Applies To:Show Versions
BIG-IQ Centralized Management
Security Dimensions and Metrics
Web Application Security Dimensions
- BIG-IP Host Names
- The name of each BIG-IP system that processed the monitored transactions.
- BIG-IP Blade Numbers
- The individual blades (by number) for all monitored BIG-IP devices.
- The name of each application reporting HTTP traffic data.
- Application Services
- The name of each HTTP application service reporting transaction data.
- Virtual Servers
- The name of each virtual server that processes monitored transactions.
- ASM Policy Names
- The names of the Web Application Security (ASM) policies that protect the virtual servers currently processing application traffic.
- The enforcement applied to a detected attack signature. These actions include:
- Violation Ratings
- The rating assigned to traffic by the Web Application Security policy. The assigned ratings include:
- Legal, normal traffic that does not contain any threat indicators.
- Legal (Staging), traffic that is tentatively detected as legal during the policy builder process. The relevant settings in the security policy are in staging.
- Likely F.P., traffic may present a security threat, but is likely a false positive.
- Illegal, traffic that contains known violations, or abnormalities, that pose a threat to the application's performance.
- Malicious, traffic that contains known threat actors.
- Network Protocols
- The network protocol (HTTP, HTTPS) in the transaction.
- Client IPs
- The client IP address that initiated the HTTP request that was processed by the BIG-IP system.
- Attack Types
- The general category of application-layer attack, as identified by the Web Application Security policy.
- The types of traffic violations, as detected by your Web Application Security policy.
- Virus Names
- The names of known viruses detected.
- Client Device IDs
- IP Reputation
- The IP categories configured for IP Intelligence. This dimension is relevant to users who have configured an ASM policy with IP Intelligence.
- The country listed in the HTTP request that was processed by the BIG-IP system.
- User Name
- The client login name, based on information submitted from a login page. This information is available when Web Application Service is paired with Access service.
- Session ID
- The unique identifier of an HTTP session between the client and the application. This information is stored along with other client data, such as device ID.
- The URL that initiated the HTTP request that was processed by the BIG-IP system.
- Response Code Families
- The class of the HTTP response result received by the BIG-IP system.
- The HTTP method included in the HTTP request received by the BIG-IP system.
Web Application Security Metrics
Metric Set Definition
Each initiated request between the client and BIG-IP system, regardless of the outcome.
Depending on your configuration of Web Application Security, not all legal transactions are included in the transaction totals.
Average number of transactions per second that were processed by the BIG-IP system.
Total number of transactions processed by the BIG-IP system.
The number of violations detected by the Web Application Security policy.
The average number of violations detected per second.
The total number of violations detected over the selected period of time