Forum Discussion
dechir_21483
Nimbostratus
Feb 10, 2013Automatic policy bluilding and SQL-INJECTION
Hi,
We have Web sharing hosting for our customer, and we use ASM to protect it with APB(Automatic policy bluilding),
But we have noticed that the APB can't block the SQL-INJECTION attack. and i inform you that in :
Policy Building--->Manuel---->Traffic Learning:---->attack signature detected : we can view the attack SQL-INJ with disable on parameter but not was blocked during the test.
My question: How can we block the SQL-INJECTION attack on APB ?
Regards
3 Replies
- Ido_Breger_3805Historic F5 AccountHi Dechir,
The policy builder is a tool that is creating policies automatically. It needs to see a decent amount of traffic before it could stabilize a policy (needs to see enough traffic to collect stats and build heuristics), by stabilize a policy I mean that it will learn how good traffic looks like and promote the policy into enforcement and blocking mode. The policy builder does have the capability to sort out attacks from valid traffic, however, if you try to attack the website before the policy builder stabilized a security policy, most chances are that the attack will go through as the policy doesn't enforce rules. - Ido_Breger_3805Historic F5 AccountHi Dechir,
The policy builder is a tool that is creating policies automatically. It needs to see a decent amount of traffic before it could stabilize a policy (needs to see enough traffic to collect stats and build heuristics), by stabilize a policy I mean that it will learn how good traffic looks like and promote the policy into enforcement and blocking mode. The policy builder does have the capability to sort out attacks from valid traffic, however, if you try to attack the website before the policy builder stabilized a security policy, most chances are that the attack will go through as the policy doesn't enforce rules. - Ido_Breger_3805Historic F5 AccountHi Dechir,
The policy builder is a tool that is creating policies automatically. It needs to see a decent amount of traffic before it could stabilize a policy (needs to see enough traffic to collect stats and build heuristics), by stabilize a policy I mean that it will learn how good traffic looks like and promote the policy into enforcement and blocking mode. The policy builder does have the capability to sort out attacks from valid traffic, however, if you try to attack the website before the policy builder stabilized a security policy, most chances are that the attack will go through as the policy doesn't enforce rules.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects