Traffic Generator
What This Provides
Section titled “What This Provides”The Traffic Generator produces controlled attack traffic, reconnaissance scans, bot simulations, API abuse patterns, and browser-driven Client-Side Defense scenarios against an F5 Distributed Cloud HTTP load balancer. Choose either the existing Azure deployment or the independent AWS deployment. They share suite intent, but they do not imply cloud, runtime, or detection parity.
The Azure path provisions its established toolset with cloud-init. The AWS path uses a public-subnet
worker with an explicit Elastic IP, SSH restricted to the operator jumpbox’s current public /32,
Systems Manager recovery, immutable source and runtime inputs, and sanitized browser evidence. A
completed browser scenario proves execution and evidence capture; it does not guarantee a corresponding
F5 Distributed Cloud detection.
For AWS Client-Side Defense, csd-violations is the only maintained suite. Other suite entries below describe the existing Azure deployment.
Traffic Suite Categories
Section titled “Traffic Suite Categories”| Suite | Description | F5 XC Feature Validated |
|---|---|---|
| api-attacks | OWASP API Top 10, SQLMap API mode, parameter discovery, endpoint fuzzing | API Security |
| bot-simulation | Headless Chrome, Puppeteer stealth, Playwright automation, rapid crawling | Bot Defense |
| cdn-load-testing | Cache behavior, thundering herd, connection pool, HTTP/2 multiplexing | CDN Integration |
| crapi-exploits | BOLA, OTP bruteforce, JWT manipulation, SSRF, NoSQL injection, IDOR | API Security |
| csd-violations | Eleven controlled, sanitized browser scenarios with per-step evidence | Client-Side Defense |
| dvga-exploits | Batch query DoS, deep recursion, SQL injection, introspection abuse | API Security (GraphQL) |
| dvwa-exploits | Brute force, command injection, CSRF, file inclusion, SQLi, XSS | WAF |
| juice-shop-exploits | SQLi login bypass, XSS, IDOR, admin access, null byte file access | WAF, Bot Defense |
| mitre-attack | ATT&CK tactics: recon, initial access, credential access, exfiltration | WAF, Bot Defense, API Security |
| owasp-scanning | ZAP, Nikto, Nuclei, Nmap vulnerability scanning, combined OWASP report | WAF, Web App Scanning |
| performance-testing | Concurrency ramp, sustained load, spike testing, breakpoint discovery | DDoS, Rate Limiting |
| reconnaissance | Nmap, Masscan, Gobuster, Subfinder, directory brute-forcing | WAF / Bot Defense |
| restaurant-exploits | BOLA, BOPLA, BFLA, rate limiting bypass, JWT weak secret | API Security |
| ssl-scanning | SSLScan, sslyze, testssl.sh TLS configuration analysis | WAF |
| traffic-generation | High-volume legitimate HTTP traffic for baseline and load testing | All |
| waf-encoding-evasion | Multi-layer URL/HTML/Unicode encoding, mixed nested encoding, chunked Transfer-Encoding, header injection | WAF |
| web-app-attacks | SQL injection, XSS, command injection, path traversal, Nikto, Nuclei | WAF |
| demoapp-attacks | SQLi, XSS, path traversal against F5 DemoApp WAF testing endpoints | WAF |