CAUDIT: Continuous Auditing of SSH Servers To Mitigate Brute-Force Attacks

CAUDIT: Continuous Auditing of SSH Servers To Mitigate Brute-Force Attacks
复制标题

CAUDIT:持续审核 SSH 服务器以减轻暴力攻击

DOI:
--
复制
发表时间:
2019
期刊:
Symposium on Networked Systems Design and Implementation
影响因子:
--
通讯作者:
R. Iyer
R. Iyer
中科院分区:
--
文献类型:
--
作者:
Phuong Cao;Yuming Wu;Subho Sankar Banerjee;Justin Azoff;A. Withers;Z. Kalbarczyk;R. Iyer

文献摘要

参考文献

被引文献

相似文献

本文描述了部署在伊利诺伊大学国家超级计算应用中心(NCSA)的CAUDIT 1操作系统。CAUDIT是一个完全自动化的系统,能够识别fi并排除易受SSH暴力攻击的主机。它的主要特征包括:1)一个蜜罐,用于在a/16 IP地址范围内吸引基于ssh的攻击,并从这些攻击中提取关键元数据(例如,源IP、密码、ssh客户端版本或密钥fi指纹);2)通过重放蜜罐记录的攻击尝试在实时生产网络上执行审计;3)使用蜜罐记录的IP地址通过使用黑洞路由器在网络边界拦截ssh攻击尝试,同时巧妙地减少ncsa安全监控系统的负载;以及4)实时通知对等站点攻击企图的能力,以确保遏制协同攻击。该系统由带有定制组件的现有技术组成,其新奇之处在于它能够以以前从未验证过的规模执行(每天有数千个节点和数千万次攻击尝试)。463天的经验表明,使用拟议的BHR,CAUDIT平均每天成功阻止5700万次攻击尝试。这意味着与日均相比,SSH尝试次数减少了66倍,并将ncsa内部网络安全监控基础设施的traffic减少了78%。
This paper describes CAUDIT 1 , an operational system deployed at the National Center for Supercomputing Applications (NCSA) at the University of Illinois. CAUDIT is a fully automated system that enables the identification and exclusion of hosts that are vulnerable to SSH brute-force attacks. Its key features include: 1) a honeypot for attracting SSH-based attacks over a /16 IP address range and extracting key meta-data (e.g., source IP, password, SSH-client version, or key fingerprint) from these attacks; 2) executing audits on the live production network by replaying of attack attempts recorded by the honeypot; 3) using the IP addresses recorded by the honeypot to block SSH attack attempts at the network border by using a Black Hole Router (BHR) while significantly reducing the load on NCSA’s security monitoring system; and 4) the ability to inform peer sites of attack attempts in real-time to ensure containment of coordinated attacks. The system is composed of existing techniques with custom-built components, and its novelty is its ability to execute at a scale that has not been validated earlier (with thousands of nodes and tens of millions of attack attempts per day). Experience over 463 days shows that CAUDIT successfully blocks an average of 57 million attack attempts on a daily basis using the proposed BHR. This represents a 66 × reduction in the number of SSH attempts compared to the daily average and has reduced the traffic to the NCSA’s internal network-security-monitoring infrastructure by 78%.
DOI: 10.1145/3140368.3140371
发表时间: 2017-11
期刊: Proceedings of the 2017 Workshop on Automated Decision Making for Active Cyber Defense
影响因子: --
作者:
Alexander Kedrowitsch;D. Yao;G. Wang;K. Cameron
通讯作者: Alexander Kedrowitsch;D. Yao;G. Wang;K. Cameron