Spring Security: Prevent brute force attack
Spring Security can do lot of stuff for you.
Account blocking, password salt. But what about brute force blocker.
That what you have to do by yourself.
Fortunately Spring is quite flexible framework so it is not a big deal to configure it.
Let me show you little guide how to do this for Grails application.
First of all you have to enable springSecurityEventListener in your config.groovy
1 | grails.plugins.springsecurity.useSecurityEventListener = true |
then implement listeners
in /src/bruteforce create classes
01 02 03 04 05 06 07 08 09 10 11 12 13 | /** Registers all failed attempts to login. Main purpose to count attempts for particular account ant block user */ class AuthenticationFailureListener implements ApplicationListener { LoginAttemptCacheService loginAttemptCacheService @Override void onApplicationEvent(AuthenticationFailureBadCredentialsEvent e) { loginAttemptCacheService.failLogin(e.authentication.name) } } |
next we have to create listener for successful logins
in same package
01 02 03 04 05 06 07 08 09 10 11 12 | /** Listener for successfull logins. Used for reseting number on unsuccessfull logins for specific account */ class AuthenticationSuccessEventListener implements ApplicationListener{ LoginAttemptCacheService loginAttemptCacheService @Override void onApplicationEvent(AuthenticationSuccessEvent e) { loginAttemptCacheService.loginSuccess(e.authentication.name) } } |
We were not putting them in our grails-app folder so we need to regiter these classes as spring beans.
Add next lines into grails-app/conf/spring/resources.groovy
1 2 3 4 5 6 7 8 9 | beans = { authenticationFailureListener(AuthenticationFailureListener) { loginAttemptCacheService = ref( 'loginAttemptCacheService' ) } authenticationSuccessEventListener(AuthenticationSuccessEventListener) { loginAttemptCacheService = ref( 'loginAttemptCacheService' ) } } |
You probably notice usage of LoginAttemptCacheService loginAttemptCacheService
Let’s implement it. This would be typical grails service
01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 | package com.picsel.officeanywhere import com.google.common.cache.CacheBuilder import com.google.common.cache.CacheLoader import com.google.common.cache.LoadingCache import java.util.concurrent.TimeUnit import org.apache.commons.lang.math.NumberUtils import javax.annotation.PostConstruct class LoginAttemptCacheService { private LoadingCache attempts; private int allowedNumberOfAttempts def grailsApplication @PostConstruct void init() { allowedNumberOfAttempts = grailsApplication.config.brutforce.loginAttempts.allowedNumberOfAttempts int time = grailsApplication.config.brutforce.loginAttempts.time log.info 'account block configured for $time minutes' attempts = CacheBuilder.newBuilder() .expireAfterWrite(time, TimeUnit.MINUTES) .build({ 0 } as CacheLoader); } /** * Triggers on each unsuccessful login attempt and increases number of attempts in local accumulator * @param login - username which is trying to login * @return */ def failLogin(String login) { def numberOfAttempts = attempts.get(login) log.debug 'fail login $login previous number for attempts $numberOfAttempts' numberOfAttempts++ if (numberOfAttempts > allowedNumberOfAttempts) { blockUser(login) attempts.invalidate(login) } else { attempts.put(login, numberOfAttempts) } } /** * Triggers on each successful login attempt and resets number of attempts in local accumulator * @param login - username which is login */ def loginSuccess(String login) { log.debug 'successfull login for $login' attempts.invalidate(login) } /** * Disable user account so it would not able to login * @param login - username that has to be disabled */ private void blockUser(String login) { log.debug 'blocking user: $login' def user = User.findByUsername(login) if (user) { user.accountLocked = true ; user.save(flush: true ) } } } |
We will be using CacheBuilder from google guava library. So add next line to BuildConfig.groovy
1 2 3 | dependencies { runtime 'com.google.guava:guava:11.0.1' } |
And the last step add service configuration to cinfig.groovy
1 2 3 4 5 | brutforce { loginAttempts { time = 5 allowedNumberOfAttempts = 3 } |
That’s it, you ready to run you application.
For typical java project almost everething will be the same. Same listeners and same services.
More about Spring Security Events
More about caching with google guava
Grails user can simple use this plugin https://github.com/grygoriy/bruteforcedefender
Happy coding and don’t forget to share!
Reference: Prevent brute force attack with Spring Security from our JCG partner Grygoriy Mykhalyuno at the Grygoriy Mykhalyuno’s blog blog.
