Focus
on the applications:
HTTP
(less concerned about other protocols)
Knowledge
about the site and applications
Ability
to recognize abnormal behavior
Some
idea of attacker behavior
Attackers
will tailor attacks to exploit specific application vulnerabilities
There
are various attack sources (with different characteristics)
True
hackers
Scanners
(script kiddies)
Worms