Cisco LDP Authentication Failures

 Original Source: [Sigma source]
Title: Cisco LDP Authentication Failures
Status: test
Description:Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
References:
  -https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf
Author: Tim Brown
Date: 2023-01-09
modified:None
Tags:
  • -'attack.initial-access'
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.credential-access'
  • -'attack.collection'
  • -'attack.stealth'
  • -'attack.t1078'
  • -'attack.t1110'
  • -'attack.t1557'
Logsource:
  • product: cisco
  • service: ldp
  • definition: Requirements: cisco ldp logs need to be enabled and ingested
Detection:
  selection_protocol:
    - 'LDP'
  selection_keywords:
    - 'SOCKET_TCP_PACKET_MD5_AUTHEN_FAIL'
    - 'TCPMD5AuthenFail'
  condition:selection_protocol and selection_keywords
Falsepositives:
  -Unlikely. Except due to misconfigurations
Level: low