Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
filiaks1
Contributor II

FortiWeb SQL injection, XSS attacks order (signatures, Syntax Detection, ML) ?

I was wondering as for SQL or XSS attacks fortiweb has 3 options for detections what is the order of operations ?

 

Is it first signatures then Syntax Detection and  then attack ML models that are build on the appliance itself after time from the passed traffic?

 

Also what happens it an attack matches all 3 options?

 

My final question is for SQL injection and XSS attacks shouldn't signatures be stopped and just Syntax Detection and attack ML models to be used as I have read that they have less false positives ?

 

Screenshot 2025-06-17 105554.png

 

1 Solution
filiaks1
Contributor II

I think I got it with the feature false positive detection False Positive Mitigation for SQL Injection signatures | FortiWeb 7.6.2 | Fortinet Document Library  that it will then try to use the  Syntax Detection. So all features work together. Maybe for XSS there are not so many false positives and this is why it is not available. 

 

For XSS the parser seems to help wilth encodings or obfuscations so it is more to detect false negatives than to help with false positive.

 

If there is anything else please share but I think this is the case.

View solution in original post

1 REPLY 1
filiaks1
Contributor II

I think I got it with the feature false positive detection False Positive Mitigation for SQL Injection signatures | FortiWeb 7.6.2 | Fortinet Document Library  that it will then try to use the  Syntax Detection. So all features work together. Maybe for XSS there are not so many false positives and this is why it is not available. 

 

For XSS the parser seems to help wilth encodings or obfuscations so it is more to detect false negatives than to help with false positive.

 

If there is anything else please share but I think this is the case.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors