Question
HTTPS Bruteforce signature - rate limit
Hi,
I am trying to create a custom signature for HTTPS Bruteforce detection (SSL inspection enabled) and I have the following syntax: F-SBID (--name Website.Brute.Force.CustomBody; --protocol TCP; --flow from_server; --pattern "failed because"; --context body; --rate 5,45,limit; --track SRC_IP;)
it is based on server "failed" answers, but even if the rate is 5,45 sometimes alert is triggered even earlier (3,4 attempts) Does anyone know how to mitigate that, or what to change to have more accurate detection.
Thx in advance!
BR Petr Bucek
