Detection of SSH Brute Force Attacks Using Naïve Bayes Classification on Cowrie Honeypot Logs in a Virtualized Environment

Agbar Prasetyo, Herianto Herianto, Yahya, Nur Syamsiyah · Journal Technology Information and Data Analytic · 2025

The increasing number of brute force cyberattacks targeting SSH services highlights the urgent need for effective early detection and mitigation systems. This study aims to analyze brute force attack patterns using the Naïve Bayes classification algorithm based on log data generated by the Cowrie Honeypot. A simulated virtual environment was developed to emulate attack scenarios and generate authentic SSH log data while preserving real server confidentiality. The system architecture follows the CRISP-DM framework, including data preprocessing, model development, evaluation, and deployment. Evaluation using confusion matrix metrics showed that the Naïve Bayes algorithm successfully distinguished brute force attempts from normal traffic with high accuracy, precision, recall, and F1-score. The findings confirm the potential of combining Cowrie honeypot data with machine learning classifiers as an early warning tool for intrusion detection in enterprise network infrastructures.

Read the paper · More papers on PaperTik