The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Protecting your web application servers

Prev Next

One of the biggest challenges for network security professionals is securing their web servers. Because of their location in the network and the nature of applications hosted by them, enterprise web servers are generally the most vulnerable and the most targeted. The motivation to attack a web server could be financial gain, confidential data, an entry into your organization’s network, or just to cause an embarrassment or inconvenience.

A critical component of a web application is its database. Web applications use SQL to interact with their databases to retrieve and store data. During these interactions, a web application server sends SQL queries combined with user-provided data to its database. This makes web applications and databases vulnerable for SQL injection attacks, where attackers attempt arbitrary SQL commands and queries on a web application’s database. These attacks might succeed when validation of user-provided data is inadequate or due to vulnerabilities in the server application.

An SQL injection is kind of a code injection. It is a malicious SQL query injected along with a legitimate SQL query to a database. A successful SQL injection can read or write to the database, execute operations on the database server, or run commands on the operating system.

Example:

Consider the URI, http://www.example.com/news.php?ID=378144 that triggers the following legitimate SQL query: "SELECT * FROM news WHERE ID = " . $ID;

An attacker can inject a malicious SQL query within the legitimate query as shown here:

http://www.example.com/news.php?ID=378144 UNION SELECT 1,2,3,password FROM admin. This SQL injection can fetch the admin password and display it on the resulting web page.

Options to prevent SQL injection attacks

The following are the options to prevent SQL injection attacks:

  • Address the vulnerabilities on the web server, but this option might not prevent all attacks. This option can also be complicated and expensive.

  • Use the SQL-injection prevention mechanism in Trellix IPS. This feature is referred to as Heuristic Web Application Server Protection. Review these details to know how to implement the Heuristic Web Application Server Protection feature.

Advantages of Heuristic Web Application Server Protection

Traditionally, IPS products use string-matching to find malicious strings in HTTP traffic. However, this method might not be effective in case of SQL injections, because SQL queries are plain text that use common words. For example, the string SELECT is used in legitimate queries as well as in malicious ones.

The Heuristic Web Application Server Protection feature of Trellix IPS uses heuristic analysis. The heuristic engine identifies SQL injections by the following method:

  1. It checks the head token of malicious SQL queries, and recognizes any malicious keywords such as UNION. Such keywords can potentially alter the structure of an SQL query.

  2. It analyzes valid and legitimate SQL statements such as SELECT password FROM admin WHERE LastName = ‘Doe’

  3. It does correlated analysis of points 1 and 2 and triggers an alert.