A security analyst is reviewing a SIEM alert for a critical web application. The alert, generated by a correlation rule, indicates 'Multiple Failed Login Attempts from Geographically Disparate Locations within 5 Minutes'. The baseline for this application shows users typically log in from a single, consistent location. What type of attack is this correlation rule designed to detect?
- ACross-Site Scripting (XSS)
- BSession Hijacking
- CImpossible Travel
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: C. Impossible Travel
The 'Multiple Failed Login Attempts from Geographically Disparate Locations within 5 Minutes' directly describes an 'Impossible Travel' scenario. This type of correlation rule identifies when a user (or the same credentials) appears to log in or attempt to log in from locations that are physically impossible to reach within the time frame, strongly indicating compromised credentials being used by an attacker from a different location.
Why the other options are wrong
- A. XSS attacks inject malicious scripts into web pages and are not detected by analyzing login attempt locations.
- B. Session hijacking involves taking over an active user session and doesn't manifest as 'multiple failed login attempts from disparate locations'.
- D. SQL Injection targets database vulnerabilities through input fields and would not be directly detected by 'geographically disparate login attempts'.
Impossible Travel Detection
A security monitoring technique, often implemented in SIEMs or UEBA systems, that detects suspicious user activity where a user account is accessed from two geographically distant locations within an impossibly short time frame, indicating compromised credentials.
- Compares login/access locations and timestamps.
- Requires baseline understanding of user login patterns.
- Strong indicator of compromised credentials or account takeover.
Memory trick: A user can't be in two places at once, if they are, someone else is moving.