Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  SQL Injection Policy

    Posted 09-25-2025 08:10

    We have a DAM Implemented on Oracle servers and i want to apply Sql Injection alerts on the same, can somebody help me on the same, if anyone has applied this capability already in their system with very less FP.


    #DatabaseActivityMonitoring

    ------------------------------
    Shashank Mahendra
    Information Security Analyst
    Amdocs Inc
    SAINT LOUIS MO
    ------------------------------


  • 2.  RE: SQL Injection Policy

    Posted 10-03-2025 02:11

    Anyone can please comment.



    ------------------------------
    Shashank Mahendra
    Information Security Analyst
    Amdocs Inc
    SAINT LOUIS MO
    ------------------------------



  • 3.  RE: SQL Injection Policy

    Posted 10-05-2025 06:18

    Hello Shashank,

    On the MX GUI, navigate to Policies > Security.
    Locate the Web Correlation Policy, and under this section, you'll find the SQL Injection Policy.

    You can enable or apply this policy to protect against SQL injection attacks.

    Best regards,
    Raunak



    ------------------------------
    Raunak Tiwari
    ------------------------------



  • 4.  RE: SQL Injection Policy

     
    Posted 10-06-2025 09:39

    we are in version 14.19 DAM SeS  and i don't see these policies Web Correlation Policy in your mentioned path . please check and advise



    ------------------------------
    Rev1
    ------------------------------



  • 5.  RE: SQL Injection Policy

    Posted 10-06-2025 09:55

    The Web Correlation Policy

    Only applied for WAF Gateway not for DAM



    ------------------------------
    Alejandro Hernandez
    SICAP
    Professional Services Consultant and Principal Technical Trainer
    Mexico City
    ------------------------------



  • 6.  RE: SQL Injection Policy

    Posted 10-07-2025 13:52

    Hi Shashank,

    You may use signatures which are provided as a part of ADC since they will consist of signatures pertaining to SQLi attack.

    Regards,



    ------------------------------
    SBISOC 4430
    Manager
    Mumbai
    ------------------------------



  • 7.  RE: SQL Injection Policy

    Posted 27 days ago

    Thanks community for your updates, Recommended signature policy for database applications,  Shall i enable this policy to protect against sql injection attacks, if yes then this policy gives a lot of false positive and difficult to fine tune it.



    ------------------------------
    Shashank Mahendra
    Information Security Analyst
    Amdocs Inc
    SAINT LOUIS MO
    ------------------------------



  • 8.  RE: SQL Injection Policy

    Posted 27 days ago

    Hi Shashank,

    If you use out of the box security policy, then it will be difficult to apply exclusion or exception criteria. That is why we mentioned that you can use the signatures pertaining to Oracle databases which are provided as a part of ADC and add them in your custom security policy.

    Regards,



    ------------------------------
    SBISOC 4430
    Manager
    Mumbai
    ------------------------------



  • 9.  RE: SQL Injection Policy

    Posted 24 days ago

    if you don't mine, please help me to share the step wise process how to achieve this, that will helpful for applying.



    ------------------------------
    Shashank Mahendra
    Information Security Analyst
    Amdocs Inc
    SAINT LOUIS MO
    ------------------------------