6.6.1.3 Ensure Minimum Backoff Factor of 5

Information

A minimum of 5 seconds should be used for the backoff factor.

Rationale:

Remote administration protocols like Telnet and SSH are commonly targeted by Brute Force or Dictionary attacks where a malicious user attempts to guess a valid username/password combination in order to gain control of the router. To slow down the rate at which an attacker can attempt to guess passwords Juniper routers can initiate a backoff timer when a user login fails more times than a configured threshold. Once initiated the backoff will not allow a further login attempt by the user for a configured (see next recommendation) period of time called the backoff factor. After the next failed login attempt further logins will not be allowed for the 2x the backoff factor, then 3x and so on.

Solution

Configure the backoff threshold using the following command under the [edit system] hierarchy:

[edit system]
user@host#set login retry-options backoff-factor

Default Value:

For most JUNOS version the default is to backoff factor of 5 seconds.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|16

Plugin: Juniper

Control ID: 64d3dff85c7e10aafe4e3b300c90a225699af2200bdd2f0b509b84971f0078d8