SSH Bruteforce Attack Classification using Machine Learning

Marco Ariano Kristyanto, Ice Krisnahati, Franky Rawung, Dzhillan Dzhalila, Bima Dinda Nurwibawa, Wisnu Bayu Murti, Baskoro Adi Pratomo, Ary Mazharuddin Shiddiqi · 2022

One of the problems in computer network security is Intrusion Detection. To detect it, we need a NIDS (Network Intrusion Detection). One example of NIDS is a honeypot. In this research, we use a kippo honeypot as a tool as an IDS. In this paper, honeypot logs are used for classifying SSH attacks using machine learning. The research used the original dataset from Kippo's log to classify the ssh attack as the primary source. We implement four algorithm classifications: Decision Tree, Naive Bayes, SVM, and Random Forest. Our research found that Decision Tree (DT) and random forest have the same score and better accuracy than naive Bayes and SVM. The accuracy and F1 score of RF and DT are 0.92 and 0.92, respectively.

Read the paper · More papers on PaperTik