SIP.Register.Brute.Force

description-logoDescription

This indicates detection of SIP Register Brute Force attempts.
The attack consists of multiple SIP register requests intended to conduct a brute force attack, launched at a rate of about 5 times in 10 seconds.

affected-products-logoAffected Products

all vulnerable applications utilizing the SIP protocol

Impact logoImpact

System Compromise: Remote attackers can gain access to the service provided by the vulnerable systems.

recomended-action-logoRecommended Actions

Monitor the traffic from that network for any suspicious activity.
Adjust the threshold for the signature accordingly.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-04-17 14.596 Sig Added
2019-04-03 14.585 Sig Added
2018-11-20 13.494