- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- CloudGuard - WAF
- :
- Genai and learning mode question
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Genai and learning mode question
Hello,
yesterday I enabled Tech Preview mode to check out a finding and turned it off after again.
Today I discovered a "Genai" rule option in the rule base. Idk if it's related to the enable/disable of the tech preview mode.
The rule builder itself look the same and I have no idea where to put my natural language (uri regex i.e.?). I cannot find any information about this. Is this documented anywhere?
Second question. I had some SQL injections in a password field yesterday. One of them was a "legit" password matching an SQL injection (partly, mostly a false positive) and two were SQL injections by myself to confirm the previous finding.
Today I got the question, whether these 3 are malicious or benign requests, grouped together. Lets assume the first SQL injection was benign, the later malicious.
What should I answer, as I cannot split them up or should I not answer at all?
What are the consequences of flagging a malicious request as benign, in the short/medium/long term for the MLM?
Cheers
Christoph
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you try documentation? https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SaaS-Admin-Guide/Content/Topi...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Val,
I actually did.
"Genai Protect" in the Harmony SaaS Administration Guide, as a preventive measure to regulate the usage of AI in the corporate environment is more or less a DLP solution.
"Genai protection" in the Cloudguard WAF says define a custom rule in natural language and presents the standard rule options.
The Cloud Guard WAF documentation has the Genai protection, as of now, not listed. Only the following options are available:
Documentation Overview | CloudGuard WAF
Accept - Traffic matching the exception's conditions will be accepted.
Drop - Traffic matching the exception's conditions will be blocked.
Skip - Relevant only for specific keys like "Parameter Name", "Parameter Value" and "Indicator". Allows skipping the value of the matching parameter from being inspected by the CloudGuard WAF engines. The rest of the traffic will be inspected for malicious behavior. Skip action is not supported with Scheme Validation.
Suppress Log - Traffic matching the exception's condition will not activate their Log Trigger object/s upon event.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What about the link I provided you with?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I cannot find any information related to the Web Application Firewall in your link.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gotcha. Let me see what I can dig out
