pyrasp
is a Runtime Application Self Protection package for Python-based Web Servers (Flask, FastAPI and Django) and Serverless Functions (AWS Lambda, Azure and Google Cloud Functions). It protects against the main attacks web applications are exposed to, from within the application. It is also capable of providing basic telemetry such as cpu and memory usage, as well as requests count. Additionally, pyrasp
implements Zero-Trust Application Access for critical applications, ensuring only up-to-date authorized browsers can connect.
It can operate using a local configuration file or get it from a remote/cloud server. Logs and telemetry (optional) can be sent to remote servers as well, and threats information can be shared across agents.
One specificity of pyrasp
relies on the fact that it does not use signatures. Instead it will leverage decoys, thresholds, system and application internals, machine learning and grammatical analysis.
Version 0.8.3 is not provided for AWS Lambda Functions. Support will be provided in next version.
Full documentation
Release Notes
Web Site
Renaud Bidou - renaud@paracyberbellum.io