This repository has been archived on 2025-09-14. You can view files and clone it, but cannot push or open issues or pull requests.
Files
tango-maat/test/maat_json.json

4342 lines
115 KiB
JSON
Raw Normal View History

2022-12-03 22:23:41 +08:00
{
2024-09-14 11:29:12 +00:00
"rule_table": "RULE_DEFAULT",
"object_group_table": "OBJECT_GROUP",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "ASN1234",
"uuid": "00000000-0000-0000-0000-000000000001",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "AS_NUMBER",
"table_type": "expr",
"table_content": {
"expression": "^AS1234$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "ASN2345",
"uuid": "00000000-0000-0000-0000-000000000002",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "AS_NUMBER",
"table_type": "expr",
"table_content": {
"expression": "^AS2345$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "ASN6789",
"uuid": "00000000-0000-0000-0000-000000000003",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "AS_NUMBER",
"table_type": "expr",
"table_content": {
"expression": "^AS6789$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "ASN9001",
"uuid": "00000000-0000-0000-0000-000000000004",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "AS_NUMBER",
"table_type": "expr",
"table_content": {
"expression": "^AS9001$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "ASN9002",
"uuid": "00000000-0000-0000-0000-000000000005",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "AS_NUMBER",
"table_type": "expr",
"table_content": {
"expression": "^AS9002$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "ASN9003",
"uuid": "00000000-0000-0000-0000-000000000006",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "AS_NUMBER",
"table_type": "expr",
"table_content": {
"expression": "^AS9003$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "IPv4-composition-source-only",
"uuid": "00000000-0000-0000-0000-000000000007",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "192.168.50.24"
}
}
]
},
{
"object_name": "FQDN_OBJ1",
"uuid": "00000000-0000-0000-0000-000000000008",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "^sports.example.com$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "FQDN_CAT1",
"uuid": "00000000-0000-0000-0000-000000000009",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "INTERGER_PLUS",
2024-09-26 11:14:06 +00:00
"table_type": "interval",
2024-09-14 11:29:12 +00:00
"table_content": {
2024-09-26 11:14:06 +00:00
2024-09-14 11:29:12 +00:00
"interval": "1724"
}
}
]
},
{
"object_name": "IPv4-composition-NOT-client-ip",
"uuid": "00000000-0000-0000-0000-000000000010",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "192.168.58.19"
}
}
]
},
{
"object_name": "IPv4-composition-NOT-server-ip",
"uuid": "00000000-0000-0000-0000-000000000011",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "10.0.1.20-10.0.1.25"
}
}
]
},
{
"object_name": "financial-department-ip",
"uuid": "00000000-0000-0000-0000-000000000012",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "192.168.40.88/32"
}
}
]
},
{
"object_name": "security-department-ip",
"uuid": "00000000-0000-0000-0000-000000000013",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_PLUS_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "192.168.40.88/32"
}
}
]
},
{
"object_name": "develop-department-ip",
"uuid": "00000000-0000-0000-0000-000000000014",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_PLUS_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "192.168.40.88/32"
}
}
]
},
{
"object_name": "Country-Sparta-IP",
"uuid": "00000000-0000-0000-0000-000000000015",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "GeoLocation",
"table_type": "expr",
"table_content": {
"expression": "^Greece.Sparta$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "123_IP_object",
"uuid": "00000000-0000-0000-0000-000000000100",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "10.0.6.201/32"
}
},
{
"table_name": "IP_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "2001:da8:205:1::101/112"
}
}
]
},
{
"object_name": "126_interval_object",
"uuid": "00000000-0000-0000-0000-000000000106",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "CONTENT_SIZE",
"table_type": "interval",
2023-03-27 15:52:47 +08:00
"table_content": {
2024-09-14 11:29:12 +00:00
"interval": "2014-2016"
2023-03-27 15:52:47 +08:00
}
}
]
},
2024-09-14 11:29:12 +00:00
{
"object_name": "TakeMeHome",
"uuid": "00000000-0000-0000-0000-000000000111",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "Take me Home&Batman\\",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "152_mail_addr",
"uuid": "00000000-0000-0000-0000-000000000141",
2024-09-14 11:29:12 +00:00
"items": [
2023-03-27 15:52:47 +08:00
{
"table_type": "expr",
2024-09-14 11:29:12 +00:00
"table_name": "MAIL_ADDR",
2023-03-27 15:52:47 +08:00
"table_content": {
"expression": "^ceshi3@mailhost.cn",
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
2024-09-14 11:29:12 +00:00
},
2023-03-27 15:52:47 +08:00
{
"table_type": "expr",
2024-09-14 11:29:12 +00:00
"table_name": "MAIL_ADDR",
2023-03-27 15:52:47 +08:00
"table_content": {
"expression": "^ceshi6@mailhost.cn",
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "153_expr_object",
"uuid": "00000000-0000-0000-0000-000000000143",
2024-09-14 11:29:12 +00:00
"items": [
2023-03-27 15:52:47 +08:00
{
"table_type": "expr",
2024-09-14 11:29:12 +00:00
"table_name": "MAIL_ADDR",
2023-03-27 15:52:47 +08:00
"table_content": {
"expression": "^ceshi4@mailhost.cn",
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "vt_grp_http_sig1",
"uuid": "00000000-0000-0000-0000-000000000152",
2024-09-14 11:29:12 +00:00
"items": [
{
2024-09-14 11:29:12 +00:00
"table_name": "HTTP_SIGNATURE",
2024-09-26 11:14:06 +00:00
"table_type": "expr",
"table_content": {
2024-09-26 11:14:06 +00:00
"expression": "Chrome/78.0.3904.108",
"expr_type": "and"
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "167_url_object",
"uuid": "00000000-0000-0000-0000-000000000158",
2024-09-14 11:29:12 +00:00
"items": [
2023-03-27 15:52:47 +08:00
{
2024-09-14 11:29:12 +00:00
"table_name": "HTTP_URL",
"table_type": "expr",
2023-03-27 15:52:47 +08:00
"table_content": {
"expression": "2019/12/27",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject199_1",
"uuid": "00000000-0000-0000-0000-000000000189",
2024-09-14 11:29:12 +00:00
"is_exclude": 0,
"items": [
2023-03-27 15:52:47 +08:00
{
2024-09-14 11:29:12 +00:00
"table_name": "HTTP_URL",
2023-03-27 15:52:47 +08:00
"table_type": "expr",
"table_content": {
"expression": "must-contained-string-of-rule-199",
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject199_2",
"uuid": "00000000-0000-0000-0000-000000000190",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
2023-03-27 15:52:47 +08:00
{
2024-09-14 11:29:12 +00:00
"table_name": "HTTP_URL",
"table_type": "expr",
2023-03-27 15:52:47 +08:00
"table_content": {
"expression": "must-not-contained-string-of-rule-199",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject200_1",
"uuid": "00000000-0000-0000-0000-000000000192",
2024-09-14 11:29:12 +00:00
"is_exclude": 0,
"items": [
2023-03-27 15:52:47 +08:00
{
2024-09-14 11:29:12 +00:00
"table_name": "HTTP_URL",
"table_type": "expr",
2023-03-27 15:52:47 +08:00
"table_content": {
"expression": "must-contained-string-of-rule-200",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject200_2",
"uuid": "00000000-0000-0000-0000-000000000193",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
2023-03-27 15:52:47 +08:00
{
2024-09-14 11:29:12 +00:00
"table_name": "HTTP_URL",
"table_type": "expr",
2023-03-27 15:52:47 +08:00
"table_content": {
"expression": "must-not-contained-string-of-rule-200",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
2023-03-27 15:52:47 +08:00
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject202_1",
"uuid": "00000000-0000-0000-0000-000000000195",
2024-09-14 11:29:12 +00:00
"is_exclude": 0,
"items": [
{
2024-09-14 11:29:12 +00:00
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
2024-09-14 11:29:12 +00:00
"ip": "100.64.1.0-100.64.1.20"
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject202_2",
"uuid": "00000000-0000-0000-0000-000000000196",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
{
2024-09-14 11:29:12 +00:00
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
2024-09-14 11:29:12 +00:00
"ip": "100.64.1.6-100.64.1.10"
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject202_3",
"uuid": "00000000-0000-0000-0000-000000000197",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
{
2024-09-14 11:29:12 +00:00
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
2024-09-14 11:29:12 +00:00
"ip": "100.64.1.11-100.64.1.20"
}
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject203_3_1",
"uuid": "00000000-0000-0000-0000-000000000201",
2024-09-14 11:29:12 +00:00
"is_exclude": 0,
"items": [
{
"table_type": "expr",
2024-09-14 11:29:12 +00:00
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "jianshu.com$",
"expr_type": "and"
}
}
]
2022-12-03 22:23:41 +08:00
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject203_3_2",
"uuid": "00000000-0000-0000-0000-000000000202",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
2022-12-03 22:23:41 +08:00
{
2024-09-14 11:29:12 +00:00
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "^www.jianshu.com$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
2022-12-03 22:23:41 +08:00
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject204_3_1_1",
"uuid": "00000000-0000-0000-0000-000000000207",
2024-09-14 11:29:12 +00:00
"is_exclude": 0,
"items": [
2022-12-03 22:23:41 +08:00
{
2024-09-14 11:29:12 +00:00
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "baidu.com$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
2022-12-03 22:23:41 +08:00
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject204_3_1_2",
"uuid": "00000000-0000-0000-0000-000000000208",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
2022-12-03 22:23:41 +08:00
{
2024-09-14 11:29:12 +00:00
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "^www.baidu.com$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
2022-12-03 22:23:41 +08:00
}
]
},
{
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject204_3_2",
"uuid": "00000000-0000-0000-0000-000000000209",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
2022-12-03 22:23:41 +08:00
{
2024-09-14 11:29:12 +00:00
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "^mail.baidu.com$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
2022-12-03 22:23:41 +08:00
}
]
},
2024-09-14 11:29:12 +00:00
{
"object_name": "ExcludeLogicObject217_1_1",
"uuid": "00000000-0000-0000-0000-000000000223",
2024-09-14 11:29:12 +00:00
"is_exclude": 0,
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "string-of-rule-217.com$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
},
{
"object_name": "ExcludeLogicObject217_1_2",
"uuid": "00000000-0000-0000-0000-000000000224",
2024-09-14 11:29:12 +00:00
"is_exclude": 1,
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "www.string-of-rule-217.com",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
],
"object_groups": [
{
"object_uuid": "00000000-0000-0000-0000-000000000500",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000106"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000501",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000141"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000502",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000100"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000503",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000189"
2024-09-14 11:29:12 +00:00
],
"excluded_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000190"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000504",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000192"
2024-09-14 11:29:12 +00:00
],
"excluded_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000193"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000505",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000195"
2024-09-14 11:29:12 +00:00
],
"excluded_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000196",
"00000000-0000-0000-0000-000000000197"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000506",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000201"
2024-09-14 11:29:12 +00:00
],
"excluded_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000202"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000507",
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject204_3_1",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000207"
2024-09-14 11:29:12 +00:00
],
"excluded_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000208"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000508",
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject204_3",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000507"
2024-09-14 11:29:12 +00:00
],
"excluded_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000209"
2024-09-14 11:29:12 +00:00
]
},
{
"object_uuid": "00000000-0000-0000-0000-000000000509",
"included_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000223"
2024-09-14 11:29:12 +00:00
],
"excluded_sub_object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000224"
2024-09-14 11:29:12 +00:00
]
}
],
"rules": [
{
"uuid": "00000000-0000-0000-0000-000000000123",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "escaped\\bdata:have\\ba\\bspace\\band\\ba\\b\\&\\bsymbol.",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_CONFIG",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000100"
2024-09-14 11:29:12 +00:00
]
},
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "123_url_object",
"uuid": "00000000-0000-0000-0000-000000000101",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "abckkk&123",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000124",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_CONFIG",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000100"
2024-09-14 11:29:12 +00:00
]
},
{
"attribute_name": "CONTENT_SIZE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "124_interval_object",
"uuid": "00000000-0000-0000-0000-000000000102",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "CONTENT_SIZE",
"table_type": "interval",
"table_content": {
"interval": "100-500"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000125",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "125_url_object",
"uuid": "00000000-0000-0000-0000-000000000103",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "action=search\\&query=(.*)",
2024-09-14 11:29:12 +00:00
"expr_type": "regex"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000126",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "126_url_object",
"uuid": "00000000-0000-0000-0000-000000000105",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "should_not_hit_any_rule",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "CONTENT_SIZE",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000106"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000128",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "StringScan.ExprPlus",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_SIGNATURE",
2024-09-14 11:29:12 +00:00
"objects": [
{
2024-09-26 11:14:06 +00:00
"object_name": "128_expr_object",
"uuid": "00000000-0000-0000-0000-000000000107",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_SIGNATURE",
2024-09-26 11:14:06 +00:00
"table_type": "expr",
2024-09-14 11:29:12 +00:00
"table_content": {
2024-09-26 11:14:06 +00:00
"expression": "abckkk&123",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000129",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "utf8_中文",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "129_url_object",
"uuid": "00000000-0000-0000-0000-000000000108",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "C#中国",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000130",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "utf8_维语",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "130_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000109",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "2010&يىلىدىكى",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000131",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "utf8_维语2",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "131_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000110",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "سىياسىي",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000132",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "string\\bunescape",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-10-11 06:37:06 +00:00
"object_name": "TakeMeHome",
"object_uuid": "00000000-0000-0000-0000-000000000111"
2024-09-14 11:29:12 +00:00
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000133",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "13018_table_conjunction_test_part1\bnow_its_very_very_long0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefghijklmnopkrstuvwxyz0123456789abcdefg
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "133_host_object",
"uuid": "00000000-0000-0000-0000-000000000112",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_HOST",
"table_type": "expr",
"table_content": {
"expression": "www.3300av.com",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000134",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "table_conjunction_test_part2",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "134_url_object",
