In the Navigation tree, double-click Groups. The Groups Search page is

Managing Policies, Rules, and Conditions 10-53

h. Click OK.

i. Add IPs to monitor as needed.

3. Create an IP Surge High Alert group

1. In the Groups Search page, click the New Group button.

The Create Group screen appears. 2. Enter the group name, IP Surge, and select Alerts as the Group type and click Create . A confirmation message appears.

3. Click OK to dismiss the confirmation dialog.

The new IP Surge alert group is created successfully and the Group Details page is displayed.

4. Click the Alerts tab to add alerts to the group.

5. In the Alerts tab, click the Add Add Member button.

6. In the Add Member page, select Create new element.

7. For Alert Type, select Investigator.

8. For Alert Level, select High.

9. For Alert Message, enter More than 10 logins from the same IP in 1 hour.

10. Click Add to add the alert to the group.

A confirmation dialog appears.

11. Click OK to dismiss the dialog.

4. In the Navigation tree, double-click Policies.

5. In the Policies Search page, click the New Policy button.

The New Policy page appears. In the Summary tab, the default values for the new policy are displayed as follows: ■ Policy Status: Active ■ Checkpoint: Pre-Authentication ■ Scoring Engine: Average ■ Weight: 100 6. Create a new pre-authentication security policy.

a. For Policy Name, enter Logins_SameIP.

b. For Description, enter Track the number of logins from the same IP and if

there are more than 10 logins in the last hour from an IP .

c. Select Active as the policy status; otherwise the policy is not enforced at the

checkpoint.

d. Enter Weighted Maximum Score for the scoring engine and 100 as the weight.

e. Click Apply.

A confirmation dialog displays the status of the operation. If you click Apply and the required fields are not filled in an error message is displayed. 10-54 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

f. Click OK to dismiss the confirmation dialog.

7. Configure the policy to run for all users.

a. Click the Group Linking tab.

b. For Run Mode, select All Users.

Since All Users is selected for the run mode, the policy is executed run for all users. Specifying a run mode is a mandatory step in order for the policy to execute. It enables the policy to executerun for a set of users or all users. For information, see Section 10.9, Linking Policy to All Users or a User ID Group.

c. Click Apply.

A confirmation dialog displays the status of the operation.

d. Click OK to dismiss the confirmation dialog.

8. Create IP Excessive Use rule for the policy.

a. Click the Rules tab.

b. In the Rules tab, click Add to add a new rule.

The New Rule page is displayed. c. In the Summary tab, enter IP Excessive Use as the rule name. d. Enter a description for the rule.

e. Select Active as the rule status.

f. Add the Location: IP excessive use rule condition to create the new rule.

a. To add the Location: IP excessive use condition, click the Conditions tab.

b. In the Conditions tab, click Add. The Add Condition page appears.

c. Search for the Location: IP excessive use condition by entering IP in the

Condition Name field and then clicking Search.

d. In the Search Results table, select that condition and click OK.

e. In the New RuleIP page, select Location: IP excessive use in the top

panel. The bottom panel displays the parameters of the condition. f. In the bottom panel, modify the parameters. Enter 10 for Number of Users. Select 1 for Within hours. Enter 0 for and not used in days. 9. Create the Location: IP in Group rule for the policy. a. Click the Rules tab in the Policy Details page. b. In the Rules tab, click Add to add a new rule. The New Rule page is displayed.

c. In the Summary tab, enter IP in Group as the rule name.

d. Enter a description for the rule.

e. Select Active as the rule status.