DEV Community

AerieWhole123
AerieWhole123

Posted on

Tutorial and User Experience on Activating Dynamic Protection in Safeline WAF

Dynamic Protection is a new feature introduced in version [6.0.0] of Safeline WAF Community Edition, part of advanced site protection. Its main function is to automatically encrypt the HTML and JavaScript source code of websites dynamically, aimed at preventing analysis by web crawlers and automated attacks. This feature is marked as BETA in version [6.0.0], indicating it may still be in the testing phase but is already available for user access.
The implementation of the Dynamic Protection feature relies on the newly added safeline-chaos container. This container specifically processes the website's source code, employing encryption techniques to make it difficult for automated tools to parse and simulate normal user behavior, thereby enhancing website security.

Here is the specific description of the Dynamic Protection feature:
Dynamic Protection (BETA): Automatically encrypts the HTML and JavaScript source code of websites dynamically to prevent analysis by web crawlers and automated attack programs.
New Container: The safeline-chaos container has been introduced to support the Dynamic Protection feature.

Activation Tutorial:

  1. Begin by upgrading Safeline WAF to the latest version.
    Image description

  2. Click on "Sites", then navigate to "Website" to access "DYNAMIC".
    Image description

  3. After clicking on Dynamic , a popup will appear. Check the recommended options and then click SAVE.
    Image description

  4. After saving, the Dynamic Protection button will turn green, indicating it is enabled.

Effect:
When accessing the website's backend management, you will encounter Safeline WAF decryption prompts. I find this design excellent as it notifies website administrators that Safeline WAF Dynamic Protection is enabled.
Image description

Top comments (0)