"uuid": "00000000-0000-0000-0000-000000000113",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "novel&27122.txt",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000136",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
2024-10-11 06:37:06 +00:00
"effective_range":{},
"action_parameter": "offset_string",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IMAGE_FP",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "136_expr_object",
"uuid": "00000000-0000-0000-0000-000000000114",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IMAGE_FP",
"table_type": "expr",
"table_content": {
"expression": "(offset=4362,depth=4458)|323031333A30333A30372032333A35363A313000323031333A30333A30372032333A35363A3130000000FFE20C584943435F50524F46494C4500010100000C484C696E6F021000006D6E74725247422058595A2007CE00020009000600310000|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000137",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
2024-10-11 06:37:06 +00:00
"effective_range":{},
"action_parameter": "offset_string",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IMAGE_FP",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "137_expr_object",
"uuid": "00000000-0000-0000-0000-000000000115",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IMAGE_FP",
"table_type": "expr",
"table_content": {
"expression": "(offset=19339,depth=19467)|6CB2CB2F2028474C994991CCFC65CCA5E3B6FF001673985D157358610CACC674EE64CC27B5721CCDABD9CCA7C8E9F7BB1F54A930A6034D50F92711F5B2DACCB0715D2E6873CE5CE431DC701A194C260E9DB78CC89F2C84745869AB88349A3AE0412AB59D9ABA84EDEFFF0057FA4DA66D333698B5AD6F844DA2226D1CADAD5E44|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000138",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"effective_range": {"tag_sets":[[{"tag":"location","value":["北京/朝阳/华严北里","上海/浦东/陆家嘴"]},{"tag":"isp","value":["电信","联通"]}],[{"tag":"location","value":["北京"]},{"tag":"isp","value":["联通"]}]]},
"action_parameter": "Not\\baccepted\\btags",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "138_url_object",
"uuid": "00000000-0000-0000-0000-000000000116",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "should&hit&aaa",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000139",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"effective_range": "{\"tag_sets\":[[{\"tag\":\"location\",\"value\":[\"北京/朝阳/华严北里\"]},{\"tag\":\"isp\",\"value\":[\"电信\",\"移动\"]}]]}",
"action_parameter": "Accepted\\btags",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "139_url_object",
"uuid": "00000000-0000-0000-0000-000000000117",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "should&hit&bbb",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000140",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "file_streams",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "140_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000118",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "2018-10-05",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000141",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "Something:I\\bhave\\ba\\bname,7799",
2024-09-14 11:29:12 +00:00
"rule_table_name": "RULE_ALIAS",
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"o2r_table_name": "OBJECT2RULE_ALIAS",
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "141_url_object",
"uuid": "00000000-0000-0000-0000-000000000119",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "i.ytimg.com",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000142",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "StringScan.UTF8EncodedURL",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "142_url_object",
"uuid": "00000000-0000-0000-0000-000000000120",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": ",IgpwcjA0LnN2bzAzKgkxMjcuMC4wLjE",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000143",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.OneRegion",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "143_url_object1",
"uuid": "00000000-0000-0000-0000-000000000121",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-contained-string-of-rule-143",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "143_url_object2",
"uuid": "00000000-0000-0000-0000-000000000122",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-not-contained-string-of-rule-143",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000144",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.ScanNotAtLast",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "144_url_object",
"uuid": "00000000-0000-0000-0000-000000000123",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-contained-string-of-rule-144",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "144_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000124",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "must-not-contained-string-of-rule-144",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000145",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.ScanNotIP",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "145_url_object",
"uuid": "00000000-0000-0000-0000-000000000125",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-contained-string-of-rule-145",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "ATTRIBUTE_IP_CONFIG",
"negate_option": true,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000100"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000146",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.NotExprConditionAndNotIPCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "146_url_object",
"uuid": "00000000-0000-0000-0000-000000000126",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-contained-string-of-rule-146",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "146_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000127",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "must-contained-not-string-of-rule-146",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "ATTRIBUTE_IP_CONFIG",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 2,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000100"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000147",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.8NotCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_1",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "147_keywords_object1",
"uuid": "00000000-0000-0000-0000-000000000128",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition0-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_2",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "147_keywords_object2",
"uuid": "00000000-0000-0000-0000-000000000129",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition1-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_3",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 2,
"objects": [
{
"object_name": "147_keywords_object3",
"uuid": "00000000-0000-0000-0000-000000000130",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition2-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_4",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 3,
"objects": [
{
"object_name": "147_keywords_object4",
"uuid": "00000000-0000-0000-0000-000000000131",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition3-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_5",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 4,
"objects": [
{
"object_name": "147_keywords_object5",
"uuid": "00000000-0000-0000-0000-000000000132",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition4-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_6",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 5,
"objects": [
{
"object_name": "147_keywords_object6",
"uuid": "00000000-0000-0000-0000-000000000133",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition5-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_7",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 6,
"objects": [
{
"object_name": "147_keywords_object7",
"uuid": "00000000-0000-0000-0000-000000000134",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition6-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS_8",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 7,
"objects": [
{
"object_name": "147_keywords_object8",
"uuid": "00000000-0000-0000-0000-000000000135",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "condition7-in-rule-147",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000148",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "StringScan.Regex",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "148_url_object",
"uuid": "00000000-0000-0000-0000-000000000136",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "Cookie:\\s.*head",
2024-09-14 11:29:12 +00:00
