SSH Brute Force Detection

This rule detects potential SSH brute force attacks by identifying multiple failed password attempts from a single source IP address to a specific computer within a 5-minute window. It specifically looks for 'Failed password' messages in syslog entries from the 'sshd' process.