<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS Detects SQL Injection over HTTPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670002#M65254</link>
    <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;Do you think Cisco IPS is able to detect SQL Injection over HTTPS?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:20:03 GMT</pubDate>
    <dc:creator>learnsec</dc:creator>
    <dc:date>2019-03-10T12:20:03Z</dc:date>
    <item>
      <title>IPS Detects SQL Injection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670002#M65254</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;Do you think Cisco IPS is able to detect SQL Injection over HTTPS?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670002#M65254</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2019-03-10T12:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Inhection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670003#M65258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My answer would be NO as cisco does not have the SSL decryption capability yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Apr 2011 05:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670003#M65258</guid>
      <dc:creator>gaurash2</dc:creator>
      <dc:date>2011-04-21T05:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Inhection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670004#M65260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;then if Cisco IPS is not enough to&lt;/P&gt;&lt;P&gt;inspect SSL Traffic, what is the suitable way to amelliorate the security for a large&lt;/P&gt;&lt;P&gt;size company ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Apr 2011 08:36:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670004#M65260</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2011-04-21T08:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Inhection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670005#M65263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 May 2011 08:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670005#M65263</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2011-05-20T08:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Injection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670006#M65265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"In certain situations, it may be possible to detect and prevent SQL injection attacks using an Intrusion Prevention System (IPS). &lt;STRONG&gt;For an IPS to be effective, it must have visibility into the traffic of the application. For applications that use end-to-end encryption with HTTPS&lt;/STRONG&gt; (for example, applications that use HTTPS without termination or acceleration at an intermediate network device), &lt;STRONG&gt;an IPS cannot identify traffic with characteristics of a SQL injection attack.&lt;/STRONG&gt;" per:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/web/about/security/intelligence/sql_injection.html"&gt;Understanding SQL Injection&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 May 2011 13:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670006#M65265</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-05-24T13:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Injection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670007#M65266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but this lead me to ask you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;an IPS itself is configured and installed in the network, normally, as a layer 2 device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it is know that IPS can detect malicous traffic, attacks, vulnerabilities,.. up to layer 4 right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but what i am not understanding is that when we find the IPS is detecting SQL injection over http, or vulnerabilities of IIS, or Internet Explorer, or microsoft power point, or ... doesn't all that a layer 7 traffic detected? so why IPS is known to be as layer 4 device &lt;SPAN style="text-decoration: underline;"&gt;only&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i hope you can explicitly explain this issue,&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 06:32:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670007#M65266</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2011-06-21T06:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Injection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670008#M65267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"A Cisco IPS solution protects the network from policy violations, vulnerability exploitations, and anomalous activity through detailed inspection of traffic at Layers 2 through 7."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"At the core of Cisco IPS solutions are numerous methods for the inspection and analysis of traffic in Layers 2 through 7."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both quotes per &lt;A href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/product_data_sheet0900aecd805baef2.html"&gt;Cisco Intrusion Prevention System Solutions&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 13:50:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670008#M65267</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-06-21T13:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Injection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670009#M65268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you explain then why if you surf through out the internet comapring between an IPS and a Web Application Firewall (WAF) you do not stop hearing that WAF is for layer 7 Attacks that IPS Cant detect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So WAF has at least two known advantages compared to IPS, wich are: &lt;/P&gt;&lt;P&gt;- WAF can Detect Attacks hidden behind a HTTPS traffic (through SSL offloading i guess)&lt;/P&gt;&lt;P&gt;- Attacks layer 7 will be detected, IPS can detect only up to layer 4 attacks &lt;STRONG style="text-decoration: underline; "&gt;only&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 07:05:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670009#M65268</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2011-06-28T07:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Injection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670010#M65269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Thanks again Dustin&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;You're welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Can you explain then why if you surf through out the internet comapring between an IPS and a Web Application Firewall (WAF) you do not stop hearing that WAF is for layer 7 Attacks that IPS Cant detect.&lt;/PRE&gt;&lt;P&gt;I personally do not work with dedicated Web Application Firewalls so I cannot speak to their effectiveness, etc. My understanding is that they control input, output, and/or access from, to, or by an application or service by monitoring and potentially blocking the input, output, or system service calls which do not meet the configured policy of the WAF. As such, I assume they can be used for enforcing policy compliance and for additional control for specific applications (example: controlling what script can be accessed or what content-type can be transferred, etc.). An IPS device is not designed to provide that type of application-specific control; it is designed to detect/block specific threats [applicable to the application in this comparison].&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;WAF Example: Detecting and blocking attempts to access script.php on your Apache web server (due to the WAF policy configuration).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;IPS Example: Detecting and blocking attempts to exploit a known vulnerability with the version of Apache software running on your web server (due to an enabled IPS signature definition for that threat).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is probably some overlap between the two (2) types of devices (example: you could possibly configure a WAF to detect/block a particular threat given time and technical expertise; likewise, you could probably create a custom signature on an IPS device to provide some form of limited control such as blocking attempts to access a specific script). But doing so is probably a lot less efficient, more difficult, etc. and is probably subject to limitations for each type of device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;So WAF has at least two known advantages compared to IPS, wich are: &lt;P&gt;- WAF can Detect Attacks hidden behind a HTTPS traffic (through SSL offloading i guess)&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;So can an IPS device (if the HTTPS is terminated or accelerated at an intermediate network device and the IPS device is inspecting the unencrypted traffic between the backend HTTP server and the frontend HTTPS accelarator/server), per my original reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;- IPS can detect only up to layer 4 attacks &lt;STRONG style="text-decoration: underline;"&gt;only&lt;/STRONG&gt;.&lt;/PRE&gt;&lt;P&gt;This is simply incorrect, per my last reply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2011 16:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670010#M65269</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-06-30T16:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Detects SQL Injection over HTTPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670011#M65270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the explanation,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 07:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-detects-sql-injection-over-https/m-p/1670011#M65270</guid>
      <dc:creator>learnsec</dc:creator>
      <dc:date>2011-07-05T07:15:33Z</dc:date>
    </item>
  </channel>
</rss>

