A company has enabled Amazon GuardDuty in all Regions as part of its security monitoring strategy. In one of the VPCs, the company hosts an Amazon EC2 instance working as an FTP server that is contacted by a high number of clients from multiple locations. This is identified by GuardDuty as a brute force attack due to the high number of connections that happen every hour.
The finding has been flagged as a false positive. However, GuardDuty keeps raising the issue. A Security Engineer has been asked to improve the signal-to-noise ratio. The Engineer needs to ensure that changes do not compromise the visibility of potential anomalous behavior.
How can the Security Engineer address the issue?
Ghostbusters
Highly Voted 3 years, 6 months agof4bi4n
3 years, 4 months agoz0mb133
2 years, 9 months agomunish3420
3 years, 6 months agosapien45
2 years, 8 months agomvsnogueira
Highly Voted 3 years, 6 months agoAnonymousJhb
3 years, 2 months agoRaphaello
Most Recent 1 year, 3 months agoITGURU51
2 years, 1 month ago[Removed]
2 years, 5 months agoMoreOps
3 years, 3 months agoRadhaghosh
3 years, 3 months agoCloudvin
3 years, 5 months agokhos77
3 years, 6 months agohubekpeter
2 years, 5 months agodeegadaze1
3 years, 6 months agoMichael679
3 years, 6 months agoTron09
3 years, 6 months agoRajeshNayyar
3 years, 6 months agoinf
3 years, 7 months agorichasskikr
3 years, 7 months ago[Removed]
3 years, 6 months agoinf
3 years, 7 months agomychiv
3 years, 7 months agoucsdmiami2020
3 years, 6 months ago