HP Host Intrusion Detection System (HIDS) manual Failed Login Attempts, 174

Models: Host Intrusion Detection System (HIDS)

1 270
Download 270 pages 6.58 Kb
Page 186
Image 186

Templates and Alerts

Repeated Failed Logins Template

Failed Login Attempts

This template generates and forwards the following alerts to a response program when repeated failed logins are detected.

Table A-23

Failed Login Attempts Alert Properties

 

 

 

 

 

 

 

 

Response

Alert

Alert

 

 

 

Program

Field

Alert Value/Format

Description

 

Field

 

Argument

Type

 

 

 

 

 

 

 

 

 

 

 

 

 

argv[1]

Template

Integer

8

Unique code assigned to

 

 

code

 

 

template

 

 

 

 

 

 

 

argv[2]

Version

Integer

2

Version of the template

 

 

 

 

 

 

 

argv[3]

Severity

Integer

2 for user root or ids and 3 for all

Severity

 

 

 

 

other users

 

 

 

 

 

 

 

 

argv[4]

UTC Time

Integer

<secs>

UTC time in number of

 

 

 

 

 

seconds since epoch

 

 

 

 

 

when

 

 

 

 

 

<max_failed_login>

 

 

 

 

 

number of failed logins

 

 

 

 

 

are detected for a

 

 

 

 

 

particular target login

 

 

 

 

 

account.

 

 

 

 

 

 

 

argv[5]

<empty>

n/a

n/a

This field is empty

 

 

 

 

 

 

 

argv[6]

<empty>

n/a

n/a

This field is empty

 

 

 

 

 

 

 

argv[7]

Summary

String

“Failed login attempts”

Alert summary

 

 

 

 

 

 

 

argv[8]

Details

String

“More than <max_failed_login> failed

Detailed alert

 

 

 

 

logins by user <username>

description

 

 

 

 

(REMOTE: <fully qualified host

 

 

 

 

 

name> <IP address>)”

 

 

 

 

 

 

 

 

argv[9]

Local

Integer

<secs>

Local time in number of

 

 

Time

 

 

seconds since epoch

 

 

 

 

 

when

 

 

 

 

 

<max_failed_login>

 

 

 

 

 

number of failed logins

 

 

 

 

 

are detected for a

 

 

 

 

 

particular target login

 

 

 

 

 

account.

 

 

 

 

 

 

 

argv[10]

Flag

Integer

1

Indicates a failed login

 

 

 

 

 

alert versus a failed su

 

 

 

 

 

alert.

 

 

 

 

 

 

 

argv[11]

User

String

<username>

Name of target login

 

 

 

 

 

name that a user was

 

 

 

 

 

attempting to login as.

 

 

 

 

 

 

174

Appendix A

Page 186
Image 186
HP Host Intrusion Detection System (HIDS) manual Table A-23 Failed Login Attempts Alert Properties, 174