275ns | 0 | 0 | 0 | 4.31 KB |
| #7807 | EnrichedLog |
netcoreapp3.1 | 128μs | 134ns | 482ns | 0 | 0 | 0 | 4.31 KB |
| #7807 | EnrichedLog |
net472 | 166μs | 98.4ns | 381ns | 0 | 0 | 0 | 4.51 KB |
Benchmarks.Trace.NLogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 5.05μs | 5.03ns | 19.5ns | 0 | 0 | 0 | 2.24 KB |
| master | EnrichedLog |
netcoreapp3.1 | 6.89μs | 18.8ns | 67.9ns | 0 | 0 | 0 | 2.26 KB |
| master | EnrichedLog |
net472 | 7.59μs | 5.38ns | 20.1ns | 0.302 | 0 | 0 | 2.05 KB |
| #7807 | EnrichedLog |
net6.0 | 5.18μs | 8.77ns | 31.6ns | 0 | 0 | 0 | 2.24 KB |
| #7807 | EnrichedLog |
netcoreapp3.1 | 6.98μs | 24.8ns | 89.3ns | 0 | 0 | 0 | 2.26 KB |
| #7807 | EnrichedLog |
net472 | 7.63μs | 4.53ns | 17.6ns | 0.304 | 0 | 0 | 2.05 KB |
Benchmarks.Trace.RedisBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | SendReceive |
net6.0 | 1.87μs | 10.4ns | 61.6ns | 0 | 0 | 0 | 1.12 KB |
| master | SendReceive |
netcoreapp3.1 | 2.59μs | 11.2ns | 43.3ns | 0 | 0 | 0 | 1.14 KB |
| master | SendReceive |
net472 | 2.82μs | 2.14ns | 8.03ns | 0.169 | 0 | 0 | 1.12 KB |
| #7807 | SendReceive |
net6.0 | 1.97μs | 8.92ns | 34.5ns | 0 | 0 | 0 | 1.12 KB |
| #7807 | SendReceive |
netcoreapp3.1 | 2.62μs | 12.7ns | 50.8ns | 0 | 0 | 0 | 1.14 KB |
| #7807 | SendReceive |
net472 | 2.94μs | 0.957ns | 3.58ns | 0.163 | 0 | 0 | 1.12 KB |
Benchmarks.Trace.SerilogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 4.28μs | 6.24ns | 24.2ns | 0 | 0 | 0 | 1.58 KB |
| master | EnrichedLog |
netcoreapp3.1 | 5.77μs | 10.2ns | 38.3ns | 0 | 0 | 0 | 1.63 KB |
| master | EnrichedLog |
net472 | 6.58μs | 6.82ns | 26.4ns | 0.296 | 0 | 0 | 2.03 KB |
| #7807 | EnrichedLog |
net6.0 | 4.4μs | 6.35ns | 24.6ns | 0 | 0 | 0 | 1.59 KB |
| #7807 | EnrichedLog |
netcoreapp3.1 | 5.63μs | 5.38ns | 20.8ns | 0 | 0 | 0 | 1.63 KB |
| #7807 | EnrichedLog |
net472 | 6.6μs | 6.77ns | 26.2ns | 0.298 | 0 | 0 | 2.03 KB |
Benchmarks.Trace.SpanBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StartFinishSpan |
net6.0 | 773ns | 3.83ns | 15.8ns | 0 | 0 | 0 | 520 B |
| master | StartFinishSpan |
netcoreapp3.1 | 963ns | 5.18ns | 26.4ns | 0 | 0 | 0 | 520 B |
| master | StartFinishSpan |
net472 | 908ns | 0.376ns | 1.41ns | 0.082 | 0 | 0 | 522 B |
| master | StartFinishScope |
net6.0 | 887ns | 4.55ns | 20.9ns | 0 | 0 | 0 | 640 B |
| master | StartFinishScope |
netcoreapp3.1 | 1.17μs | 4.97ns | 19.2ns | 0 | 0 | 0 | 640 B |
| master | StartFinishScope |
net472 | 1.11μs | 0.318ns | 1.19ns | 0.0949 | 0 | 0 | 602 B |
| master | StartFinishTwoScopes |
net6.0 | 1.81μs | 1.91ns | 7.13ns | 0 | 0 | 0 | 1.19 KB |
| master | StartFinishTwoScopes |
netcoreapp3.1 | 2.29μs | 3.38ns | 13.1ns | 0 | 0 | 0 | 1.19 KB |
| master | StartFinishTwoScopes |
net472 | 2.18μs | 0.462ns | 1.66ns | 0.163 | 0 | 0 | 1.08 KB |
| #7807 | StartFinishSpan |
net6.0 | 769ns | 0.422ns | 1.63ns | 0 | 0 | 0 | 520 B |
| #7807 | StartFinishSpan |
netcoreapp3.1 | 949ns | 4.99ns | 23.9ns | 0 | 0 | 0 | 520 B |
| #7807 | StartFinishSpan |
net472 | 899ns | 0.26ns | 1.01ns | 0.0813 | 0 | 0 | 522 B |
| #7807 | StartFinishScope |
net6.0 | 932ns | 4.8ns | 21.5ns | 0 | 0 | 0 | 640 B |
| #7807 | StartFinishScope |
netcoreapp3.1 | 1.15μs | 4.92ns | 19.1ns | 0 | 0 | 0 | 640 B |
| #7807 | StartFinishScope |
net472 | 1.15μs | 1.46ns | 5.25ns | 0.0939 | 0 | 0 | 602 B |
| #7807 | StartFinishTwoScopes |
net6.0 | 1.79μs | 8.38ns | 34.6ns | 0 | 0 | 0 | 1.19 KB |
| #7807 | StartFinishTwoScopes |
netcoreapp3.1 | 2.23μs | 11.5ns | 57.3ns | 0 | 0 | 0 | 1.19 KB |
| #7807 | StartFinishTwoScopes |
net472 | 2.16μs | 1.62ns | 5.86ns | 0.163 | 0 | 0 | 1.08 KB |
Benchmarks.Trace.TraceAnnotationsBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | RunOnMethodBegin |
net6.0 | 1.07μs | 5.19ns | 21.4ns | 0 | 0 | 0 | 640 B |
| master | RunOnMethodBegin |
netcoreapp3.1 | 1.38μs | 7.31ns | 36.6ns | 0 | 0 | 0 | 640 B |
| master | RunOnMethodBegin |
net472 | 1.45μs | 0.578ns | 2.24ns | 0.0945 | 0 | 0 | 602 B |
| #7807 | RunOnMethodBegin |
net6.0 | 1.08μs | 3.43ns | 13.3ns | 0 | 0 | 0 | 640 B |
| #7807 | RunOnMethodBegin |
netcoreapp3.1 | 1.38μs | 7.12ns | 32.6ns | 0 | 0 | 0 | 640 B |
