Strange behavior: lots of logins by one user
Raja V, Scientist - B (CS)
raja at inflibnet.ac.in
Fri Feb 1 07:09:51 EST 2019
We have developed the Stats System to track the users. You may use this
code and block from identity system.
https://parichay.inflibnet.ac.in/features.php
On Fri, Feb 1, 2019 at 5:05 PM Manolo Garcia Alvarez <mgarciaal at uoc.edu>
wrote:
> Thanks Jim,
>
> an anti-DDoS policy is a great idea, but we'd prefer to identify first the
> source of the problem. I'm still on it.
>
> If we don't manage to get the answer, I suppose we'll end up with a
> anti-DDoS policy in our viprion.
>
> Thanks again !
>
> ------------------------------
> Manolo García
> Arquitectura i Sistemes
> Universitat Oberta de Catalunya
>
> 93 326 (3451) | 689 88 30 93 | mgarciaal at uoc.edu
> Parc Mediterrani de la Tecnologia (edifici B3)
> Av. Carl Friedrich Gauss, 5.
> 08860 Castelldefels
> [image: Universitat Oberta de Catalunya]
> Aquest missatge s'adreça exclusivament a qui va destinat i pot contenir
> informació privilegiada o confidencial i dades de caràcter personal, la
> difusió de les quals és regulada per la Llei orgànica de protecció de dades
> i la Llei de serveis de la societat de la informació. Si no sou la persona
> destinatària indicada (o la responsable de lliurar-lo a qui va destinat),
> no heu de copiar aquest missatge ni lliurar-lo a tercers per cap concepte.
> Si heu rebut aquest missatge per error o l'heu aconseguit per altres
> mitjans, us demanem que ens ho comuniqueu immediatament per aquesta mateixa
> via i l'elimineu irreversiblement.
>
> Abans d'imprimir aquest missatge electrònic penseu en el medi ambient.
>
>
> El jue., 31 ene. 2019 a las 19:07, Jim Fox (<fox at washington.edu>)
> escribió:
>
>>
>> > We are reducing the suspects to Google Suite (which is the SP that's
>> causing the logins), an specific browser or a combination of both. About
>> your
>> > "Force Authentication" suggestion, we are running 3,1 and this is a
>> production environment and will affect a lot of users, so I don't think it's
>> > possible. We're now trying to identify the browser of the users with
>> huge number of logins, but as you said it's clear the problem it's on the
>> > SP.
>>
>> We have had this issue for many years and never did figure out what the
>> cause is. I suspect phone apps, for no really good reason.
>>
>> We mitigate the problem by temporarily denying access to clients that hit
>> the IdP at too rapid a rate. First we used mod_evasive, now we use
>> scripts on our F5 traffic manager. Essentually any client that makes,
>> say, 20 requests in 10 seconds gets blocked for a minute. (Not the exact
>> numbers.) Sometimes this stops the offender. Sometime they come back in
>> a minute.
>>
>> Jim--
>> For Consortium Member technical support, see
>> https://wiki.shibboleth.net/confluence/x/coFAAg
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190201/6e9d178c/attachment.html>
More information about the users
mailing list