A brute-force attack is a trial-and-error method used to obtain unauthorized access to resources. An IPS platform detects repeated failed login attempts as well as common password-stealing and password-guessing mechanisms, such as dictionary attack. By analyzing the pattern and volume of activities and hosts, the IPS-enabled rules engine can distinguish between brute force attacks and valid network traffic. The platform triggers a brute-force event when the number of failed login attempts to or from the same IP address reaches a certain threshold within a 60‑second rolling window. You can configure the number of failed login attempts that triggers a brute-force event. For details, see Configuring the detection threshold for brute-force attacks (CLI).
Brute-force detection is enabled if an active IPS policy selects one or more IPS brute-force rules.
IPS brute-force events do not trigger FireEye event notifications and cannot be acknowledged.
Protocol ports supported
The IPS-enabled rules engine detects brute-force attacks by applications that use ports for the following protocols. The list is dynamic, and Trellix controls the list through periodic updates of IPS security content.
IPv4 FTP
IPv4 Mysql
IPv4 Postgress
IPv4 rsh
IPv4 SMB
Additional protocol ports supported in detailed inspection mode
To protect additional protocol ports from brute-force attacks, you can enable the IPS rules engine to operate in detailed inspection mode. In this mode, the rules engine performs a more detailed inspection of packets than it does when operating in default mode. The list of protocol ports that require detailed inspection mode is dynamic, and Trellix controls the list through periodic updates of IPS security content.
At the time of this release, detailed inspection mode enables the platform to detect brute-force attacks by applications that use ports for the following protocols:
IPv4 Telnet
IPv4 VNC
IPv4 rlogin
IPv6 Telnet
IPv6 FTP
Caution
IPS detailed packet inspection may slow IPS processing.