r1 - 17 Oct 2008 - 15:08:45 - MattJonkmanYou are here: TWiki >  Main Web > OpenInfosec > EngineFeatures > ApplicationStateTracking

Application State Tracking

From Andre Ludwig: Some sort of meta language needs to be created that easily and effectively can communicate any applications "state". Even if this means creating application specific "translation" modules that allow end users to effectively outline functions used by an application (and what they do).

This of course would come in handy by allowing end users the ability to effectively "peer" inside the "mapped logic" of an application. This in turn (if done right) could aid in an analysts ability to alert and investigate malicious behavior of an application vs simply producing mind numbingly general "signatures' and hoping for the best. (xss alerts come to mind, as well as other web app attacks)

-- MattJonkman - 17 Oct 2008

Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback