Change the order of custom rules

Prev Next

The order of the rules in the Custom Rules list is important. The first rule that is matched is the rule that is applied to the statement. If a statement does not match any of the existing rules, the statement is allowed.

The Database Security system enables you to create a policy according to your preferences and security requirements in various ways.

Fundamentally, there are two approaches to define a policy:

  • Allow list approach — Resembles the approach of firewalls, whereby you determine the allowed actions first and then alert on all other actions (assuming that all other actions are suspect).

  • Block list approach — Resembles the approach of IDS/IPS systems, whereby everything is allowed except actions that are considered suspect.

Database Security users normally create a policy that integrates elements of both approaches, for example, using a Block list approach for all known attacks, while using a Allow list approach for the use of development SQL tools.

Note

Incoming statements are checked against the vPatch Rules list before they are checked against the Custom Rules list.

  1. On the Rules page, select the Custom Rules tab.

  2. Select the rule in the Custom Rules list and then drag the position indicator GUID-E1B71CDD-80E4-463F-85C6-5FC3B261CCCA-low.png on the slider to a new location as required.