THINK FIRST·CODE LATER

← All labs

Brute-force protection: account lockout

Problem

Implement requirement SEC-3 (an EARS requirement from Chapter 4):

If a login for an account fails 5 times within 10 minutes, then the system shall lock the account for 15 minutes. While an account is locked, every login attempt is rejected (even with the correct password) and does not extend the lock. A successful login resets the failure count.

Input: events minute username OK|FAIL, in non-decreasing order of time, until the end of input. "Within 10 minutes" means the 5 failures happened at times t1 … t5 with t5 - t1 < 10. A lock that starts at minute L ends at minute L + 15 (an attempt at minute L + 15 is allowed again). Failures from before a lock do not count after it ends.

Output per event:

  • t user: SUCCESS / t user: FAILED (n recent) where n is the number of failures of this user within the 10-minute window ending now (including this one);
  • when the 5th failure triggers the lock: t user: FAILED (5 recent) -> LOCKED until L+15;
  • when locked: t user: REJECTED (locked until X).

At the end: Locks: k.

Input:

0 yuki FAIL
1 yuki FAIL
2 yuki FAIL
3 yuki FAIL
4 yuki FAIL
5 yuki OK
19 yuki OK
20 yuki OK

Output:

0 yuki: FAILED (1 recent)
1 yuki: FAILED (2 recent)
2 yuki: FAILED (3 recent)
3 yuki: FAILED (4 recent)
4 yuki: FAILED (5 recent) -> LOCKED until 19
5 yuki: REJECTED (locked until 19)
19 yuki: SUCCESS
20 yuki: SUCCESS

Write it here or in your IDE, then paste it. Compile and test it yourself before comparing. Your code stays in your browser — it is never sent to or stored on the server.