Skip to main content
dzimofuk
New Member
October 31, 2016
Question

HTTPS Bruteforce signature - rate limit

  • October 31, 2016
  • 5 replies
  • 5847 views

Hi,

I am trying to create a custom signature for HTTPS Bruteforce detection (SSL inspection enabled) and I have the following syntax: F-SBID (--name Website.Brute.Force.CustomBody; --protocol TCP; --flow from_server; --pattern "failed because"; --context body; --rate 5,45,limit; --track SRC_IP;)

it is based on server "failed" answers, but even if the rate is 5,45 sometimes alert is triggered even earlier (3,4 attempts) Does anyone know how to mitigate that, or what to change to have more accurate detection.

Thx in advance!

BR Petr Bucek

5 replies

ede_pfau
SuperUser
SuperUser
October 31, 2016

I think you should use

--flow from_server,reversed;
See post #102544 for example.

dzimofuk
dzimofukAuthor
New Member
November 1, 2016

Hi,

 

thx for your answer, but even if i added "reversed" the detection is not working properly.

F-SBID(--name Website.Brute.Force; --protocol TCP; --flow from_server,reversed; --pattern "failed because"; --context body; --rate 6,60,limit; --track SRC_IP;) The behavior is the same like before, (example: even 4 attempts generate 3 alarms etc.)

dzimofuk
dzimofukAuthor
New Member
November 3, 2016

noone knows?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!