Identifying User Authentication Methods on Connections for SSH Dictionary Attack Detection

Akihiro Satoh, Yutaka Nakamura, Takeshi Ikenaga · 2013

A dictionary attack against SSH is a common security threat. Many published ways rely on network traffic to detect SSH dictionary attacks. This is because the connections of remote login, file transfer, and TCP/IP forwarding are visibly distinct from those of the attacks. However these ways incorrectly consider the connections of automated tasks as those of the attacks because of the mutual similarities. In this paper, we propose a new approach to identify user authentication methods on SSH connections and to remove connections that employ non-keystroke based authentication. This approach rests on two perspectives: (1) an SSH dictionary attack targets a host that provides keystroke based authentication, (2) automated tasks through SSH need to support non-keystroke based authentication. Thus, our proposal contributes to improvement in the detection accuracy of SSH dictionary attacks.

Read the paper · More papers on PaperTik