Forum Discussion
OTP Flood Attack mitigation
Hi ,
sure. Can you explain in 3-4 sentences about the attack. As much as you know... Is it always same IP, rotating IP, always same user-agent string? Also please explain about the process of requesting an OTP.
Knowing this can help to find the right mitigation strategy for your issue.
Bonus question - do you have IP Intelligence licensed?
KR
Daniel
- JaspreetgurmSep 10, 2021Altocumulus
HI
Thanks for quick reply.
IP rotating always, looks like at attacker setup some sort of script which has more than lakh phone numbers requesting for OTP same time.
So can we mitigate such attacks.
- Daniel_WolfSep 10, 2021MVP
Yes, I would setup a Bot Defense profile and I'd also enable Device ID in this profile.
In this solution article you will find all settings for creating a Bot Defense profile explained.
K42323285: Overview of the unified Bot Defense profile
Additionally check out this lab guide from Agility 2021, it will give you some rough idea how to set up Bot Defense with Device ID.
https://clouddocs.f5.com/training/community/waf/html/waf241/module1-elevated-bot/lab1/lab1.html
- Daniel_WolfSep 12, 2021MVP
Hey ,
could you mitigate the attack with a bot defense profile? In case you cannot share further details of the attack, you can DM me and I can try to help you.
KR
Daniel
- JaspreetgurmSep 13, 2021Altocumulus
Hi Daniel,
bot profiles is already configured with device ID enabled and enforcement mode is set to transparent in system.
As i have verified other settings there is no brute force attack/DOS protection enabled for virtual server. The Application security policy configured with minimal protection as only few parameters are set to block or alarm. Could you please suggest which parameters should be blocked ?
Also could you please let me know how to collect such flood type request in application event logs to prepare report on it.
thanks
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com