For this Discussion I thought that I would focus on Brute Force Attacks. During my day-to-day
operations I see a large amount of brute force attacks and attempts on our systems. A brute force
attack is a hacking method where attackers consistently test login credentials until a valid response is
determined. This can be automated to test most common or a guessing algorithm. The information
that could be obtained by successfully pulling off a brute force attack could be detrimental. Once
access has been gained, it could become more difficult to secure a system or account. And, at that
point the best assumption is that the damage has already been done.
In 2021, Forbes published an article stating that Russia may have been to blame for a two-year
campaign to break into Microsoft Office 365 accounts. The accusation came from the NSA, FBI and
DHS in which they claimed that “Fancy Bear” a Russian General Staff Main Intelligence Directorate
was behind the brute force attacks. The technique utilized here was password spraying, simply
trying to login to a system by trying usernames and passwords as quickly as possible.
Of course, in an instance like this, recommendations had been made and the idea of educating the
Users is a key part of securing an account or system against a brute force attack. The
recommendations were to utilize multi-factor authentication and a lockout feature be put in place so
that multiple failures at logging in would at least slow down the attempts.
Brewster, T. (2021). NSA And FBI Blame Russia for Massive “Brute Force” Attacks on Microsoft 365.
Forbes.Com, N.PAG