Analysis and visualization of SSH attacks using honeypots

Analysis and visualization of SSH attacks using honeypots
复制标题

使用蜜罐进行 SSH 攻击的分析和可视化

DOI:
10.1109/eurocon.2013.6624967
复制
发表时间:
2013
期刊:
Eurocon 2013
影响因子:
--
通讯作者:
Petros Nicopolitidis
Petros Nicopolitidis
中科院分区:
--
文献类型:
--
作者:
Ioannis Koniaris;G. Papadimitriou;Petros Nicopolitidis

文献摘要

被引文献

相似文献

在计算机安全领域,蜜罐是一种旨在欺骗对各种组织的服务器和网络基础设施发动攻击的恶意用户的系统。它们可以被部署为组织的真实系统的保护机制,或者作为研究单位来研究和分析个别黑客使用的方法。在这篇文章中,我们介绍了一个研究蜜罐操作的结果,该操作承担了针对SSH服务的攻击者的网络陷阱的角色,以便获得非法的服务器访问。在随后的几个月里,这个虚假的系统一直保持在线并完全运行,捕获攻击并记录所有恶意活动。在评估期间,结果表明,蜜罐在收集有关SSH攻击的信息方面仍然是非常有效的工具。此外,我们观察到,攻击者经常使用现成的工具和词典在野外攻击服务器,而他们的后妥协行为主要包括旋转和IRC相关活动。最后,我们提供了一个可视化工具,旨在帮助安全研究人员在分析和得出结论阶段,与本文概述的相同的SSH蜜罐实现软件一起使用。
In the field of computer security, honeypots are systems aimed at deceiving malicious users who launch attacks against the servers and network infrastructure of various organizations. They can be deployed as protection mechanisms to an organization's real systems, or as research units to study and analyze the methods employed by individual hackers. In this paper we present the results of a research honeypot's operation, which undertook the role of a web trap for attackers who target the SSH service in order to gain illegal server access. The fake system has remained online and fully operational during a course of several consequent months, capturing attacks and logging all malicious activity. During this assessment it was shown that honeypots remain very effective tools in gathering information about SSH attacks. Furthermore, we observed that attackers are constantly targeting servers in the wild employing ready-to-use tools and dictionaries, while their post-compromise actions include mostly pivoting and IRC-related activities. Lastly we present a visualization tool aimed at helping security researchers during the analysis and conclusions drawing phases, for use with the same SSH honeypot implementation software as outlined in this work.