Blocking Low and Slow botnet authentication attacks against exposed SSL VPN portal.
Over the past year, the amount of low and slow botnet authentications to numerous end-customer SSL VPN portals has been increasing. This is where the attacks do not trip the native brute force measures in a FortiGate and the wave of attacks comes in groups of between 3 and 5 public IP addresses for a day or so, then shift to new IP groups. Time intervals of each hit can be from 10 minutes to 20 hours.
So far, we have implemented in the FortiGates the Automation methods to auto block and quarantine any SSL VPN attempts for generic usernames that are not in use (admin, root, sslvpn, test, testuser, user, etc....) Some end clients have 50 or more new blocked IP addresses added to their FortiGate daily! Where this was implemented we see the volume of attacks drop from up to 1,000+ in a 24 hour period to under 100.
We also already employ the method of pinning the SSL VPN interface to local loopback interface on the FortiGate, then use firewall policies to help block access to a variety of IP reputation lists, block lists, swatfeeds, IPS policies, DOS policies, and so forth. (This was a huge help to knock down the volume of attacks!)
Here is example of one FortiGate Failed Authentication attempts. My human eyes can see the pattern rather quickly, and daily we look at reports for the worst offenders and add them to our swat feed that our managed firewalls all subscribe to block those IP addresses. FYI-none of these usernames are actual usernames in their domain.

 
Any ideas? If the logs gave code or reason such as 'user does not exist', this would be easy!
Does Fortinet not offer the ability to control the 'login-attempt-limit' time window? It seems to be too short! Should be tiered options. 2 failures in 60 seconds, quarantine for 1 to 5 minutes, 5 failures in 24 hours, then quarantine IP for 24 hours.
I have had some thoughts, but the scripting and automation is beyond our abilities. Such as "block/quarantine IP for non-existing user" or "x number of failed attempts in a 24 hour period".
We use FortiAnalyzer inhouse and FortiSIEM via a partner.
