Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  When does ADC content for predefined signature dictionaries get updated?

    Posted 03-02-2023 12:41

    When do signature dictionaries get updated?  We're set to do an automatic ADC update every 4 days.

    We've noticed that newer CVEs for Oracle are not in the dictionaries.

    I've checked in the All Signatures for Database Applications and Recommended for Blocking for Database Applications dictionaries and the newest item I found was from 2014 (searched for "deprecated").

    Our ADC was last updated in Feburary, this on a DAM MX.  Do the counts look correct?


    #DatabaseActivityMonitoring

    ------------------------------
    Robert Miller
    Senior Cybersecurity Engineer
    Bank of the West
    Omaha NE
    ------------------------------


  • 2.  RE: When does ADC content for predefined signature dictionaries get updated?

    Posted 03-02-2023 16:54

    Hi,

    Signatures are updated regularly usually on a bi-weekly basis. You can subscribe to the release notes from the support portal I beleive.

    Which CVE are you looking for, I can check on the internal DB if it is covered or not.

    Regards



    ------------------------------
    Sarvesh Lad
    Tech Lead @ On-Prem Managed Services (WAF, DAM, DRA & Sonar)
    ------------------------------



  • 3.  RE: When does ADC content for predefined signature dictionaries get updated?

    Posted 03-03-2023 04:15

    Hi Robert,

    Same SS for different ADC Update Times are seen below:



    ------------------------------
    Cezmi Cal
    technical support engineer
    Barikat Internet Guvenligi Bilisim Ticaret A.S.
    Ankara
    ------------------------------



  • 4.  RE: When does ADC content for predefined signature dictionaries get updated?

    Posted 03-03-2023 13:39

    I was not given specific CVEs, I think a couple that would apply are CVE-2012-3132 and CVE-2009-0992.

    I have a meeting next week with the people that asked the question, and I'll get more details.

    This may not be an issue as according to the coverage tool Oracle 19c & 21c are the only versions supported when using Securesphere v14 on VMware.  We have several 12c databases still installed.



    ------------------------------
    Robert Miller
    Senior Cybersecurity Engineer
    Bank of the West
    Omaha NE
    ------------------------------