Newbie517762 Lv5Posted 12 Mar 2024 17:41
  
This is facing an issue with brute force detection not working effectively after changing the cookie structure on their Sangfor WAF. They are solutions and best practices to mitigate brute force attacks.


Solutions:
  • Update cookie validation logic to consider the updated cookie structure.
  • Check cookie expiration time to ensure effectiveness in detecting ongoing attacks.
  • Implement IP address-based blocking as an additional security measure.
  • Enable two-factor authentication (2FA) for user accounts.
  • Use rate limiting to restrict login attempts from a single source.
  • Incorporate CAPTCHAs to distinguish legitimate users from automated bots.


Best Practices:
  • Use strong passwords and enforce regular password changes.
  • Implement account lockout policies after failed login attempts.
  • Monitor logs for suspicious activities and investigate anomalies.
  • Keep software and security patches up to date.
  • Educate users about security best practices.

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders