-
Notifications
You must be signed in to change notification settings - Fork 291
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add exclusions for openid4java and seasar frameworks #7417
Merged
manuel-alvarez-alvarez
merged 1 commit into
master
from
malvarez/iast-exclude-openid4java
Aug 13, 2024
Merged
Add exclusions for openid4java and seasar frameworks #7417
manuel-alvarez-alvarez
merged 1 commit into
master
from
malvarez/iast-exclude-openid4java
Aug 13, 2024
+2
−0
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
manuel-alvarez-alvarez
added
the
comp: asm iast
Application Security Management (IAST)
label
Aug 13, 2024
smola
approved these changes
Aug 13, 2024
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 48 metrics, 15 unstable metrics. Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.053 s) : 0, 1052568
Total [baseline] (10.385 s) : 0, 10385130
Agent [candidate] (1.046 s) : 0, 1046233
Total [candidate] (10.375 s) : 0, 10374653
section appsec
Agent [baseline] (1.168 s) : 0, 1167836
Total [baseline] (10.488 s) : 0, 10488412
Agent [candidate] (1.169 s) : 0, 1169073
Total [candidate] (10.467 s) : 0, 10466588
section iast
Agent [baseline] (1.176 s) : 0, 1175520
Total [baseline] (10.812 s) : 0, 10812083
Agent [candidate] (1.174 s) : 0, 1174027
Total [candidate] (10.781 s) : 0, 10781327
section profiling
Agent [baseline] (1.244 s) : 0, 1244054
Total [baseline] (10.636 s) : 0, 10636380
Agent [candidate] (1.244 s) : 0, 1244088
Total [candidate] (10.589 s) : 0, 10589490
gantt
title petclinic - break down per module: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (671.953 ms) : 0, 671953
BytebuddyAgent [candidate] (667.336 ms) : 0, 667336
GlobalTracer [baseline] (307.673 ms) : 0, 307673
GlobalTracer [candidate] (306.424 ms) : 0, 306424
AppSec [baseline] (51.222 ms) : 0, 51222
AppSec [candidate] (50.875 ms) : 0, 50875
Remote Config [baseline] (695.265 µs) : 0, 695
Remote Config [candidate] (687.48 µs) : 0, 687
Telemetry [baseline] (7.521 ms) : 0, 7521
Telemetry [candidate] (7.485 ms) : 0, 7485
section appsec
BytebuddyAgent [baseline] (677.25 ms) : 0, 677250
BytebuddyAgent [candidate] (677.801 ms) : 0, 677801
GlobalTracer [baseline] (299.731 ms) : 0, 299731
GlobalTracer [candidate] (300.441 ms) : 0, 300441
AppSec [baseline] (156.637 ms) : 0, 156637
AppSec [candidate] (156.608 ms) : 0, 156608
Remote Config [baseline] (598.7 µs) : 0, 599
Remote Config [candidate] (607.365 µs) : 0, 607
Telemetry [baseline] (8.72 ms) : 0, 8720
Telemetry [candidate] (9.013 ms) : 0, 9013
IAST [baseline] (22.867 ms) : 0, 22867
IAST [candidate] (22.2 ms) : 0, 22200
section iast
BytebuddyAgent [baseline] (781.674 ms) : 0, 781674
BytebuddyAgent [candidate] (780.484 ms) : 0, 780484
GlobalTracer [baseline] (296.08 ms) : 0, 296080
GlobalTracer [candidate] (295.777 ms) : 0, 295777
AppSec [baseline] (53.346 ms) : 0, 53346
AppSec [candidate] (51.533 ms) : 0, 51533
Remote Config [baseline] (577.527 µs) : 0, 578
Remote Config [candidate] (619.151 µs) : 0, 619
Telemetry [baseline] (7.107 ms) : 0, 7107
Telemetry [candidate] (7.947 ms) : 0, 7947
IAST [baseline] (23.286 ms) : 0, 23286
IAST [candidate] (24.214 ms) : 0, 24214
section profiling
BytebuddyAgent [baseline] (662.475 ms) : 0, 662475
BytebuddyAgent [candidate] (663.15 ms) : 0, 663150
GlobalTracer [baseline] (389.896 ms) : 0, 389896
GlobalTracer [candidate] (389.749 ms) : 0, 389749
AppSec [baseline] (52.1 ms) : 0, 52100
AppSec [candidate] (52.01 ms) : 0, 52010
Remote Config [baseline] (687.111 µs) : 0, 687
Remote Config [candidate] (684.877 µs) : 0, 685
Telemetry [baseline] (7.362 ms) : 0, 7362
Telemetry [candidate] (7.389 ms) : 0, 7389
ProfilingAgent [baseline] (94.36 ms) : 0, 94360
ProfilingAgent [candidate] (93.976 ms) : 0, 93976
