DNS Based Detection of SSH Dictionary Attack in Campus Network

Dennis Arturo Ludeña Romaña, Yasuo Musashi, Kazuya Takemori, Masaya Kumagai, Shinichiro Kubota, Kenichi Sugitani, Tsuyoshi Usagawa, Toshinori Sueyoshi · 2009

We statistically investigated the DNS query access traffic from a university campus network toward the top domain DNS through March 14th, 2009, when the hosts in the campus network were under inbound SSH dictionary brute force attack. The interesting results are obtained, as follows: (1) the several hosts generated the DNS query packet traffic, taking a rate of more than 1,000 hour -1 , through 07:30-08:30 in March 14th, 2009, (2) the DNS query packet traffic correlates with the DNS query packet one including more than two specific query keywords (payloads of the packets), and (3) the former keyword is a fully qualified domain name (FQDN) and the latter one is an IP address. Therefore, we can detect inbound SSH dictionary attack by watching frequencies of the FQDNs and the IP addresses as query keywords in the DNS query packets from the hosts in the campus network.

Read the paper · More papers on PaperTik