| #7807 | RunOnMethodBegin |
net472 | 1.42μs | 0.394ns | 1.52ns | 0.0924 | 0 | 0 | 602 B |
b9b45f9 to
5c5e07a
Compare
|
✅ Tests 🎉 All green!❄️ No new flaky tests detected 🔗 Commit SHA: c775aa4 | Docs | Datadog PR Page | Was this helpful? Give us feedback! |
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing This PR (7807) and master. ✅ No regressions detected - check the details below Full Metrics ComparisonFakeDbCommand
HttpMessageHandler
Comparison explanationExecution-time benchmarks measure the whole time it takes to execute a program, and are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are highlighted in **red**. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). Duration chartsFakeDbCommand (.NET Framework 4.8)gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (76ms) : 70, 82
master - mean (76ms) : 70, 82
section Bailout
This PR (7807) - mean (80ms) : 76, 85
master - mean (81ms) : 75, 87
section CallTarget+Inlining+NGEN
This PR (7807) - mean (1,065ms) : 1019, 1111
master - mean (1,076ms) : 995, 1158
FakeDbCommand (.NET Core 3.1)gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (119ms) : 111, 126
master - mean (119ms) : 112, 126
section Bailout
This PR (7807) - mean (118ms) : 113, 124
master - mean (120ms) : 115, 126
section CallTarget+Inlining+NGEN
This PR (7807) - mean (762ms) : 726, 798
master - mean (768ms) : 733, 802
FakeDbCommand (.NET 6)gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (105ms) : 100, 111
master - mean (106ms) : 99, 112
section Bailout
This PR (7807) - mean (108ms) : 102, 114
master - mean (106ms) : 99, 114
section CallTarget+Inlining+NGEN
This PR (7807) - mean (712ms) : 682, 742
master - mean (719ms) : 670, 769
FakeDbCommand (.NET 8)gantt
title Execution time (ms) FakeDbCommand (.NET 8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (104ms) : 98, 111
master - mean (104ms) : 96, 111
section Bailout
This PR (7807) - mean (106ms) : 100, 113
master - mean (107ms) : 101, 113
section CallTarget+Inlining+NGEN
This PR (7807) - mean (693ms) : 659, 727
master - mean (697ms) : 670, 723
HttpMessageHandler (.NET Framework 4.8)gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (196ms) : 188, 205
master - mean (196ms) : 190, 202
section Bailout
This PR (7807) - mean (199ms) : 194, 204
master - mean (198ms) : 194, 203
section CallTarget+Inlining+NGEN
This PR (7807) - mean (1,133ms) : 1069, 1197
master - mean (1,136ms) : 1067, 1205
HttpMessageHandler (.NET Core 3.1)gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (282ms) : 274, 290
master - mean (282ms) : 275, 289
section Bailout
This PR (7807) - mean (282ms) : 275, 289
master - mean (282ms) : 276, 288
section CallTarget+Inlining+NGEN
This PR (7807) - mean (927ms) : 878, 976
master - mean (915ms) : 881, 949
HttpMessageHandler (.NET 6)gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (275ms) : 269, 282
master - mean (274ms) : 268, 280
section Bailout
This PR (7807) - mean (274ms) : 268, 279
master - mean (274ms) : 268, 279
section CallTarget+Inlining+NGEN
This PR (7807) - mean (893ms) : 856, 931
master - mean (898ms) : 850, 946
HttpMessageHandler (.NET 8)gantt
title Execution time (ms) HttpMessageHandler (.NET 8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (7807) - mean (273ms) : 267, 280
master - mean (274ms) : 267, 280
section Bailout
This PR (7807) - mean (273ms) : 266, 281
master - mean (274ms) : 266, 282
section CallTarget+Inlining+NGEN
This PR (7807) - mean (839ms) : 815, 864
master - mean (838ms) : 815, 860
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
8afd0f6 to
b78f9a8
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
795a193 to
a972351
Compare
a972351 to
c775aa4
Compare
|
/merge |
|
View all feedbacks in Devflow UI.
Added to the queue but the mergequeue is not enabled for now.
This pull request was merged directly. |
Summary of changes
This PR:
v1.30.0Reason for change
Implementation details
SecurityResponseIdin block actionsTest coverage
Unit tested:
security_response_idsecurity_response_idelementsecurity_response_idquery parameterIntegration tests:
security_response_idon all blocked requestsSystem tests: DataDog/system-tests#5517