Skip to content

[Bot detection] Add a second kind of fingerprint collection #4662

Description

@Dryusdan

What would you like to be added?

/kind feature

I was really looking forward to the bot detection feature.
But, the fingerprint collection require Javascript (and maybe someday can be spoofed ?).
Also, javascript requirement can be a blocker for some users who disable Javascript or some reader that don't implement it.

I think, adding a TLS fingerprint (like ja4 and not ja4+) with matching user_agent and fingerprint to determine if user can access or not (without javascript) and let admin choose if tls fingerprint is require, device fingerprint or both

Why is this needed?

This is needed to no discriminate some users, device or something else and (maybe) make Crowdsec’s WAF even more secure

PS : another haproxy ressource : https://github.com/O-X-L/haproxy-ja4-fingerprint ^^

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions