Templates and Alerts
Repeated Failed Logins Template
Failed Login Attempts
This template generates and forwards the following alerts to a response program when repeated failed logins are detected.
Table | Failed Login Attempts Alert Properties |
| |||
|
|
|
|
|
|
| Response | Alert | Alert |
|
|
| Program | Field | Alert Value/Format | Description | |
| Field | ||||
| Argument | Type |
|
| |
|
|
|
| ||
|
|
|
|
|
|
| argv[1] | Template | Integer | 8 | Unique code assigned to |
|
| code |
|
| template |
|
|
|
|
|
|
| argv[2] | Version | Integer | 2 | Version of the template |
|
|
|
|
|
|
| argv[3] | Severity | Integer | 2 for user root or ids and 3 for all | Severity |
|
|
|
| other users |
|
|
|
|
|
|
|
| argv[4] | UTC Time | Integer | <secs> | UTC time in number of |
|
|
|
|
| seconds since epoch |
|
|
|
|
| when |
|
|
|
|
| <max_failed_login> |
|
|
|
|
| number of failed logins |
|
|
|
|
| are detected for a |
|
|
|
|
| particular target login |
|
|
|
|
| account. |
|
|
|
|
|
|
| argv[5] | <empty> | n/a | n/a | This field is empty |
|
|
|
|
|
|
| argv[6] | <empty> | n/a | n/a | This field is empty |
|
|
|
|
|
|
| argv[7] | Summary | String | “Failed login attempts” | Alert summary |
|
|
|
|
|
|
| argv[8] | Details | String | “More than <max_failed_login> failed | Detailed alert |
|
|
|
| logins by user <username> | description |
|
|
|
| (REMOTE: <fully qualified host |
|
|
|
|
| name> <IP address>)” |
|
|
|
|
|
|
|
| argv[9] | Local | Integer | <secs> | Local time in number of |
|
| Time |
|
| seconds since epoch |
|
|
|
|
| when |
|
|
|
|
| <max_failed_login> |
|
|
|
|
| number of failed logins |
|
|
|
|
| are detected for a |
|
|
|
|
| particular target login |
|
|
|
|
| account. |
|
|
|
|
|
|
| argv[10] | Flag | Integer | 1 | Indicates a failed login |
|
|
|
|
| alert versus a failed su |
|
|
|
|
| alert. |
|
|
|
|
|
|
| argv[11] | User | String | <username> | Name of target login |
|
|
|
|
| name that a user was |
|
|
|
|
| attempting to login as. |
|
|
|
|
|
|
174 | Appendix A |