AWS Verified Access anomalous failed authentication attempts by IP

aws

Classification:

attack

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when access is denied to an IP authenticating using AWS Verified Access.

Strategy

The anomaly detection generates a security signal when an IP’s authentication failure requests deviates from its baseline.

For more information about the anomaly detection method, see Detect security threats with anomaly detection rules.

Triage and response

Determine if the IP {{@network.client.ip}} should have access.