
Templates and Alerts
Repeated Failed Logins Template
| 
 | Repeated Failed Logins Template | 
| The vulnerability | An attacker can gain access to a system by repeatedly attempting to guess the password | 
| addressed by this | of an account. | 
| template | 
 | 
| How this template | The Failed Login template monitors for repeated failed attempts to login to the system. | 
| addresses the | Specifically, this template monitors btmp on 11i and btmps on 11i v2 for a given number | 
| vulnerability | of failed login attempts within a specified time span. | 
| 
 | • Failed remote logins | 
| 
 | • Failed ftp logins (starting with  | 
| 
 | If an unusual number of failed attempts occur, this template generates an alert. | 
How this template This template supports the following properties: is configured
| Table  | Template Properties | 
 | 
 | 
| 
 | 
 | 
 | 
 | 
| 
 | Name | Type | Default Value | 
| 
 | 
 | 
 | 
 | 
| 
 | max_failed_login | VIII | 2 | 
| 
 | 
 | 
 | 
 | 
| 
 | fail_interval | VI | 10s | 
| 
 | 
 | 
 | 
 | 
| 
 | warning_interval | VI | 30s | 
| 
 | 
 | 
 | 
 | 
Properties• Property: max_failed_login
The number of failed attempts to login as the same user.
•Property: fail_interval
The time interval over which the failed login attempts must occur to generate an alert.
•Property: warning_interval
The minimum time that must elapse before an identical failed login alert is generated.
| 
 | The default settings mean that more than two login failures for a particular target user | 
| 
 | within 10 seconds will cause an alert to be generated, and duplicate alerts that occur | 
| 
 | within 30 seconds will not be reported. It is not an uncommon occurrence for a user to | 
| 
 | mistype a password when attempting to login. By modifying the values, this template | 
| 
 | can be customized to local user behavior. | 
| Alerts generated | • “Failed Login Attempts” on page 174 | 
| by this template | 
 | 
| Appendix A | 173 | 
