The document discusses a method for detecting online password attacks through high-level protocol analysis and clustering techniques, emphasizing the inadequacy of existing host-based solutions in the face of increasing cyber threats. A novel network-based monitoring system is proposed that uses unsupervised learning and clustering to identify brute force attacks by analyzing specific features of network traffic. The experimental implementation of this approach has shown positive results, particularly in protecting FTP servers from password attacks.