Forum Discussion

dechir_21483's avatar
dechir_21483
Icon for Nimbostratus rankNimbostratus
Feb 10, 2013

Automatic policy bluilding and SQL-INJECTION

Hi,

 

We have Web sharing hosting for our customer, and we use ASM to protect it with APB(Automatic policy bluilding),

 

But we have noticed that the APB can't block the SQL-INJECTION attack. and i inform you that in :

 

 

Policy Building--->Manuel---->Traffic Learning:---->attack signature detected : we can view the attack SQL-INJ with disable on parameter but not was blocked during the test.

 

 

My question: How can we block the SQL-INJECTION attack on APB ?

 

 

Regards

 

3 Replies

  • Ido_Breger_3805's avatar
    Ido_Breger_3805
    Historic F5 Account
    Hi Dechir,

     

    The policy builder is a tool that is creating policies automatically. It needs to see a decent amount of traffic before it could stabilize a policy (needs to see enough traffic to collect stats and build heuristics), by stabilize a policy I mean that it will learn how good traffic looks like and promote the policy into enforcement and blocking mode. The policy builder does have the capability to sort out attacks from valid traffic, however, if you try to attack the website before the policy builder stabilized a security policy, most chances are that the attack will go through as the policy doesn't enforce rules.
  • Ido_Breger_3805's avatar
    Ido_Breger_3805
    Historic F5 Account
    Hi Dechir,

     

    The policy builder is a tool that is creating policies automatically. It needs to see a decent amount of traffic before it could stabilize a policy (needs to see enough traffic to collect stats and build heuristics), by stabilize a policy I mean that it will learn how good traffic looks like and promote the policy into enforcement and blocking mode. The policy builder does have the capability to sort out attacks from valid traffic, however, if you try to attack the website before the policy builder stabilized a security policy, most chances are that the attack will go through as the policy doesn't enforce rules.
  • Ido_Breger_3805's avatar
    Ido_Breger_3805
    Historic F5 Account
    Hi Dechir,

     

    The policy builder is a tool that is creating policies automatically. It needs to see a decent amount of traffic before it could stabilize a policy (needs to see enough traffic to collect stats and build heuristics), by stabilize a policy I mean that it will learn how good traffic looks like and promote the policy into enforcement and blocking mode. The policy builder does have the capability to sort out attacks from valid traffic, however, if you try to attack the website before the policy builder stabilized a security policy, most chances are that the attack will go through as the policy doesn't enforce rules.