AWS Verified Access anomalous failed authentication attempts by IP

aws

Classification:

attack

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when access is denied to an IP authenticating using AWS Verified Access.

Strategy

The anomaly detection generates a security signal when an IP’s authentication failure requests deviates from its baseline.

For more information about the anomaly detection method, see Detect security threats with anomaly detection rules.

Triage and response

Determine if the IP {{@network.client.ip}} should have access.