Faith Olajide

Cybersecurity & IT Support Specialist

View on GitHub

Detection Engineering & Suricata Rules

Overview

Five custom Suricata IDS signatures engineered to detect the three web application attacks demonstrated in this capstone.


Rule Philosophy

Specificity Over Generality: Rules target the exact attack patterns validated in the lab, not generic vulnerability signatures. This reduces false positives while maintaining high confidence.

Confidence Tiering: High-confidence rules (block-ready), Medium-confidence rules (alert-only during observation period).

Behavioral Detection: IDOR requires threshold-based detection since individual requests appear legitimate.


Rule Details

Rule 1000001: SQL Injection - Tautology

Type: High-confidence, block-ready

Target: POST /rest/user/login endpoint with exact SQLi payload

Detection Logic:

False-Positive Risk: Very low (specific endpoint, specific payload pattern)

Production Recommendation: Deploy for blocking immediately


Rule 1000002: SQL Injection - Quote + OR

Type: Medium-confidence, alert-only

Target: Login endpoint with quote + OR pattern (broader variant)

Detection Logic:

False-Positive Risk: Higher (legitimate users may have apostrophes in names/emails)

Production Recommendation: Alert-only for 7 days, then promote to blocking after tuning


Rule 1000003: Path Traversal - Obfuscation Bypass

Type: High-confidence, block-ready

Target: /ftp/ endpoint with ....// obfuscation

Detection Logic:

False-Positive Risk: Very low (unusual pattern, not standard file requests)

Production Recommendation: Deploy for blocking immediately


Rule 1000004: Path Traversal - Double URL-Encoding

Type: Medium-confidence, alert-only

Target: Alternative traversal technique using %252f (double-encoded slash)

Detection Logic:

False-Positive Risk: Low but possible with legitimate double-encoded URLs

Production Recommendation: Alert-only initially, observe for baseline behavior


Rule 1000005: IDOR - Behavioral Threshold

Type: Medium-confidence, alert-only (behavioral)

Target: Rapid enumeration of different basket IDs

Detection Logic:

False-Positive Risk: Medium (power users checking multiple baskets legitimately may trigger)

Tuning Notes:

Production Recommendation: Alert-only for 7 days minimum, then tune based on environment


Tuning Strategy

Phase 1: Deployment (Immediate)

Phase 2: Observation (Days 1-7)