{"id":11692,"date":"2021-02-22T06:00:17","date_gmt":"2021-02-22T11:00:17","guid":{"rendered":"https:\/\/blog.litespeedtech.com\/?p=11692"},"modified":"2021-02-22T06:00:17","modified_gmt":"2021-02-22T11:00:17","slug":"asynchronous-modsecurity-engine","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2021\/02\/22\/asynchronous-modsecurity-engine\/","title":{"rendered":"Asynchronous ModSecurity Enhancement"},"content":{"rendered":"<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-11694\" src=\"https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity.png\" alt=\"Asynchronous ModSecurity Engine\" width=\"1536\" height=\"768\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity.png 1536w, https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity-300x150.png 300w, https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity-1024x512.png 1024w, https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity-768x384.png 768w, https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity-1320x660.png 1320w, https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity-600x300.png 600w\" sizes=\"(max-width: 1536px) 100vw, 1536px\" \/><br \/>\nLiteSpeed Web Server\u2019s proprietary ModSecurity engine already delivers stellar performance. We\u2019ve achieved that with an implementation that is highly optimized and well-integrated into the server. <a href=\"https:\/\/lswp.store\/2019\/12\/02\/modsecurity-performance-apache-nginx-litespeed\/\">In-depth testing<\/a> shows that LiteSpeed\u2019s ModSecurity solution is faster and more efficient than Apache\u2019s or nginx\u2019s.<\/p>\n<p>Even so, ModSecurity, being CPU intensive, can be a drag on performance. Our implementation already reduces the CPU impact with measures such as:<\/p>\n<ul>\n<li>Intelligently skipping some rules based on the request input<\/li>\n<li>Caching regex results to speed up regular expression matching<\/li>\n<li>Execution suspension for long-running rule processing<\/li>\n<\/ul>\n<p>That said, we\u2019re not ones to rest on our laurels! And that is why we are pleased to announce a major feature enhancement for LiteSpeed Web Server v6.0: an Asynchronous ModSecurity Engine.<\/p>\n<h2>The Problems with ModSecurity<\/h2>\n<p>Implementing ModSecurity is a challenge due to the heavy reliance on CPU, limited resources available, and ModSecurity\u2019s tendency to clog the main event loop thread.<\/p>\n<h3>Clogging the Main Event Loop Thread<\/h3>\n<p>Popular ModSecurity rulesets contain hundreds of rules. Depending on the input size, one request could take upwards of a few hundred milliseconds to scan. In an event-driven server, where the main event loop thread handles all events, everything else must wait while a ModSecurity scan executes.<\/p>\n<p>LiteSpeed already has a mechanism in place that tracks the time spent in the ModSecurity engine, and suspends execution if necessary, to give other events a chance to process in a timely manner. But even with this execution suspension, the main event loop can still get bogged down by ModSecurity. For example, regular expression execution cannot be interrupted, and some of these executions (particularly during ReDoS attacks) can be highly expensive.<\/p>\n<h3>Limited CPU Resources Available<\/h3>\n<p>The main event loop thread uses a single CPU core. When executing ModSecurity rules in the main event loop thread, the only way to get better performance is to increase the number of worker processes, which means upgrading to a more powerful license.<\/p>\n<h2>Solving ModSecurity\u2019s Problems<\/h2>\n<p>One obvious solution to the problem of CPU resources is to create more lshttpd workers. The more workers available, the more CPU processing power ModSecurity can take advantage of. But managing a large number of workers means a more expensive license. Until now.<\/p>\n<p>LiteSpeed is introducing a better way.<\/p>\n<p>As of LiteSpeed Web Server v6.0, <strong>we have introduced a separate worker thread pool for ModSecurity processing<\/strong>. When a request needs to be scanned, it is offloaded to the dedicated thread pool. The benefits of this are numerous:<\/p>\n<ul>\n<li>Most importantly, it allows the main event loop thread to become available immediately for processing the next event.<\/li>\n<li>CPUs with a large number of cores can be better utilized without having to upgrade to a more powerful license.<\/li>\n<li>The worker thread pool may have a different priority and CPU affinity from the main event loop thread, which minimizes the potential impact of thread scheduling.<\/li>\n<li>With a dedicated worker thread, LiteSpeed\u2019s ModSecurity engine is able to scan the response body. Support for applying ModSecurity to a response body was not available until now, mainly due to the problems described above.<\/li>\n<\/ul>\n<p>LiteSpeed Web Server v6.0 is available now. <a href=\"https:\/\/www.litespeedtech.com\/products\/litespeed-web-server\/download\">Download it<\/a> and try it out today!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>LiteSpeed Web Server 6.0 features a new Asynchronous ModSecurity Engine that stops ModSecurity from being a drag on CPU resources.<\/p>\n","protected":false},"author":1,"featured_media":11694,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[27],"tags":[173,190],"class_list":["post-11692","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web-server","tag-lsws-v6-0","tag-mod_security"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2021\/02\/LiteSpeed-v6.0-Asynchronous-ModSecurity.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/11692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=11692"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/11692\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/11694"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=11692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=11692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=11692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}