RE: How to monitor encrypted connections...

Leonardo wrote:


On my Msc thesis I finished last year, I proposed an IDS/IPS
and developed what I call Application-based sensor.
In this sense, I debugged Apache behavior and catch the requests after
were decrypted and before they were processed by the app server.

How is it different than ModSecurity?

BTW, Did you check about WAF - Web Application firewall??


~ Ofer

Ofer Shezaf
ofers@xxxxxxxxxx, Phone:+972-9-9560036 #212, Cell: +972-54-4431119

CTO, Breach Security; Chair, OWASP Israel; Leader, ModSecurity Core Rule
Set Project;
Leader, WASC Web Hacking Incidents Database Project

Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to
to learn more.