AWS Verified Access anomalous failed authentication attempts by IP

aws

Classification:

attack

이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect when access is denied to an IP authenticating using AWS Verified Access.

Strategy

The anomaly detection generates a security signal when an IP’s authentication failure requests deviates from its baseline.

For more information about the anomaly detection method, see Detect security threats with anomaly detection rules.

Triage and response

Determine if the IP {{@network.client.ip}} should have access.