IMAP: Brute Force Login Attempt

This protocol anomaly detects multiple login failures within a short period of time between a unique pair of hosts. The number of login failures for triggering this attack can be configured in the Sensor Settings Rulebase of your Security Policy.

Extended Description

Multiple login failures within a short period could indicate that a brute force password guessing attack is taking place or has taken place.

Short Name
IMAP:FAILURE:BRUTE-FORCE
Severity
Major
Recommended
False
Recommended Action
None
Category
IMAP
Keywords
brute force imap
Release Date
01/27/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?