« Act Like You've Been There Before | Main | Move along, nothing to see here... »

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8345207f669e200e552ae41dc8834

Listed below are links to weblogs that reference Ryan Barnett - ModSecurity Web Security Metrics:

Comments

You can't count false negatives. You might count false negatives that you can detect through alternative means; but the total "false negatives" is unknown. That is why they are called false negatives; because you don't detect them.

@Vicente -

I agree that you may never count all of them, but I also think you can get most of them through those alternate means. That's why we have multiple layers of defense. Your best effort is all you can do.

Pete

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment