Talk With an Expert

Profiling Web Applications for Improved Intrusion Detection

Profiling Web Applications for Improved Intrusion Detection (PDF, 2.86MB)Published: 07 Sep, 2016
Created by:
Manuel Leos Rivas

Web application firewalls using generic out of the box configurations work well for common vulnerabilities but lack the capability to address application-specific contexts. Due to this lack of context, it is difficult for the firewall to determine what it is 'good' versus 'bad'. In addition, several learning features of certain high-end devices are inaccessible to companies and individuals. This document provides a generic approach to protecting web applications using freely available software by configuring ModSecurity. This approach enables differentiation between what is acceptable for the application and what may be interesting for investigation purposes. The process for creating an application profile should be well documented, repeatable, verifiable and automated as much as possible to ease integration into the application development lifecycle.