From 4c5ee689f28f31df6ca4328f6b08a46e49092a01 Mon Sep 17 00:00:00 2001 From: Yamin Zeadneh Date: Mon, 27 Jul 2026 20:35:23 +0300 Subject: [PATCH] 2nd task final --- Attack_Simulation/README.md | 47 +++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) diff --git a/Attack_Simulation/README.md b/Attack_Simulation/README.md index 737f56e..94e41eb 100644 --- a/Attack_Simulation/README.md +++ b/Attack_Simulation/README.md @@ -39,3 +39,50 @@ - Re-enable affected user accounts with new credentials. - Continue monitoring logs for suspicious authentication attempts. - Validate that security controls (MFA, rate limiting, monitoring) are functioning correctly. +## Preventing the Attack on Ghaymah + +### 1. Network Policies + +- Apply **Rate Limiting** on the `/api/login` endpoint to limit the number of login attempts from a single IP address. +- Configure **Kubernetes Network Policies** so that only the API service can communicate with the PostgreSQL database. +- Deploy a **Web Application Firewall (WAF)** to filter malicious requests and block brute force attacks. +- Restrict access to internal services by allowing traffic only from trusted containers and namespaces. +- Enable automatic IP blocking after multiple failed authentication attempts. +- Encrypt all communication using **HTTPS/TLS** to protect authentication traffic. + +### 2. Container Security + +- Run containers as **non-root** users to minimize the impact of a container compromise. +- Use trusted and regularly updated base images to reduce known vulnerabilities. +- Store passwords, API keys, and JWT secrets in **Kubernetes Secrets** or a secure secret manager instead of environment variables or Docker images. +- Continuously scan container images with tools such as **Trivy** before deployment. +- Apply the **Principle of Least Privilege** by granting containers only the permissions they require. +- Enable centralized logging and monitoring for all containers to quickly detect suspicious authentication activity. + +## Alert Rule (Splunk SPL) +normally request look something like +```json +{ + "timestamp": "2026-07-27T09:42:11Z", + "src_ip": "192.168.1.50", + "endpoint": "/api/login", + "method": "POST", + "status": 401, + "username": "admin", + "user_agent": "Mozilla/5.0" +} +``` +so we can make SPL code like +```spl +index=api_logs endpoint="/api/login" status=401 +| bucket span=1m _time +| stats count by src_ip, _time +| where count >= 20 +``` + +**Alert Condition** + +- Trigger when a single IP generates **20 or more failed login attempts within 1 minute**. +- Alert severity: **High**. +- Send an email notification to the SOC team. +- Automatically block the source IP for 15 minutes using the firewall or WAF. \ No newline at end of file