"expr_type": "regex"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000150",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "StringScan.BugReport20190325",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "TROJAN_PAYLOAD",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "billgates_regist1",
"uuid": "00000000-0000-0000-0000-000000000138",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "TROJAN_PAYLOAD",
"table_content": {
"expression": "(offset=0,depth=4)|01000000|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "TROJAN_PAYLOAD",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "billgates_regist2",
"uuid": "00000000-0000-0000-0000-000000000139",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "TROJAN_PAYLOAD",
"table_content": {
"expression": "1:G2.40",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000151",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "StringScan.PrefixAndSuffix",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "MAIL_ADDR",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "151_expr_object",
"uuid": "00000000-0000-0000-0000-000000000140",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "MAIL_ADDR",
"table_content": {
"expression": "ceshi3@mailhost.cn$",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000152",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "StringScan.PrefixAndSuffix",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "MAIL_ADDR",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000141"
2024-09-14 11:29:12 +00:00
]
},
{
"attribute_name": "CONTENT_SIZE",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000500"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000153",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "Policy.SubObject",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "MAIL_ADDR",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000143",
"00000000-0000-0000-0000-000000000501"
2024-09-14 11:29:12 +00:00
]
},
{
"attribute_name": "IP_CONFIG",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000502"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000154",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "ipv4_plus",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "154_IP_object",
"uuid": "00000000-0000-0000-0000-000000000145",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "10.0.7.100-10.0.7.101"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000155",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "ipv6_plus",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "155_IP_object",
"uuid": "00000000-0000-0000-0000-000000000146",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "1001:da8:205:1::101-1001:da8:205:1::102"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000157",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "StringScan.StreamScanUTF8",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "TROJAN_PAYLOAD",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "157_expr_object",
"uuid": "00000000-0000-0000-0000-000000000148",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "TROJAN_PAYLOAD",
"table_content": {
"expression": "我的订单",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000158",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "IPScan.IPv4_CIDR",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "158_IP_object",
"uuid": "00000000-0000-0000-0000-000000000149",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "192.168.0.1/32"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000159",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "IPScan.IPv6_CIDR",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "159_IP_object",
"uuid": "00000000-0000-0000-0000-000000000150",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "2001:db8::/120"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000160",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "AttributeWithOnePhysical",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
"negate_option": false,
"object_uuids":[
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000111"
2024-09-14 11:29:12 +00:00
]
},
{
"attribute_name": "HTTP_URL",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "160_url_object",
"uuid": "00000000-0000-0000-0000-000000000151",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "https://blog.csdn.net/littlefang/article/details/8213058",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000163",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "OneObjectInTwoAttribute",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_REQUEST_HEADER",
"negate_option": false,
2024-10-14 02:25:36 +00:00
"objects": [
{
"object_name": "vt_grp_http_sig2",
"uuid": "00000000-0000-0000-0000-000000000153",
"items": [
{
"table_name": "HTTP_SIGNATURE",
"table_type": "expr",
"table_content": {
"expression": "uid=12345678",
"expr_type": "and"
}
},
{
"table_name": "HTTP_SIGNATURE",
"table_type": "expr",
"table_content": {
"expression": "sessionid=888888",
"expr_type": "and"
}
}
]
}
]
2024-09-14 11:29:12 +00:00
},
{
"attribute_name": "HTTP_RESPONSE_HEADER",
"negate_option": false,
2024-10-14 02:25:36 +00:00
"object_name": "vt_grp_http_sig2"
2024-09-14 11:29:12 +00:00
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000164",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "CharsetWindows1251",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "164_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000154",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": ">ЗАО «Севергазвтоматика АйС»<",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000165",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "EvaluationOrder",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"evaluation_order": "2.111",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "165_url_object",
"uuid": "00000000-0000-0000-0000-000000000155",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "cavemancircus.com/",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "165_IP_object",
"uuid": "00000000-0000-0000-0000-000000000156",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "192.168.23.1/24"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000166",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "EvaluationOrder",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"evaluation_order": "100.233",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "166_url_object",
"uuid": "00000000-0000-0000-0000-000000000157",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "2019/12/27/pretty-girls-6",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000167",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "EvaluationOrder",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"evaluation_order": "300.999",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000158"
2024-09-14 11:29:12 +00:00
]
},
{
"attribute_name": "HTTP_URL",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000158"
2024-09-14 11:29:12 +00:00
],
"condition_index": 3
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000168",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "EvaluationOrder",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"evaluation_order": "0",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000158"
2024-09-14 11:29:12 +00:00
],
"condition_index": 2
},
{
"attribute_name": "HTTP_URL",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000158"
2024-09-14 11:29:12 +00:00
],
"condition_index": 6
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000169",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "IPScan.IPv4_Any",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "169_IP_object",
"uuid": "00000000-0000-0000-0000-000000000160",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "100.64.3.1/32"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000170",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "IPScan.IPv4_attribute_name.source",
2024-09-14 11:29:12 +00:00
"is_valid": "no",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "ipv4_attribute_name.source",
"uuid": "00000000-0000-0000-0000-000000000161",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "192.168.40.10/32"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000171",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "IPScan.IPv4_attribute_name.destination",
2024-09-14 11:29:12 +00:00
"is_valid": "no",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "ipv4_attribute_name.destination",
"uuid": "00000000-0000-0000-0000-000000000162",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "192.168.231.46/32"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000177",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.Multiand_conditionsInOneNotCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "ASN_NOT_LOGIC",
"negate_option": true,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000001",
