A new approach to identify user authentication methods toward SSH dictionary attack detection

0Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.

Abstract

A dictionary attack against SSH is a common security threat. Many methods rely on network traffic to detect SSH dictionary attacks because the connections of remote login, file transfer, and TCP/IP forwarding are visibly distinct from those of attacks. However, these methods incorrectly judge the connections of automated operation tasks as those of attacks due to their mutual similarities. In this paper, we propose a new approach to identify user authentication methods on SSH connections and to remove connections that employ non-keystroke based authentication. This approach is based on two perspectives: (1) an SSH dictionary attack targets a host that provides keystroke based authentication; and (2) automated tasks through SSH need to support non-keystroke based authentication. Keystroke based authentication relies on a character string that is input by a human; in contrast, non-keystroke based authentication relies on information other than a character string. We evaluated the effectiveness of our approach through experiments on real network traffic at the edges in four campus networks, and the experimental results showed that our approach provides high identification accuracy with only a few errors.

Cite

CITATION STYLE

APA

Satoh, A., Nakamura, Y., & Ikenaga, T. (2015). A new approach to identify user authentication methods toward SSH dictionary attack detection. IEICE Transactions on Information and Systems, E98D(4), 760–768. https://doi.org/10.1587/transinf.2014ICP0005

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free