Templates and Alerts

Repeated Failed Logins Template

 

Repeated Failed Logins Template

The vulnerability

An attacker can gain access to a system by repeatedly attempting to guess the password

addressed by this

of an account.

template

 

How this template

The Failed Login template monitors for repeated failed attempts to login to the system.

addresses the

Specifically, this template monitors btmp on 11i and btmps on 11i v2 for a given number

vulnerability

of failed login attempts within a specified time span.

 

• Failed remote logins

 

• Failed ftp logins (starting with HP-UX 11i v2 only)

 

If an unusual number of failed attempts occur, this template generates an alert.

How this template This template supports the following properties: is configured

Table A-22

Template Properties

 

 

 

 

 

 

 

Name

Type

Default Value

 

 

 

 

 

max_failed_login

VIII

2

 

 

 

 

 

fail_interval

VI

10s

 

 

 

 

 

warning_interval

VI

30s

 

 

 

 

PropertiesProperty: max_failed_login

The number of failed attempts to login as the same user.

Property: fail_interval

The time interval over which the failed login attempts must occur to generate an alert.

Property: warning_interval

The minimum time that must elapse before an identical failed login alert is generated.

 

The default settings mean that more than two login failures for a particular target user

 

within 10 seconds will cause an alert to be generated, and duplicate alerts that occur

 

within 30 seconds will not be reported. It is not an uncommon occurrence for a user to

 

mistype a password when attempting to login. By modifying the values, this template

 

can be customized to local user behavior.

Alerts generated

• “Failed Login Attempts” on page 174

by this template

 

Appendix A

173

Page 185
Image 185
HP Host Intrusion Detection System (HIDS) manual Repeated Failed Logins Template, Table A-22 Template Properties