"00000000-0000-0000-0000-000000000003",
"00000000-0000-0000-0000-000000000004"
2024-09-14 11:29:12 +00:00
],
"condition_index": 0
},
{
"attribute_name": "DESTINATION_IP_ASN",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000002"
2024-09-14 11:29:12 +00:00
],
"condition_index": 1
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000178",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "Hierarchy.MultiObjectInOneCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "SOURCE_IP_ASN",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000001",
"00000000-0000-0000-0000-000000000003",
"00000000-0000-0000-0000-000000000004"
2024-09-14 11:29:12 +00:00
],
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 0
},
{
"attribute_name": "DESTINATION_IP_ASN",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000002"
2024-09-14 11:29:12 +00:00
],
"condition_index": 1
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000180",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "Hierarchy.MultiObjectInOneCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"negate_option": false,
"or_conditions":[
{
"attribute_name": "SOURCE_IP_ASN",
"object_uuids": [
"00000000-0000-0000-0000-000000000001",
"00000000-0000-0000-0000-000000000003",
"00000000-0000-0000-0000-000000000004"
]
},
{
"attribute_name": "SOURCE_IP_GEO",
"object_uuids": [
"00000000-0000-0000-0000-000000000015"
]
}
]
2024-09-14 11:29:12 +00:00
},
{
"attribute_name": "IP_CONFIG",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000012"
2024-09-14 11:29:12 +00:00
],
"condition_index": 1
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000181",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.MultiLiteralsInOneNotCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"negate_option": true,
"or_conditions": [
{
"attribute_name": "SOURCE_IP_ASN",
"object_uuids": [
"00000000-0000-0000-0000-000000000001",
"00000000-0000-0000-0000-000000000003",
"00000000-0000-0000-0000-000000000004"
]
},
{
"attribute_name": "IP_PLUS_CONFIG",
"object_uuids": [
"00000000-0000-0000-0000-000000000014"
]
}
]
2024-09-14 11:29:12 +00:00
},
{
"attribute_name": "SOURCE_IP_GEO",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000015"
]
2024-09-14 11:29:12 +00:00
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000182",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "8-expr",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "182_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000167",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "string1&string2&string3&string4&string5&string6&string7&string8",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000184",
"action_parameter": "APP_ID=6006740;Liumengyan-Bugreport-20210515",
2024-09-14 11:29:12 +00:00
"description": "Hulu",
"is_valid": "yes",
"do_blacklist": 0,
"do_log": 0,
"action": 0,
"service": 0,
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "184_IP_object",
"uuid": "00000000-0000-0000-0000-000000000169",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "::/128"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000185",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.SameAttributeInMultiCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"negate_option": true,
"or_conditions": [
{
"attribute_name": "DESTINATION_IP_ASN",
"object_uuids": [
"00000000-0000-0000-0000-000000000001",
"00000000-0000-0000-0000-000000000003",
"00000000-0000-0000-0000-000000000004"
]
},
{
"attribute_name": "SOURCE_IP_GEO",
"object_uuids": [
"00000000-0000-0000-0000-000000000015"
]
}
]
2024-09-14 11:29:12 +00:00
},
{
"attribute_name": "DESTINATION_IP_ASN",
"negate_option": true,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000005"
2022-12-03 22:23:41 +08:00
],
2024-09-14 11:29:12 +00:00
"condition_index": 1
},
{
"attribute_name": "DESTINATION_IP_ASN",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000006"
2024-09-14 11:29:12 +00:00
],
"condition_index": 2
},
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000013"
2024-09-14 11:29:12 +00:00
],
"condition_index": 3
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000186",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.ScanHitAtLast",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "186_expr_object",
"uuid": "00000000-0000-0000-0000-000000000170",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-not-contained-string-of-rule-186",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "186_IP_object",
"uuid": "00000000-0000-0000-0000-000000000171",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "10.0.8.186"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000187",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.ScanHitAtLast",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "187_url_object",
"uuid": "00000000-0000-0000-0000-000000000172",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-not-contained-string-of-rule-187",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "187_IP_object",
"uuid": "00000000-0000-0000-0000-000000000173",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "10.0.8.187"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000188",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NOTLogic.ScanHitAtLast",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "188_url_object",
"uuid": "00000000-0000-0000-0000-000000000174",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "must-not-contained-string-of-rule-188",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "188_IP_object",
"uuid": "00000000-0000-0000-0000-000000000175",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "10.0.8.188"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000189",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"do_log": 0,
"action": 0,
"service": 0,
"do_blacklist": 0,
"action_parameter": "StringScan.ShouldNotHitExprPlus",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "APP_PAYLOAD",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "189_app_object",
"uuid": "00000000-0000-0000-0000-000000000176",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "APP_PAYLOAD",
2024-09-26 11:14:06 +00:00
"table_type": "expr",
2024-09-14 11:29:12 +00:00
"table_content": {
2024-09-26 11:14:06 +00:00
"expression": "|ab00|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000191",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "StringScan.HexBinCaseSensitive",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "191_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000178",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "|54455354|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000192",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "FLAG_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "192_flag_object",
"uuid": "00000000-0000-0000-0000-000000000179",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "flag",
"table_name": "FLAG_CONFIG",
"table_content": {
"flag": 1,
"mask": 3
2024-09-14 11:29:12 +00:00
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000193",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "FLAG_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "193_flag_object",
"uuid": "00000000-0000-0000-0000-000000000180",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "flag",
"table_name": "FLAG_CONFIG",
"table_content": {
"flag": 2,
"mask": 3
2024-09-14 11:29:12 +00:00
}
}
]
}
]
},
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "193_url_object",
"uuid": "00000000-0000-0000-0000-000000000181",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "hello",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000194",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "FLAG_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "194_flag_object",
"uuid": "00000000-0000-0000-0000-000000000182",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "flag",
"table_name": "FLAG_CONFIG",
"table_content": {
"flag": 21,
"mask": 31
2024-09-14 11:29:12 +00:00
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000197",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "Something:I\\bhave\\ba\\bname,8866",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "197_url_object",
"uuid": "00000000-0000-0000-0000-000000000186",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "hqdefault.jpg",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000198",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "Something:I have a name,7799",
2024-09-14 11:29:12 +00:00
"rule_table_name": "RULE_FIREWALL_DEFAULT",
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"o2r_table_name": "OBJECT2RULE_FIREWALL",
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "198_url_object",