Profiling [baseline] (94.384 ms) : 0, 94384
Profiling [candidate] (94.0 ms) : 0, 94000
Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.046 s) : 0, 1046418
Total [baseline] (8.471 s) : 0, 8470708
Agent [candidate] (1.043 s) : 0, 1043211
Total [candidate] (8.505 s) : 0, 8504827
section iast
Agent [baseline] (1.174 s) : 0, 1173507
Total [baseline] (8.938 s) : 0, 8937733
Agent [candidate] (1.186 s) : 0, 1186108
Total [candidate] (9.014 s) : 0, 9013919
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.174 s) : 0, 1174346
Total [baseline] (8.948 s) : 0, 8947862
Agent [candidate] (1.174 s) : 0, 1174095
Total [candidate] (8.981 s) : 0, 8981402
section iast_TELEMETRY_OFF
Agent [baseline] (1.173 s) : 0, 1172872
Total [baseline] (8.979 s) : 0, 8978956
Agent [candidate] (1.172 s) : 0, 1171866
Total [candidate] (8.963 s) : 0, 8962785
gantt
title insecure-bank - break down per module: candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (667.941 ms) : 0, 667941
BytebuddyAgent [candidate] (665.096 ms) : 0, 665096
GlobalTracer [baseline] (305.971 ms) : 0, 305971
GlobalTracer [candidate] (305.621 ms) : 0, 305621
AppSec [baseline] (50.913 ms) : 0, 50913
AppSec [candidate] (50.894 ms) : 0, 50894
Remote Config [baseline] (688.286 µs) : 0, 688
Remote Config [candidate] (684.503 µs) : 0, 685
Telemetry [baseline] (7.516 ms) : 0, 7516
Telemetry [candidate] (7.521 ms) : 0, 7521
section iast
BytebuddyAgent [baseline] (780.799 ms) : 0, 780799
BytebuddyAgent [candidate] (789.347 ms) : 0, 789347
GlobalTracer [baseline] (295.354 ms) : 0, 295354
GlobalTracer [candidate] (298.34 ms) : 0, 298340
AppSec [baseline] (54.052 ms) : 0, 54052
AppSec [candidate] (52.82 ms) : 0, 52820
IAST [baseline] (22.239 ms) : 0, 22239
IAST [candidate] (24.24 ms) : 0, 24240
Remote Config [baseline] (587.348 µs) : 0, 587
Remote Config [candidate] (589.283 µs) : 0, 589
Telemetry [baseline] (7.045 ms) : 0, 7045
Telemetry [candidate] (7.196 ms) : 0, 7196
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (781.572 ms) : 0, 781572
BytebuddyAgent [candidate] (780.686 ms) : 0, 780686
GlobalTracer [baseline] (296.633 ms) : 0, 296633
GlobalTracer [candidate] (296.612 ms) : 0, 296612
AppSec [baseline] (51.728 ms) : 0, 51728
AppSec [candidate] (51.092 ms) : 0, 51092
IAST [baseline] (22.336 ms) : 0, 22336
IAST [candidate] (22.775 ms) : 0, 22775
Remote Config [baseline] (579.328 µs) : 0, 579
Remote Config [candidate] (595.333 µs) : 0, 595
Telemetry [baseline] (7.982 ms) : 0, 7982
Telemetry [candidate] (8.809 ms) : 0, 8809
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (778.957 ms) : 0, 778957
BytebuddyAgent [candidate] (778.259 ms) : 0, 778259
GlobalTracer [baseline] (296.238 ms) : 0, 296238
GlobalTracer [candidate] (296.699 ms) : 0, 296699
AppSec [baseline] (50.781 ms) : 0, 50781
AppSec [candidate] (52.283 ms) : 0, 52283
IAST [baseline] (25.683 ms) : 0, 25683
IAST [candidate] (23.571 ms) : 0, 23571
Remote Config [baseline] (627.162 µs) : 0, 627
Remote Config [candidate] (595.404 µs) : 0, 595
Telemetry [baseline] (7.09 ms) : 0, 7090
Telemetry [candidate] (6.957 ms) : 0, 6957
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 17 unstable metrics. Request duration reports for petclinicgantt
title petclinic - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section baseline
no_agent (1.339 ms) : 1320, 1358
. : milestone, 1339,
appsec (1.714 ms) : 1690, 1738
. : milestone, 1714,
appsec_no_iast (1.697 ms) : 1672, 1722
. : milestone, 1697,
iast (1.476 ms) : 1454, 1498
. : milestone, 1476,
profiling (1.48 ms) : 1456, 1505
. : milestone, 1480,
tracing (1.469 ms) : 1445, 1493
. : milestone, 1469,
section candidate
no_agent (1.34 ms) : 1321, 1360
. : milestone, 1340,
appsec (1.714 ms) : 1691, 1738
. : milestone, 1714,
appsec_no_iast (1.723 ms) : 1699, 1747
