cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
256
Views
0
Helpful
1
Replies

IDS and SQL Injection

quandm
Level 1
Level 1

Hi all,

My Web server is IIS 5.0.

I have IDS 4235.

So my question is:

1. Is IDS can detects and protects again SSL encripted sessions (HTTPS).

2. How IDS can detects SQL injection in encripted sessions.

Pls, help

1 Reply 1

ktimm
Level 1
Level 1

The IDS can not do much with encrypted traffic except understand a few protocol violations. For the IDS to understand see the traffic you might want to use a SSL accelerator and have the IDS behind that. Another option you may want to consider is HIDS. Since the IDS CAN NOT understand the encrypted traffic it is blind to SQL injection / insertion techniques. These are not always done over SSL so some signatures may catch minor stuff. The majority, however, should be over SSL. Once again HIDS probably does a better job with this.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: