What Lies Beneath? Analyzing Automated SSH Bruteforce Attacks

What Lies Beneath? Analyzing Automated SSH Bruteforce Attacks
复制标题

下面是什么?

DOI:
10.1007/978-3-319-29938-9_6
复制
发表时间:
2015
期刊:
Indian journal of science and technology
影响因子:
--
通讯作者:
P. V. Oorschot
P. V. Oorschot
中科院分区:
--
文献类型:
--
作者:
A. Abdou;David Barrera;P. V. Oorschot

文献摘要

被引文献

相似文献

我们报告了我们认为是迄今为止最大的自动安全外壳(SSH)暴力攻击数据集。除了时间、来源和用户名详细信息外,该数据集还包括明文密码猜测,这使我们能够分析攻击者的行为和动态(例如,协同攻击和密码字典共享)。我们的方法包括在六个城市托管六个仪表化SSH服务器。在一年的时间里,我们总共记录了来自112个不同国家/地区和6000多个不同来源IP地址的1700万次登录尝试。我们阐明了攻击者的行为,并根据我们的发现为SSH用户和管理员提供了建议。
We report on what we believe to be the largest dataset (to date) of automated secure shell (SSH) bruteforce attacks. The dataset includes plaintext password guesses in addition to timing, source, and username details, which allows us to analyze attacker behaviour and dynamics (e.g., coordinated attacks and password dictionary sharing). Our methodology involves hosting six instrumented SSH servers in six cities. Over the course of a year, we recorded a total of \(\sim \)17M login attempts originating from 112 different countries and over 6 K distinct source IP addresses. We shed light on attacker behaviour, and based on our findings provide recommendations for SSH users and administrators.