SQL injection ruleset

clearplane-sql-injection inspects selected request fields for SQL injection syntax, database functions and fingerprint matches. The protocol ruleset supplies complementary inspection-limit protection.

Paranoia levels and compatibility

SQL editors, query-building APIs and documentation search can legitimately contain SQL syntax. A full SQL statement in an ordinary parameter can reach the blocking threshold at level 1. Higher paranoia levels add matches. Use a reviewed target exclusion for a trusted field and verify attack controls outside that field before promotion.

Start in Detection, review detections, and configure only the exclusions needed for the affected route and field.

See the measured coverage for the exact tested payload hashes, missed detections and false-positive rates. Ruleset operation explains activation, stages and rollback.