"uuid": "00000000-0000-0000-0000-000000000187",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "firewall",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000199",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "ExcludeLogic.ScanNotAtLast",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject199",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000503"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000200",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "ExcludeLogic.OneRegion",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000504"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000202",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "null",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "ATTRIBUTE_IP_PLUS_TABLE",
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject202",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000505"
2024-09-14 11:29:12 +00:00
],
"condition_index": 0
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000203",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "null",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "ATTRIBUTE_IP_PLUS_SOURCE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "ExcludeLogicObject203_1",
"uuid": "00000000-0000-0000-0000-000000000198",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_PLUS_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "192.168.50.43-192.168.50.43"
}
}
]
}
]
},
{
"attribute_name": "ATTRIBUTE_IP_PLUS_DESTINATION",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "ExcludeLogicObject203_2",
"uuid": "00000000-0000-0000-0000-000000000199",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_PLUS_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "47.92.108.93-47.92.108.93"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
2024-09-14 11:29:12 +00:00
"object_name": "ExcludeLogicObject203_3",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000506"
]
2024-09-14 11:29:12 +00:00
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000204",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "null",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "ATTRIBUTE_IP_PLUS_SOURCE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "ExcludeLogicObject204_1",
"uuid": "00000000-0000-0000-0000-000000000203",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_PLUS_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "100.64.2.0-100.64.2.5"
}
}
]
}
]
},
{
"attribute_name": "ATTRIBUTE_IP_PLUS_DESTINATION",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "ExcludeLogicObject204_2",
"uuid": "00000000-0000-0000-0000-000000000204",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_PLUS_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "100.64.2.6-100.64.2.10"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000508"
]
2024-09-14 11:29:12 +00:00
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000205",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "StringScan.RegexExpressionIllegal",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "205_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000210",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "123^456",
2024-09-14 11:29:12 +00:00
"expr_type": "regex"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000206",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "duplicateRuleFor191",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "206_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000211",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "|54455354|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000207",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "duplicateRuleFor192",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "FLAG_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "207_flag_object",
"uuid": "00000000-0000-0000-0000-000000000212",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "flag",
"table_name": "FLAG_CONFIG",
"table_content": {
"flag": 1,
"mask": 3
2024-09-14 11:29:12 +00:00
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000208",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "duplicateRuleFor154",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "208_IP_object",
"uuid": "00000000-0000-0000-0000-000000000213",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "10.0.7.100-10.0.7.106"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000210",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "ipv6_::",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "210_IP_object",
"uuid": "00000000-0000-0000-0000-000000000215",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "::/0"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000211",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "ip_perf_test",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PERF_CONFIG",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "211_IP_object",
"uuid": "00000000-0000-0000-0000-000000000216",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PERF_CONFIG",
"table_content": {
"ip": "10.0.0.1-10.0.0.6"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000212",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "integer_perf_test",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "INTEGER_PERF_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "212_interval_object",
"uuid": "00000000-0000-0000-0000-000000000217",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "INTEGER_PERF_CONFIG",
"table_type": "interval",
"table_content": {
"interval": "3000"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000213",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "expr_perf_test",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "EXPR_LITERAL_PERF_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "213_expr_object",
"uuid": "00000000-0000-0000-0000-000000000218",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "EXPR_LITERAL_PERF_CONFIG",
"table_type": "expr",
"table_content": {
"expression": "today&yesterday",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000214",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "flag_perf_test",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "FLAG_PERF_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "214_flag_object",
"uuid": "00000000-0000-0000-0000-000000000219",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "flag",
"table_name": "FLAG_PERF_CONFIG",
"table_content": {
"flag": 15,
"mask": 15
2024-09-14 11:29:12 +00:00
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000215",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "expr_perf_test",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "EXPR_REGEX_PERF_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "215_expr_object",
"uuid": "00000000-0000-0000-0000-000000000220",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "EXPR_REGEX_PERF_CONFIG",
"table_type": "expr",
"table_content": {
"expression": "action=search\\&query=(.*)",
2024-09-14 11:29:12 +00:00
"expr_type": "regex"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000216",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "NOTCondition&ExcludeObject",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": false,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000504"
2024-09-14 11:29:12 +00:00
],
"condition_index": 0
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject216",
"uuid": "00000000-0000-0000-0000-000000000221",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-for-rule-211",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000217",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "NOTCondition&ExcludeObject",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL_FILTER",
"negate_option": true,
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000509"
2024-09-14 11:29:12 +00:00
],
"condition_index": 0
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject217_2",
"uuid": "00000000-0000-0000-0000-000000000225",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-for-rule-217",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000218",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "CONTENT_SIZE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "218_interval_object",
"uuid": "00000000-0000-0000-0000-000000000226",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "CONTENT_SIZE",
"table_type": "interval",
"table_content": {
"interval": "3000"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000219",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_DUMMY",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_1",
"uuid": "00000000-0000-0000-0000-000000000227",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-1",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_2",
