Intrusion detection andrew rowley
    Intrusion detection Synametrics Support

From: andrew rowley
Date: 12/12/17 10:55 AM
Topic: Intrusion detection
Type: General Discussions
Post a follow up

A suggestion.

 

The category of "Terminarion after authentication" in the intrusion detection menu, recommends adding the IP addresses to Xeams balcklist - why not include a button beside the address so it can be added to the blacklist.  Just easier than cut & paste?

 

Andrew

Top

From: Synametrics Support
Date: 12/14/17 9:14 AM
Topic: Intrusion detection
Type: General Discussions
Post a follow up

Andrew,

Blacklisting these IP in Xeams is not much of a value since that only affects how emails are scored. Since no email is being sent in this case, there is no value in adding the IP address. Xeams will automatically do three things if it detects too many incorrect logins attempts from a single IP:

  1. It will block the IP from authenticating - meaning even if they use the right combination of user id/password, Xeams wont' accept it
  2. It will log an entry in InvalidPasswordAttempts.log
  3. It will send an email alert to the administrator once the number of attempt goes beyond the configured threshold

A better location for blocking an IP that you see too in Intrusion detection is your firewall.

 

Top