Infineon Security Platform Solution |
Dictionary Attack User Interface
Notes:
|
The Security Platform Owner and administrator is responsible for dictionary attack settings and defense measures. In case of repeatedly mistyped passwords and in case of a real dictionary attack the Security Platform User is informed accordingly.
The following table lists dictionary attack related user interface parts:
Configure dictionary attack threshold |
The Security Platform Owner or an authorized administrator can set the number of allowed failed authentication attempts before dictionary attack defending measures are taken. This can be done either via the configuration of Security Platform Features, or via policy Configure dictionary attack threshold. |
Defense level reset |
Stand-alone mode: The Owner Password is required to perform this operation. You can either type in the Owner Password or provide an Owner Password Backup File. Make sure to provide the correct password. After multiple wrong owner authentication, your Security Platform will be temporarily locked. During this time you will not be able to reset the dictionary attack defense level any more. Server mode:
If the administrator knows the Owner Password, the defense level can also be reset locally by starting the Security Platform Initialization Wizard SpTPMWz.exe with the command line parameter −resetattack or /resetattack. This is the only allowed usage of Security Platform Initialization Wizard in server mode. |
Notifications and warnings |
Messages explaining the current state and dictionary attack defense measures are displayed in the following situations:
In the case of a real dictionary attack (not caused by accidental failed authentications) an alarm error message is displayed. |
©Infineon Technologies AG