"uuid": "00000000-0000-0000-0000-000000000228",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-2",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 2,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_3",
"uuid": "00000000-0000-0000-0000-000000000229",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-3",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 3,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_4",
"uuid": "00000000-0000-0000-0000-000000000230",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-4",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 4,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_5",
"uuid": "00000000-0000-0000-0000-000000000231",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-5",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 5,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_6",
"uuid": "00000000-0000-0000-0000-000000000232",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-6",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 6,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_7",
"uuid": "00000000-0000-0000-0000-000000000233",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-7",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 7,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject219_8",
"uuid": "00000000-0000-0000-0000-000000000234",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-219-8",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000220",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "anything",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_DUMMY",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject220_1",
"uuid": "00000000-0000-0000-0000-000000000235",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-220-1",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject220_2",
"uuid": "00000000-0000-0000-0000-000000000236",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-220-2",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_DUMMY",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 2,
"objects": [
{
"object_name": "NOTConditionAndExcludeObject220_3",
"uuid": "00000000-0000-0000-0000-000000000237",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "keywords-dummy-220-3",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000222",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "NOTLogic.SingleNotCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_NOT_LOGIC_1",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "NOTLogicObject_222",
"uuid": "00000000-0000-0000-0000-000000000240",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "not_logic_keywords_222",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000223",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "NOTLogic.MultiNotCondition",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_NOT_LOGIC",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "NOTLogicObject_223_1",
"uuid": "00000000-0000-0000-0000-000000000241",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "not_logic_rule_223_1",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_NOT_LOGIC",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "NOTLogicObject_223_2",
"uuid": "00000000-0000-0000-0000-000000000242",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "not_logic_rule_223_2",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_NOT_LOGIC",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 2,
"objects": [
{
"object_name": "NOTLogicObject_223_1",
"uuid": "00000000-0000-0000-0000-000000000243",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "not_logic_rule_223_3",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000224",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "NOTLogic.NotPhysicalTable",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "NOTLogicObject_224_1",
"uuid": "00000000-0000-0000-0000-000000000244",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "not_logic_rule_224_1",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "NOTLogicObject_224_2",
"uuid": "00000000-0000-0000-0000-000000000245",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "not_logic_rule_224_2",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000225",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "Payload escape",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "EscapeObject_225_1",
"uuid": "00000000-0000-0000-0000-000000000246",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "GET / HTTP/1.1\\r\\nHost: www.baidu.com\\r\\n\\r\\n",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000226",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "maat_scan_object",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"object_name": "226_url_object",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000247"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000227",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "maat_scan_object",
2024-09-14 11:29:12 +00:00
"rule_table_name": "RULE_FIREWALL_DEFAULT",
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"object_name": "227_url_object",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000248"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000228",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "NotConditionHitPath",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 1,
"objects": [
{
"object_name": "228_url_object",
"uuid": "00000000-0000-0000-0000-000000000249",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "youtube.com",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
},
{
"attribute_name": "ATTRIBUTE_IP_CONFIG",
"negate_option": true,
2024-09-14 11:29:12 +00:00
"condition_index": 2,
"objects": [
{
"object_name": "228_IP_object",
"uuid": "00000000-0000-0000-0000-000000000250",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "IP_CONFIG",
"table_type": "ip",
"table_content": {
"ip": "192.168.101.102/32"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000229",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "StringScan.Regex",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_URL",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "229_url_object",
"uuid": "00000000-0000-0000-0000-000000000251",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "HTTP_URL",
"table_type": "expr",
"table_content": {
"expression": "É",
2024-09-14 11:29:12 +00:00
"expr_type": "regex"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000230",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "ipv6_::",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "230_IP_object",
"uuid": "00000000-0000-0000-0000-000000000256",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "2607:5d00:2:2::32:28/128",
"port": "80-443"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000231",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "should_not_hit",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "231_IP_object",
"uuid": "00000000-0000-0000-0000-000000000257",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "2607:5d00:2:2::32:28/128",
"port": "80"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000232",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "should_not_hit",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "IP_PLUS_CONFIG",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "232_IP_object",
"uuid": "00000000-0000-0000-0000-000000000258",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "ip",
"table_name": "IP_PLUS_CONFIG",
"table_content": {
"ip": "192.168.30.44/32",
"port": "80"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000233",
2024-09-14 11:29:12 +00:00
"service": 1,
"action": 1,
"do_blacklist": 1,
"do_log": 1,
"action_parameter": "maat_scan_object",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "HTTP_RESPONSE_KEYWORDS",
2024-09-14 11:29:12 +00:00
"object_name": "233_url_object",
"object_uuids": [
2024-09-26 11:14:06 +00:00
"00000000-0000-0000-0000-000000000259"
2024-09-14 11:29:12 +00:00
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000234",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "Payload escape",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "EscapeObject_234_1",
"uuid": "00000000-0000-0000-0000-000000000260",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "html>\\\\r\\\\n",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000235",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "Payload escape",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
"negate_option": false,
2024-09-14 11:29:12 +00:00
"condition_index": 0,
"objects": [
{
"object_name": "EscapeObject_235_1",
"uuid": "00000000-0000-0000-0000-000000000261",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_name": "KEYWORDS_TABLE",
"table_type": "expr",
"table_content": {
"expression": "\\(\\)abc\\^\\$def\\|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
