This blog has moved! Please update your
bookmarks to http://www.blog.modsecurity.org.

« Web Application Firewall Use Case: Continuous Security Assessment | Main

Web Application Monitoring Data Model

A data model is the foundation of web application monitoring and, thus, key to successful utilisation of web application firewalls. We don't get to design the model; we can only deduct it from the information provided to us from the underlying technology. What we can do is build on it, and, for that reason, it is very important to understand what we have to work with.

An ideal model is one that helps structure the information available to us, allows us to enrich it with additional pieces of data and generally helps us raise events based on the information it contains.

The major parts of a web application monitoring data model are as follows:

Most of the components are easy to construct, mapping from the structures used in programming, but there are a few places where the technology does not support the view, or where what we are given is not what we want to see:

Note: This post is part of the Web Application Firewall Concepts series.

Posted by ivanr at March 27, 2008 12:10 PM