|
|
|
|
|
by lloeki
2564 days ago
|
|
(Sqreen Ruby engineer) You're right about the basic premise, (but not about the details, we don't monitor syscalls): since we stand within the application we have context of the operations performed and can pinpoint whether some query fragment is a) executable and b) coming from a user, and therefore reliably conclude the action is malicious. |
|