DoS/Brute Force [Not Directly IDP Related]

Joshua Brodie josbrodie at gmail.com
Tue Aug 22 16:23:32 EDT 2017


Not directly Shibboleth related.....but there is no better audience than
this user group, I will live with taking the risk of posting off topic.

Assuming you don't have a big budget -- and no infrastructure defenses --
beyond bare bones firewall -- how would you protect the IdP from a DoS type
attack...

We have had brute force attacks -- which become DoS events due to the
load....are thinking of implementing Fail2Ban (it won't protect against DoS
but at least we will be alerted and can mitigate brute force by shutting
down the IP on the server level -- the upstream firewall will only kick in
after a few hours due to manual update by external vendor).

Any other thoughts?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170822/65f12917/attachment.html>


More information about the users mailing list