Detecting suspicious behaviour in a web application - what to look for?
- by Sosh
I would like to ask the proactive (or paranoid;) among us: What are you looking for, and how?
I'm thinking mainly about things that can be watched for programaticaly, rather than manually inspecting logs.
For example:
- Manual/automated hack attempts
- Data skimming
- Bot registrations (that have evaded captcha etc.)
- Other unwanted behaviour
Just wondering what most people would consider practical and effective..