How does amaise protect against brute force attacks?
amaise uses a multi-layered protection against brute force attacks:
Authentication level: Maximum 5 attempts per user ID and IP address. If exceeded, access is automatically locked and the user is notified. Suspicious IP addresses are automatically throttled.
Web Application Firewall (WAF): Rate limiting of 100 requests per 5 minutes per IP address on public and analytics endpoints. Configured at CDN and load balancer levels.
Geo-blocking: Unauthorized countries are blocked at both WAF levels (CDN and load balancer).
IP reputation: A managed rule automatically blocks known malicious IP addresses.
These measures work independently and together provide comprehensive protection.