Abstract
In this paper we propose a method to detect distributed bruteforcing by modeling failed login attempts as a Poisson probability distribution. We use content similarity between known SSH connection and flow characteristics of failed login attempts to attribute a flow to SSH application and subsequently either as failure or success. Using the failed login count in a window time, we label window as either normal or containing bruteforce attempts.
Author supplied keywords
Cite
CITATION STYLE
Hubballi, N., Tiwari, N., & Khandait, P. (2020). POSTER: Distributed SSH Bruteforce Attack Detection with Flow Content Similarity and Login Failure Reputation. In Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, ASIA CCS 2020 (pp. 916–918). Association for Computing Machinery, Inc. https://doi.org/10.1145/3320269.3405443
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.