← Prev in month
← Prev in thread
WAS Protect update
I've taken the work one step further and created the attached examples. This is not my first attempt. I tried other approaches but this was the only one that could do the work while still being reasonably easy to use. Obviously, the examples are not 100% complete but the bulk of functionality is there. The "edge" functionality is missing: how to connect the signature to a WAS documented vulnerability, and how to connect an event with the engine. In my view Protect should only reference a vulnerability already documented with Meta/Profile and provide signatures for detection/protection. Also, the signature should not decide on an action either. It is there only to report the findings. So there are two use cases: 1. A signature is there to address a vulnerability, and it references it by its unique id. The user downloads relevant signatures based on system configuration and available meta data. 2. A user deploys a web protection engine that understands Protect signatures, and he/she writes custom signatures to protect some web application. We don't need to do much to support this, perhaps only add mechanisms to pass a message from a signature to the engine. These types of signatures will not exist in the database. Some features mentioned in my first document are removed for now or, in other words, left for future development phases. -- ModSecurity (http://www.modsecurity.org) [ Open source IDS for Web applications ]
← Prev in month
← Prev in thread