{"title":"A distributed active response architecture for preventing SSH dictionary attacks","authors":"J. L. Thames, R. Abler, D. Keeling","doi":"10.1109/SECON.2008.4494264","DOIUrl":null,"url":null,"abstract":"Dictionary attacks against Internet servers that provide the secure shell (SSH) service for secure, remote login is very common. The dictionary attack is an attempt to gain unauthorized access to a server by continuously guessing username and password pairs using sophisticated brute force techniques. Solutions exist that can detect and prevent this attack for a local host. However, a technique that distributes the detection and prevention information to a server's trusted neighbors can provide a gain in security by way of preemptive protection. This paper describes a distributed active response architecture that provides proactive, preemptive protection against the SSH dictionary attack.","PeriodicalId":188817,"journal":{"name":"IEEE SoutheastCon 2008","volume":"29 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-04-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"29","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE SoutheastCon 2008","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SECON.2008.4494264","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 29
Abstract
Dictionary attacks against Internet servers that provide the secure shell (SSH) service for secure, remote login is very common. The dictionary attack is an attempt to gain unauthorized access to a server by continuously guessing username and password pairs using sophisticated brute force techniques. Solutions exist that can detect and prevent this attack for a local host. However, a technique that distributes the detection and prevention information to a server's trusted neighbors can provide a gain in security by way of preemptive protection. This paper describes a distributed active response architecture that provides proactive, preemptive protection against the SSH dictionary attack.