. : milestone, 1723,
iast (1.483 ms) : 1460, 1506
. : milestone, 1483,
profiling (1.508 ms) : 1482, 1534
. : milestone, 1508,
tracing (1.459 ms) : 1434, 1484
. : milestone, 1459,
Request duration reports for insecure-bankgantt
title insecure-bank - request duration [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section baseline
no_agent (359.226 µs) : 339, 379
. : milestone, 359,
iast (473.582 µs) : 452, 495
. : milestone, 474,
iast_FULL (550.188 µs) : 528, 573
. : milestone, 550,
iast_GLOBAL (501.06 µs) : 478, 524
. : milestone, 501,
iast_HARDCODED_SECRET_DISABLED (469.156 µs) : 448, 490
. : milestone, 469,
iast_INACTIVE (457.979 µs) : 436, 480
. : milestone, 458,
iast_TELEMETRY_OFF (461.395 µs) : 441, 482
. : milestone, 461,
tracing (435.267 µs) : 415, 456
. : milestone, 435,
section candidate
no_agent (369.839 µs) : 350, 389
. : milestone, 370,
iast (473.406 µs) : 452, 495
. : milestone, 473,
iast_FULL (543.868 µs) : 522, 566
. : milestone, 544,
iast_GLOBAL (506.115 µs) : 484, 529
. : milestone, 506,
iast_HARDCODED_SECRET_DISABLED (473.739 µs) : 453, 495
. : milestone, 474,
iast_INACTIVE (452.0 µs) : 430, 474
. : milestone, 452,
iast_TELEMETRY_OFF (471.288 µs) : 450, 493
. : milestone, 471,
tracing (440.242 µs) : 419, 462
. : milestone, 440,
DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 12 metrics, 0 unstable metrics. Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section baseline
no_agent (15.471 s) : 15471000, 15471000
. : milestone, 15471000,
appsec (15.082 s) : 15082000, 15082000
. : milestone, 15082000,
iast (18.81 s) : 18810000, 18810000
. : milestone, 18810000,
iast_GLOBAL (17.929 s) : 17929000, 17929000
. : milestone, 17929000,
profiling (15.276 s) : 15276000, 15276000
. : milestone, 15276000,
tracing (15.014 s) : 15014000, 15014000
. : milestone, 15014000,
section candidate
no_agent (15.224 s) : 15224000, 15224000
. : milestone, 15224000,
appsec (15.106 s) : 15106000, 15106000
. : milestone, 15106000,
iast (18.905 s) : 18905000, 18905000
. : milestone, 18905000,
iast_GLOBAL (17.818 s) : 17818000, 17818000
. : milestone, 17818000,
profiling (15.24 s) : 15240000, 15240000
. : milestone, 15240000,
tracing (15.161 s) : 15161000, 15161000
. : milestone, 15161000,
Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.39.0-SNAPSHOT~ca5db118ab, baseline=1.39.0-SNAPSHOT~594de2e160
dateFormat X
axisFormat %s
section baseline
no_agent (1.467 ms) : 1455, 1478
. : milestone, 1467,
appsec (2.217 ms) : 2182, 2252
. : milestone, 2217,
iast (1.956 ms) : 1914, 1997
. : milestone, 1956,
iast_GLOBAL (2.017 ms) : 1975, 2060
. : milestone, 2017,
profiling (1.852 ms) : 1818, 1885
. : milestone, 1852,
tracing (1.854 ms) : 1821, 1886
. : milestone, 1854,
section candidate
no_agent (1.466 ms) : 1454, 1477
. : milestone, 1466,
appsec (2.22 ms) : 2186, 2255
. : milestone, 2220,
iast (1.978 ms) : 1935, 2020
. : milestone, 1978,
iast_GLOBAL (2.019 ms) : 1976, 2062
. : milestone, 2019,
profiling (1.86 ms) : 1826, 1894
. : milestone, 1860,
tracing (1.847 ms) : 1814, 1880
. : milestone, 1847,
|
smola
pushed a commit
that referenced
this pull request
Aug 13, 2024
(cherry picked from commit 8b3304e)
5 tasks
smola
added a commit
that referenced
this pull request
Aug 14, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What Does This Do
Adds IAST exclusions for
org.openid4java
andorg.seasar
Motivation
We've seen issues in one customer related to classes that get instrumented by IAST, since it provides no value it's better to exclude them.
Additional Notes
Contributor Checklist
type:
and (comp:
orinst:
) labels in addition to any usefull labelsclose
,fix
or any linking keywords when referencing an issue.Use
solves
instead, and assign the PR milestone to the issueJira ticket: [PROJ-IDENT]