Detection of SSH Dictionary Attack in DNS Reverse Resolution Traffic
スポンサーリンク
概要
- 論文の詳細を見る
We developed and evaluated Euclidian distance based detection method for SSH dictionary attacks in the total PTR resource record (RR) based DNS query request packet traffic from the campus network to the DNS cache server in a university through January 1st to December 31st, 2009. The obtained results are: (1) The network servers, especially, they have a function of SSH services, generated the significant PTR RR based DNS query request packet traffic through 07:30-08:30 in March 14th, 2009. (2) We found eleven SSH dictionary attacks in the score changes for the detection method using the calculated Euclidian distance between the observed query IP address and the last one by employing a distance value of zero and the obtained signature data at March 14th, 2009. Also (3), we found twenty-seven SSH dictionary attacks in the score changes for the detection method employing daily generated signature data. Therefore, it can be concluded that the Euclidian distance based detection method can be useful for detecting the SSH dictionary attacks in the campus network.
- 2011-07-08
著者
-
Yasuo Musashi
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Shinichiro Kubota
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Kenichi Sugitani
Center for Multimedia and Information Technologies (CMIT), Kumamoto University
-
Yasuo Musashi
Center For Multimedia And Information Technologies Kumamoto University
-
Shinichiro Kubota
Center For Multimedia And Information Technologies Kumamoto University
-
Kenichi Sugitani
Center For Multimedia And Information Technologies Kumamoto University
-
Yasuo Musashi
Center For Multimedia And Information Technologies (cmit) Kumamoto University
-
Shinichiro Kubota
Center For Multimedia And Information Technologies (cmit) Kumamoto University
-
Masaya Kumagai
Graduate School of Science and Technology, Kumamoto University
-
Masaya Kumagai
Graduate School Of Science And Technology Kumamoto University
関連論文
- Detection of Host Search Attacks in PTR Resource Record DNS Query Packet Traffic
- Detection of Host Name Harvesting Attack in PTR Resource Record Based DNS Query Packet Traffic
- Detection of NS Resource Record DNS Resolution Traffic, Host Search, and SSH Dictionary Attack Activities
- Detection of SSH Dictionary Attack in DNS Reverse Resolution Traffic