Replay Attack Check

Microsoft.Windows.RemoteAccess.Monitor.DA_DOSP_HEURISTIC_REPLAY_ATTACK (UnitMonitor)


A network security component is under a Replay attack. A Replay attack is a form of network attack in which a valid
data transmission is maliciously or fraudulently repeated or delayed.

Knowledge Base article:

Summary

A network security component is under a Replay attack. A Replay attack is a form of network attack in which a valid data transmission is maliciously or fraudulently repeated or delayed.

Causes

The server is receiving a large number of packets that have failed Replay detection.

Resolutions

1. A Replay attack might be underway. Monitor the server for signs of an attack. If an attack is detected, take mitigation measures to stop it.

2. Check for network errors as these will generate high counters.

Element properties:

TargetMicrosoft.Windows.RemoteAccess.DirectAccessServer.Class
Parent MonitorSystem.Health.SecurityState
CategoryCustom
EnabledTrue
Alert GenerateTrue
Alert SeverityError
Alert PriorityNormal
Alert Auto ResolveTrue
Monitor TypeMicrosoft.Windows.RemoteAccess.Monitor.Heuristic.MonitorType
RemotableTrue
AccessibilityPublic
Alert Message
Potential Replay Attack

Error Description - {0}
Error Cause - {1}
Error Resolution - {2}
RunAsDefault