This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong.
xxxxxxxxxx
====== Detecting SSH bruteforce attacks using triggers in QoE ======
{{indexmenu_n>6}}
[[dpi:dpi_components:dpiui:user_guide:qoe_analytics:triggers_and_notifications|Triggers]] are used to search for data in the QoE Stor by specified parameters. After the trigger action one of the following steps is possible:
* notification in GUI
* HTTP action
* sending an email
\\
The required options of the Stingray Service Gateway:
* [[dpi:dpi_options:opt_statistics|]]
* [[dpi:dpi_options:opt_notify|]]
Required additional modules:
* [[dpi:dpi_components:dpiui|]]
* [[dpi:dpi_components:qoestor|]]
===== System trigger to detect SSH bruteforce attacks =====
Trigger to detect SSH bruteforce attacks (Name - "ssh bruteforce") is a system trigger and is available in the subsection "QoE Analytics" - "Triggers and Notifications" (disabled by default).
{{ dpi:qoe:use_cases:dpiui2_triggers_bruteforce.png?nolink&600 |}}
=== General trigger information ===
{{ dpi:qoe:use_cases:dpiui2_triggers_bruteforce_common.png?nolink&600 |}}
* The name of the trigger "ssh bruteforce";
* Days of the week - all;
* Checking frequency - every 10 minutes;