},
{
"uuid": "00000000-0000-0000-0000-000000000236",
2024-09-14 11:29:12 +00:00
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "StringScan.HexBinCombineString",
2024-09-14 11:29:12 +00:00
"is_valid": "yes",
"and_conditions": [
2024-09-14 11:29:12 +00:00
{
"attribute_name": "KEYWORDS_TABLE",
2024-09-14 11:29:12 +00:00
"objects": [
{
"object_name": "236_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000262",
2024-09-14 11:29:12 +00:00
"items": [
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "cd |6162|",
2024-09-14 11:29:12 +00:00
"expr_type": "and"
}
}
]
}
]
}
]
2024-10-24 07:12:57 +00:00
},
{
"uuid": "00000000-0000-0000-0000-000000000237",
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "FileTest.StreamFiles",
"is_valid": "yes",
"and_conditions": [
{
"attribute_name": "KEYWORDS_TABLE",
"objects": [
{
"object_name": "237_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000263",
2024-10-24 07:12:57 +00:00
"items": [
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "处女座从学习寻找自我",
"expr_type": "and"
}
},
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "亦庄",
"expr_type": "and"
}
},
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "金牛座&стейк&Taurus",
"expr_type": "and"
}
},
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "王守仁",
"expr_type": "and"
}
}
]
}
]
}
]
2024-10-25 03:31:55 +00:00
},
{
"uuid": "00000000-0000-0000-0000-000000000238",
"service": 0,
"action": 0,
"do_blacklist": 0,
"do_log": 0,
"action_parameter": "null",
"is_valid": "yes",
"and_conditions": [
{
"attribute_name": "KEYWORDS_TABLE",
"objects": [
{
"object_name": "238_keywords_object",
"uuid": "00000000-0000-0000-0000-000000000264",
"items": [
{
"table_type": "expr",
"table_name": "KEYWORDS_TABLE",
"table_content": {
"expression": "(offset=0,depth=20)|00A12B3CEEFF|",
"expr_type": "and"
}
}
]
}
]
}
]
2024-09-14 11:29:12 +00:00
}
],
"plugin_table": [
{
"table_name": "QD_ENTRY_INFO",
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000001", "ip":"192.168.0.1", "entry_id":101, "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000002", "ip":"192.168.0.2", "entry_id":102, "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000003", "ip":"192.168.1.1", "entry_id":103, "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_PLUGIN_EXDATA_TABLE",
2024-09-14 11:29:12 +00:00
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000001", "key":"HeBei", "city":"Shijiazhuang", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000002", "key":"HeNan", "city":"Zhengzhou", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000003", "key":"ShanDong", "city":"Jinan", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000004", "key":"ShanXi", "city":"Taiyuan", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_PLUGIN_LONG_KEY_TYPE_TABLE",
2024-09-14 11:29:12 +00:00
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000001", "key":11111111, "city":"Shijiazhuang", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000002", "key":22222222, "city":"Zhengzhou", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000003", "key":33333333, "city":"Jinan", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000004", "key":44444444, "city":"Taiyuan", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_PLUGIN_INT_KEY_TYPE_TABLE",
2024-09-14 11:29:12 +00:00
"table_content": [
{ "uuid":"00000000-0000-0000-0000-000000000001", "key":101, "city":"China", "is_valid":1},
{ "uuid":"00000000-0000-0000-0000-000000000002", "key":102, "city":"America", "is_valid":1},
{ "uuid":"00000000-0000-0000-0000-000000000003", "key":103, "city":"Russia", "is_valid":1},
{ "uuid":"00000000-0000-0000-0000-000000000004", "key":104, "city":"Japan", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_PLUGIN_IP_KEY_TYPE_TABLE",
2024-09-14 11:29:12 +00:00
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000001", "key":"100.64.1.1", "addr_type":4, "city":"XiZang", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000002", "key":"100.64.1.2", "addr_type":4, "city":"XinJiang", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000003", "key":"2001:da8:205:1::101", "addr_type":6, "city":"GuiZhou", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000004", "key":"1001:da8:205:1::101", "addr_type":6, "city":"SiChuan", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000005", "key":"100.64.1.3", "addr_type":7, "city":"QingHai", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000006", "key":"100.64.1.4", "addr_type":6, "city":"GanSu", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_IP_PLUGIN_WITH_EXDATA",
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000101", "ip":"192.168.30.99-192.168.30.101", "buffer":"Something-like-json", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000102", "ip":"192.168.30.90-192.168.30.128", "buffer":"Bigger-range-should-in-the-back", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000103", "ip":"2001:db8:1234::-2001:db8:1235::", "buffer":"Bigger-range-should-in-the-back", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000104", "ip":"2001:db8:1234::1-2001:db8:1234::5210", "buffer":"Something-like-json", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000105", "ip":"2620:100:3000::-2620:0100:30ff:ffff:ffff:ffff:ffff:ffff", "buffer":"Bugreport-liumengyan-20210517", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_IPPORT_PLUGIN_WITH_EXDATA",
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000101", "ip":"192.168.100.1", "port":"0-255", "is_valid":1},
2024-10-17 06:37:29 +00:00
{"uuid":"00000000-0000-0000-0000-000000000102", "ip":"192.168.100.2-192.168.100.5", "port":"100-200", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000103", "ip":"192.168.100.1", "port":"255-300", "is_valid":1},
2024-10-17 06:37:29 +00:00
{"uuid":"00000000-0000-0000-0000-000000000104", "ip":"2001:db8:1234::5210-2001:db8:1234::5215", "port":"255-512", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_FQDN_PLUGIN_WITH_EXDATA",
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000201", "fqdn":"www.example1.com", "buffer":"catid=1", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000202", "fqdn":"*.example1.com", "buffer":"catid=1", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000203", "fqdn":"news.example1.com", "buffer":"catid=2", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000204", "fqdn":"r3---sn-i3belne6.example2.com", "buffer":"catid=3", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000205", "fqdn":"r3---sn-i3belne6.example2.com", "buffer":"catid=3", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_BOOL_PLUGIN_WITH_EXDATA",
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000301", "bool_expr":"1&2&1000", "buffer":"tunnel1", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000302", "bool_expr":"101&102", "buffer":"tunnel2", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000303", "bool_expr":"102", "buffer":"tunnel3", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000304", "bool_expr":"101", "buffer":"tunnel4", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000305", "bool_expr":"0&1&2&3&4&5&6&7", "buffer":"tunnel5", "is_valid":1},
{"uuid":"00000000-0000-0000-0000-000000000306", "bool_expr":"101&101", "buffer":"invalid", "is_valid":1}
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "TEST_EFFECTIVE_RANGE_TABLE",
2024-09-14 11:29:12 +00:00
"table_content": [
{"uuid":"00000000-0000-0000-0000-000000000001", "status":"SUCCESS", "entry_id":99, "is_valid":1, "effective_range":{"tag_sets":[[{"tag":"location","value":["北京/朝阳/华严北里"]},{"tag":"isp","value":["电信","移动"]}]]} },
{"uuid":"00000000-0000-0000-0000-000000000002", "status":"SUCCESS", "entry_id":66, "is_valid":1, "effective_range":0},
{"uuid":"00000000-0000-0000-0000-000000000003", "status":"FAILED", "entry_id":11, "is_valid":1, "effective_range":{"tag_sets":[[{"tag":"location","value":["北京/朝阳/华严北里","上海/浦东/陆家嘴"]},{"tag":"isp","value":["电信","联通"]}], [{"tag":"location","value":["北京"]},{"tag":"isp","value":["联通"]}]]} },
{"uuid":"00000000-0000-0000-0000-000000000004", "status":"SUCCESS", "entry_id":66, "is_valid":1, "effective_range":{} },
{"uuid":"00000000-0000-0000-0000-000000000005", "status":"SUCCESS", "entry_id":66, "is_valid":1, "effective_range":{"tag_sets":[[{"tag":"location","value":["北京"]}]]} },
{"uuid":"00000000-0000-0000-0000-000000000006", "status":"SUCCESS", "entry_id":66, "is_valid":1, "effective_range":{"tag_sets":[[{"tag":"weather","value":["hot"]}]]} }
2024-09-14 11:29:12 +00:00
]
},
{
"table_name": "IR_INTERCEPT_IP",
2024-09-14 11:29:12 +00:00
"table_content": [
{ "uuid":"00000000-0000-0000-0000-001000000130", "is_valid":1, "effective_range":{}},
{ "uuid":"00000000-0000-0000-0000-000000000161", "is_valid":1, "effective_range":0}
2024-09-14 11:29:12 +00:00
]
}
]
2023-03-27 15:52:47 +08:00
}