← Prev in month ← Prev in thread

WAS Protect update

From
Ivan Ristic <>
Date
2004-05-03T21:33:08+00:00
ID
Thread
WAS Protect update
I've taken the work one step further and created the attached
examples. This is not my first attempt. I tried other approaches
but this was the only one that could do the work while still
being reasonably easy to use.

Obviously, the examples are not 100% complete but the bulk
of functionality is there. The "edge" functionality is
missing: how to connect the signature to a WAS documented
vulnerability, and how to connect an event with the engine.

In my view Protect should only reference a vulnerability
already documented with Meta/Profile and provide signatures
for detection/protection. Also, the signature should not
decide on an action either. It is there only to report the
findings. So there are two use cases:

1. A signature is there to address a vulnerability, and
   it references it by its unique id. The user downloads
   relevant signatures based on system configuration and
   available meta data.

2. A user deploys a web protection engine that understands
   Protect signatures, and he/she writes custom signatures
   to protect some web application. We don't need to do
   much to support this, perhaps only add mechanisms to
   pass a message from a signature to the engine.

   These types of signatures will not exist in the
   database.

Some features mentioned in my first document are removed for
now or, in other words, left for future development phases.

-- 
ModSecurity (http://www.modsecurity.org)
[ Open source IDS for Web applications ]
← Prev in month ← Prev in thread