RP3: Suspicious Client-Side Behavior: Removed code from title
← Older revision
Revision as of 20:46, 1 July 2013
(One intermediate revision by one user not shown)
Line 2,492:
Line 2,492:
<tr><td style="border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase " >Examples</td>
<tr><td style="border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase " >Examples</td>
<td style="background-color:#F2F2F2;table-layout:fixed;width:700px;" >
<td style="background-color:#F2F2F2;table-layout:fixed;width:700px;" >
−
Example 1:
An
IDS has detected suspicious activity by a particular IP address, and this is used to temporarily tighten the attack detection thresholds for requests from all users in the same IP address range.
+
Example 1:
A network
IDS has detected suspicious activity by a particular IP address, and this is used to temporarily tighten the attack detection thresholds for requests from all users in the same IP address range.
Example 2: An application is using the ModSecurity web application firewall with the [[:Category:OWASP ModSecurity Core Rule Set Project|Core Rule Set]], and utilises the anomaly score data passed forward in the X-WAF-Events and X-WAF-Score HTTP headers (optional rules in modsecurity_crs_49_header_tagging.conf) to adjust the level of application logging for each user.
Example 2: An application is using the ModSecurity web application firewall with the [[:Category:OWASP ModSecurity Core Rule Set Project|Core Rule Set]], and utilises the anomaly score data passed forward in the X-WAF-Events and X-WAF-Score HTTP headers (optional rules in modsecurity_crs_49_header_tagging.conf) to adjust the level of application logging for each user.
Line 2,507:
Line 2,507:
<div id="RP3"></div>
<div id="RP3"></div>
+
===RP3: Suspicious Client-Side Behavior===
===RP3: Suspicious Client-Side Behavior===
Line 2,516:
Line 2,517:
<tr><td style="border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase " >Title</td>
<tr><td style="border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase " >Title</td>
<td style="background-color:#F2F2F2;table-layout:fixed;width:700px;" >
<td style="background-color:#F2F2F2;table-layout:fixed;width:700px;" >
−
RP3
Suspicious Client-Side Behavior
+
Suspicious Client-Side Behavior
</td></tr>
</td></tr>
<tr><td style="border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase " >Category</td>
<tr><td style="border-style:solid;border-width:1px;background-color:#CCCCCC;text-transform:uppercase " >Category</td>