SSH Dictionary Attack Detection Based on Flow Analysis

SSH Dictionary Attack Detection Based on Flow Analysis
复制标题

基于流分析的SSH字典攻击检测

DOI:
10.1109/saint.2012.16
复制
发表时间:
2012
期刊:
2012 IEEE/IPSJ 12th International Symposium on Applications and the Internet
影响因子:
--
通讯作者:
T. Ikenaga
T. Ikenaga
中科院分区:
--
文献类型:
--
作者:
Akihiro Satoh;Yutaka Nakamura;T. Ikenaga

文献摘要

被引文献

相似文献

SSH服务运行在许多不同作用域的主机上,而不仅仅是操作,因此针对该服务的字典攻击是一种常见的安全威胁。SANS报告了分布式SSH字典攻击的出现,与简单的攻击相比,这种攻击非常隐蔽。由于此类攻击即使一次成功也会导致严重问题,管理员应该实施对策。SSH字典攻击已通过两种基本方式检测到,这两种方式依赖于日志文件或网络流量。然而,这两种方法都有局限性。第一种方法给管理员带来了沉重的维护成本,维护成本随着网络中主机数量的增加而线性增长。第二种方法无法区分成功和不成功的攻击。更直接的问题是,这两种方法都不能有效地对抗秘密攻击,因为这些攻击的登录尝试对日志文件或网络流量几乎没有影响。理想的方法应该能够检测单独的攻击,并使用仅从网络流量获得的信息来区分攻击的成功或失败。在本文中,我们描述了这样一种方法,它是由两个新的元素结合而成的。首先,在假设的基础上,我们使用了两个标准:“连接协议的存在”和“身份验证分组到达间隔时间的差异”。然而,由于SSH协议的机密性和灵活性,这些标准不可用。其次,我们通过流特征和机器学习算法来识别子协议的过渡点,从而解决了这个问题。我们通过在校园网边缘采集的真实流量轨迹的实验来评估该方法的有效性。实验结果对这一研究方向是令人鼓舞的,尽管它们是从SSH字典攻击的约简数据集和简化的假设下得出的。重要的贡献是证明了一种检测SSH字典攻击的理想方法似乎是可行的。
SSH services are run on many hosts with various scopes other than just operation, so dictionary attack against the service is a common security threat. SANS has reported the emergence of distributed SSH dictionary attacks, which are very stealthy in comparison with a simple one. Since even one success of such an attack causes serious problems, administrators should implement countermeasures. SSH dictionary attacks have been detected in two basic ways that rely on either log files or network traffic. Both approaches, however, have limitations. The first approach imposes upon administrators heavy maintenance costs, which grow linearly with the number of hosts in networks. The second approach cannot distinguish between successful and unsuccessful attacks. Of more immediate concern, neither approach is effective against stealthy attacks because the login attempts of these attacks have little impact on log files or network traffic. An ideal method would be able to detect individual attacks and distinguish between an attack's success or failure, using information derived from only network traffic. In this paper, we describe such a method, which was developed by combining two novel elements. First, on the basis of our assumptions, we use two criteria: "existence of a connection protocol" and "difference in the inter-arrival time of an auth-packet". These criteria are not available, though, owing to the confidentiality and flexibility of the SSH protocol. Second, we resolve this problem by identifying transition points of a sub-protocol through flow features and machine learning algorithms. We evaluate the effectiveness of the proposed method through experiments on real traffic traces collected at the edge in our campus networks. The experimental results are encouraging for this research direction, though they are derived from reduced datasets of SSH dictionary attacks and under simplifying assumptions. The significant contribution is the demonstration that an ideal method for detecting SSH dictionary attacks seems feasible.