CSP-Reports: Best Practice to handle false positive csp-reports with logstash

Viewed 91

We have created an endpoint in logstash for our CSP-Reports. As is well known, there is also the problem that a lot of reports come in here that are actually garbage or also not reproducible. Like https://github.com/nico3333fr/CSP-useful/tree/master/csp-wtf

Our system checks every 30 minutes if a new CSP report has come in. If so, an email is sent to the system administration. This is because it could be that relevant content is being blocked. The website is very complex and also very dynamic in terms of content.

Ideally, only relevant CSP reports should pass through the logstash pipeline, triggering an email notification.

So far I filter mainly based on the (csp-report.blocked-uri and the csp-report.violated-directive) in the filter of the pipeline. But this is very ineffective and like a fight against windmills.

Are there any other and maybe more up-to-date best practices to filter out the unnecessary reports using the filters in logstash? This article is good, but also quite a few years old: https://matatall.com/csp/twitter/2014/07/25/twitters-csp-report-collector-design.html

0 Answers
Related