<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.vmssoftware.com/index.php?action=history&amp;feed=atom&amp;title=Intrusion_database</id>
	<title>Intrusion database - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.vmssoftware.com/index.php?action=history&amp;feed=atom&amp;title=Intrusion_database"/>
	<link rel="alternate" type="text/html" href="https://wiki.vmssoftware.com/index.php?title=Intrusion_database&amp;action=history"/>
	<updated>2026-04-30T16:33:28Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.3</generator>
	<entry>
		<id>https://wiki.vmssoftware.com/index.php?title=Intrusion_database&amp;diff=179&amp;oldid=prev</id>
		<title>Darya.zelenina: Created page with &quot;The &#039;&#039;&#039;intrusion database&#039;&#039;&#039; is a database of login failures kept by the Security Server process.  =Severity classes=  After one failed login attempt, the user becomes a &quot;...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.vmssoftware.com/index.php?title=Intrusion_database&amp;diff=179&amp;oldid=prev"/>
		<updated>2019-01-18T13:26:25Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;The &amp;#039;&amp;#039;&amp;#039;intrusion database&amp;#039;&amp;#039;&amp;#039; is a database of login failures kept by the &lt;a href=&quot;/index.php?title=Security_Server&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;Security Server (page does not exist)&quot;&gt;Security Server&lt;/a&gt; process.  =Severity classes=  After one failed login attempt, the user becomes a &amp;quot;...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The &amp;#039;&amp;#039;&amp;#039;intrusion database&amp;#039;&amp;#039;&amp;#039; is a database of login failures kept by the [[Security Server]] process.&lt;br /&gt;
&lt;br /&gt;
=Severity classes=&lt;br /&gt;
&lt;br /&gt;
After one failed login attempt, the user becomes a &amp;quot;Suspect&amp;quot;: the system begins to monitor the terminal, terminal server connection, or network connection where the login is taking place (whether failures from terminal class logins are counted by terminal is controlled by [[System parameter|LGI_BRK_TERM]]). As failures continue, the operating system not only records failures but takes restrictive measures. The person attempting login is monitored more closely and limited to a certain number of login retries within a limited period of time. Once a person exceeds either the retry or time limitation, he or she cannot log in for a while, even with a valid user name and password.&lt;br /&gt;
At a later point, the restriction eases, and login is allowed once again.&lt;br /&gt;
&lt;br /&gt;
==Suspect==&lt;br /&gt;
The suspect status is given to the user, terminal, terminal server connection, or network connection after one incorrect login attempt. It is maintained for [[System parameter|LGI_BRK_TMO]] (five minutes by default). If during that time another login attempt is failed, the monitoring period is increased by the value of [[System parameter|LGI_BRK_TMO]]. If during the monitoring period the maximum number of attempts [[System parameter|LGI_BRK_LIM]] (five by default) is exceeded, the status is changed to &amp;quot;Intruder&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
==Intruder==&lt;br /&gt;
The user, terminal, terminal server connection, or network connection with the Intruder status is denied login during a time period equal to the value of [[System parameter|LGI_HID_TIM]] (five minutes by default) multiplied by a random value between 1 and 1.5. If [[System parameter|LGI_BRK_DISUSER]] is set to 1, the DISUSER flag is set on the account so all subsequent login attempts are prevented.&lt;br /&gt;
&lt;br /&gt;
=Managing the Intrusion Database=&lt;br /&gt;
You can view the intrusion database with the SHOW INTRUSION command. This requires Security privilege.&lt;br /&gt;
You can delete intrusion records with DELETE/INTRUSION_RECORD. &lt;br /&gt;
&lt;br /&gt;
=See also=&lt;br /&gt;
* [https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c04623140| OpenVMS Guide to System Security]&lt;br /&gt;
* [[LGI parameters]]&lt;/div&gt;</summary>
		<author><name>Darya.zelenina</name></author>
	</entry>
</feed>