SSH Brute-Force Attack Inbound Rapid Auth Attempts by Source IP

This rule monitors incoming TCP traffic on port 22 (SSH) and alerts when a single source IP address exhibits an excessive number of authentication attempts within a 60-second window, which is indicative of a brute-force attack against the SSH service.