Configuring Policies for Login and Logout Events
Learn how to configure Database Firewall policy for login and logout events.
You can specify login and logout policies for database users. For example, configure to raise alerts or block database users who make a specified number of unsuccessful login attempts.
Prerequisite: In order to use a login or logout policy for a target database, you must activate database response monitoring when configuring the Database Firewall monitoring point for the specific target database.
To configure the login and logout policies:
-
Log in to the Oracle Database Security Central console as an auditor.
-
Select Policies
-
From the left navigation menu, select Database Firewall Policies.
-
Select the name of the specific policy.
-
In the Policy section, select Configuration.
-
Under the Login/Logout tab and Login section, configure the following:
-
Action: Specify the action for login sessions.
-
Threat Severity: Select the severity level for successful or unsuccessful database user logins.
-
Set Logging: Check this box to enable logging for logins and to view login session information in reports and alerts.
-
Failed Login: Optionally, select the checkbox Set failed login policy threshold.
This setting lets you produce an alert, or block a client program, after exceeding a specified number of consecutive unsuccessful logins. You can set a threshold and action.
If the threshold limit is reached, the login sessions are blocked for the specified Reset Period (in seconds). After this period, the client program login attempts are passed to the target database.
Note: Blocking a client program session after exceeding a specified number of consecutive unsuccessful logins is supported in Monitoring / Blocking (Proxy) deployment mode only.
-
-
Under the Logout section, configure the following:
-
Action: Specify the action on logout sessions (whether to pass or alert).
-
Threat Severity: Select the severity level for successful or unsuccessful database user logouts.
-
Set Logging: To view logout session information in reports or alerts.
-
-
Select Save in the top right corner.