IMAP: Brute Force Login Attempt
This protocol anomaly detects multiple login failures within a short period of time between a unique pair of hosts. The number of login failures for triggering this attack can be configured in the Sensor Settings Rulebase of your Security Policy.
Extended Description
Multiple login failures within a short period could indicate that a brute force password guessing attack is taking place or has taken place.
References
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3