You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Java网络编程:登录验证失败后如何永久封禁客户端IP?

Implementing Permanent IP Ban After 4 Failed Login Attempts

Great question! Implementing permanent IP bans after repeated failed logins is a solid security measure for your client-server program. Let's walk through how to build this step by step, with practical examples:

Core Logic Breakdown

First, you need three key components in your server code:

  • A way to track failed login attempts per client IP
  • A permanent ban list to block repeat offenders
  • A modified login flow that enforces the attempt limit and ban rule

Step 1: Track Attempts & Validate IP on Connection

Every time a client connects, your server should first check if their IP is already banned. If it is, immediately close the connection. If not, start tracking their login attempts.

Use a data structure like a dictionary to map IP addresses to their failed attempt count, and a set to store permanently banned IPs (for fast lookups). For persistence (so bans survive server restarts), save these to a file or database instead of just keeping them in memory.

Step 2: Enforce Login Attempt Limit

Here's the modified login flow:

  1. On client connection, check if the IP is in the banned list → reject if yes.
  2. Accept username/password input from the client.
  3. If credentials are invalid:
    • Increment the failed attempt count for that IP.
    • If the count hits 4: add the IP to the banned list, send a ban notification, and close the connection.
    • If not, send a message telling the client how many attempts they have left.
  4. If credentials are valid: reset the failed attempt count for that IP, and proceed with the session.

Step 3: Persist Ban Data (Critical!)

Memory-only storage (like a Python dict or set) will lose all ban data when the server restarts. For a permanent solution:

  • Use a lightweight database like SQLite for small-scale apps.
  • For production, use a full database (MySQL/PostgreSQL) plus a cache (Redis) to speed up IP checks.
  • Alternatively, write the banned IPs to a JSON/CSV file and load it when the server starts.

Example Code Snippet (Python TCP Server)

Here's a simplified example to illustrate the logic:

import socket
from collections import defaultdict

# Track failed attempts: key = client IP, value = number of failures
failed_attempts = defaultdict(int)
# Permanent ban list (use a database/file for persistence)
banned_ips = set()
# Preserved valid credentials
VALID_USERNAME = "admin"
VALID_PASSWORD = "server123"

def handle_client_connection(conn, client_addr):
    client_ip = client_addr[0]
    
    # Check if IP is banned first
    if client_ip in banned_ips:
        conn.send(b"Error: Your IP has been permanently banned.")
        conn.close()
        return
    
    # Allow up to 4 login attempts
    for attempt in range(4):
        # Receive credentials (simplified: expect "username,password" format)
        raw_creds = conn.recv(1024).decode().strip()
        username, password = raw_creds.split(",") if "," in raw_creds else ("", "")
        
        if username == VALID_USERNAME and password == VALID_PASSWORD:
            conn.send(b"Login successful!")
            # Reset failed attempts for this IP
            failed_attempts[client_ip] = 0
            # Proceed with your application logic here...
            break
        else:
            failed_attempts[client_ip] += 1
            remaining_attempts = 4 - failed_attempts[client_ip]
            if remaining_attempts > 0:
                conn.send(f"Invalid credentials. {remaining_attempts} attempts left.".encode())
            else:
                # Ban the IP permanently
                banned_ips.add(client_ip)
                conn.send(b"4 failed attempts. Your IP is now permanently banned.")
    
    conn.close()

# Server setup code (omitted for brevity)
# ...

Key Considerations

  • NAT Networks: Be cautious with permanent bans if your clients might share an IP (like office/home NATs). You might want to combine IP tracking with device identifiers if possible.
  • Unban Mechanism: Add an admin interface to remove IPs from the ban list in case of false positives.
  • Security: To prevent IP spoofing, make sure your server correctly identifies the client's real IP (especially if using proxies).

内容的提问来源于stack exchange,提问作者Brianna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:48:14