Detecting SSH bruteforce attacks using triggers in QoE [Документация VAS Experts]

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
en:dpi:qoe_analytics:cases:network_health:triggers_ssh_bruteforce [2025/12/10 16:03] elena.krasnobryzhen:dpi:qoe_analytics:cases:network_health:triggers_ssh_bruteforce [2025/12/10 16:03] (current) elena.krasnobryzh
Line 17: Line 17:
  
 The trigger for detecting SSH bruteforce attacks (name — "ssh bruteforce") is a system trigger and is available in "QoE analytics" → "Triggers and notifications" (disabled by default). The trigger for detecting SSH bruteforce attacks (name — "ssh bruteforce") is a system trigger and is available in "QoE analytics" → "Triggers and notifications" (disabled by default).
- 
-{{ :dpi:qoe_analytics:cases:network_health:triggers_ssh_bruteforce:dpiui2_triggers_bruteforce.png?nolink&600 |}} 
  
 === General trigger information === === General trigger information ===
Line 81: Line 79:
   * Select notification type — "Warning"   * Select notification type — "Warning"
   * This will create a notification in the SSG system   * This will create a notification in the SSG system
- 
-{{ :dpi:qoe_analytics:cases:network_health:triggers_ssh_bruteforce:dpiui2_triggers_bruteforce_alerting.png?nolink&600 |}} 
  
 You can get a link to the report via the notifications menu You can get a link to the report via the notifications menu
- 
-{{ :dpi:qoe_analytics:cases:network_health:triggers_ssh_bruteforce:dpiui2_triggers_bruteforce_notofication.png?nolink&400 |}} 
  
 Select the notification Select the notification
 Choose — "Details" Choose — "Details"
- 
-{{ :dpi:qoe_analytics:cases:network_health:triggers_ssh_bruteforce:dpiui2_triggers_bruteforce_notofication_details.png?nolink&400 |}} 
  
 Follow the report link — the report will open in a new browser window. Follow the report link — the report will open in a new browser window.