-
Notifications
You must be signed in to change notification settings - Fork 30
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: add quantitative testing #355
Conversation
3fc916a
to
1dcebc6
Compare
9ad2906
to
6de43c0
Compare
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
6de43c0
to
32bd0e9
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Really cool!
Co-authored-by: Max Leske <250711+theseion@users.noreply.github.com>
Could you please link some basic theoretical explanation to this issue to outline the motivation standing behind this PR. |
Well, I don't know if there is any "theoretical" explanation here, other than plain numbers. We take a bunch of standard (meaning it doesn't contain attacks) text grabbed from the internet, and we run it against CRS. We get the percentage of the text that matches certain rules. If you modify a rule and the numbers go up, your change will get more false positives. That's the gist of quantitative testing around rules. |
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
df968f9
to
b921abe
Compare
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
b921abe
to
56d047d
Compare
BTW, this is experimental until we have a good notion on what output we want from the tool. |
@fzipi there are still two unresolved comments from the previous review. |
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
I always fall in the hidden comments 🤦 |
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
d742042
to
81f0e99
Compare
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
|
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
Co-authored-by: Max Leske <250711+theseion@users.noreply.github.com>
Signed-off-by: Felipe Zipitria <felipe.zipitria@owasp.org>
what
why
future