Forum Discussion
Stevenson_88156
Nimbostratus
Jan 28, 2013ASM Attack Signatures
Hi
We are currently using F5 ASM for one of our custom developed application and we are running into an issue as F5 ASM seems to be blocking some parameters. After some investigation, we ...
Mike_Maher
Nimbostratus
Jan 29, 2013So Attack Signatures are the negative security that is built into ASM, the big power of ASM is in the policy design. So how much protection you will receive is based upon how well the rest of your policy is designed. Are you doing input validation of the parameters and restricting what type of input and/or meta-characters are allowed to be used within the parameter. If so then you should still have a good deal of protection because you are only allowing what is necessary. You are obviously losing some protection because if there is a known attack pattern that can be passed using characters or other input you have to allow for the application then yes it would get through. However using solid input validation both at the ASM and with in the application should give most of the protection you need.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects