Skip to content

Commit 4f0cd70

Browse files
Update application-gateway-crs-rulegroups-rules.md
Adding the subsection about upgrading rulesets.
1 parent 27d3984 commit 4f0cd70

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

articles/web-application-firewall/ag/application-gateway-crs-rulegroups-rules.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -101,6 +101,10 @@ If the anomaly score is 5 or greater, and the WAF is in Prevention mode, the req
101101

102102
For example, a single *Critical* rule match is enough for the WAF to block a request when in Prevention mode, because the overall anomaly score is 5. However, one *Warning* rule match only increases the anomaly score by 3, which isn't enough by itself to block the traffic. When an anomaly rule is triggered, it shows a "Matched" action in the logs. If the anomaly score is 5 or greater, there is a separate rule triggered with either "Blocked" or "Detected" action depending on whether WAF policy is in Prevention or Detection mode. For more information, please see [Anomaly Scoring mode](ag-overview.md#anomaly-scoring-mode).
103103

104+
### Upgrading Rulesets
105+
106+
Note...
107+
104108
### DRS 2.1
105109

106110
DRS 2.1 rules offer better protection than earlier versions of the DRS. It includes more rules developed by the Microsoft Threat Intelligence team and updates to signatures to reduce false positives. It also supports transformations beyond just URL decoding.

0 commit comments

Comments
 (0)