A security engineer is developing a custom integration for Cortex XSOAR that needs to interact with an internal legacy system. This system uses a proprietary authentication mechanism that involves calculating a unique signature for each request based on a shared secret, timestamp, and request payload. How should the engineer implement this custom authentication within the integration?
- ALeverage Cortex XSOAR's built-in OAuth2 authentication flow, configuring it for the legacy system.
- BUse an encrypted integration instance parameter for the shared secret and override the `_http_request` method to inject the signature.
- CStore the shared secret in a non-encrypted integration parameter and pass it as a custom header.
- DHardcode the shared secret in the integration script and calculate the signature before each request.
Show answer & explanationAnswer & explanation
Correct answer: B. Use an encrypted integration instance parameter for the shared secret and override the `_http_request` method to inject the signature.
For proprietary authentication mechanisms requiring custom signature generation, the shared secret must be stored securely (encrypted parameter). The `_http_request` method in the `BaseClient` class should be overridden to intercept outgoing requests, calculate the signature using the shared secret, and inject it into the request (e.g., as a header) before sending.
Why the other options are wrong
- A. OAuth2 is a standard protocol; a proprietary legacy system is unlikely to support it directly without significant modification or an adapter layer. This option is not suitable for a 'proprietary authentication mechanism'.
- C. Storing the secret in a non-encrypted parameter is insecure, and simply passing it as a custom header doesn't account for the signature calculation logic.
- D. Hardcoding secrets is a major security risk and should never be done.
Custom Authentication with _http_request
Implementing bespoke authentication logic within a Cortex XSOAR integration by overriding the `_http_request` method of the `BaseClient` to modify requests before they are sent, often for signature-based or complex token mechanisms.
- Allows for pre-request manipulation like header injection, payload signing.
- Requires secure storage of credentials (e.g., encrypted parameters).
- Essential for interacting with non-standard or legacy APIs.
Memory trick: Override HTTP request to sign and send, keeping secrets encrypted.