AWS Verified Access anomalous failed authentication attempts by IP

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Goal

Detect when access is denied to an IP authenticating using AWS Verified Access.

Strategy

The anomaly detection generates a security signal when an IP’s authentication failure requests deviates from its baseline.

For more information about the anomaly detection method, see Detect security threats with anomaly detection rules.

Triage and response

Determine if the IP {{@network.client.ip}} should have access.