Detection Engineering & Suricata Rules
Overview
Five custom Suricata IDS signatures engineered to detect the three web application attacks demonstrated in this capstone.
Rule Philosophy
Specificity Over Generality: Rules target the exact attack patterns validated in the lab, not generic vulnerability signatures. This reduces false positives while maintaining high confidence.
Confidence Tiering: High-confidence rules (block-ready), Medium-confidence rules (alert-only during observation period).
Behavioral Detection: IDOR requires threshold-based detection since individual requests appear legitimate.
Rule Details
Rule 1000001: SQL Injection - Tautology
Type: High-confidence, block-ready
Target: POST /rest/user/login endpoint with exact SQLi payload
Detection Logic:
- HTTP method: POST
- URI:
/rest/user/login - Request body contains:
' OR 1=1-- - Case-insensitive matching
False-Positive Risk: Very low (specific endpoint, specific payload pattern)
Production Recommendation: Deploy for blocking immediately
Rule 1000002: SQL Injection - Quote + OR
Type: Medium-confidence, alert-only
Target: Login endpoint with quote + OR pattern (broader variant)
Detection Logic:
- HTTP method: POST
- URI:
/rest/user/login - Request body contains: single quote
- Followed by (within 15 bytes):
ORkeyword
False-Positive Risk: Higher (legitimate users may have apostrophes in names/emails)
Production Recommendation: Alert-only for 7 days, then promote to blocking after tuning
Rule 1000003: Path Traversal - Obfuscation Bypass
Type: High-confidence, block-ready
Target: /ftp/ endpoint with ....// obfuscation
Detection Logic:
- URI contains:
/ftp/ - URI contains:
....//sequence - Detects the specific bypass technique (not naive
../)
False-Positive Risk: Very low (unusual pattern, not standard file requests)
Production Recommendation: Deploy for blocking immediately
Rule 1000004: Path Traversal - Double URL-Encoding
Type: Medium-confidence, alert-only
Target: Alternative traversal technique using %252f (double-encoded slash)
Detection Logic:
- URI.raw (before decoding) contains:
%252f - Suspicious double-encoding pattern
False-Positive Risk: Low but possible with legitimate double-encoded URLs
Production Recommendation: Alert-only initially, observe for baseline behavior
Rule 1000005: IDOR - Behavioral Threshold
Type: Medium-confidence, alert-only (behavioral)
Target: Rapid enumeration of different basket IDs
Detection Logic:
- URI contains:
/rest/basket/ - Threshold: 3 or more distinct requests within 10 seconds
- From same source IP
- Behavioral pattern indicates enumeration attempt
False-Positive Risk: Medium (power users checking multiple baskets legitimately may trigger)
Tuning Notes:
- Initial threshold: 3 requests in 10 seconds
- Observable baseline period: 7 days
- Adjust based on legitimate user behavior patterns
- Consider increasing to 5 requests in 30 seconds after observation
Production Recommendation: Alert-only for 7 days minimum, then tune based on environment
Tuning Strategy
Phase 1: Deployment (Immediate)
- Deploy Rules 1000001, 1000003 for blocking
- Deploy Rules 1000002, 1000004, 1000005 for alerting
Phase 2: Observation (Days 1-7)
- Monitor all alerts
- Calculate