Network-Based Dictionary Attack Detection

  • Authors:
  • Jan Vykopal;Tomas Plesnik;Pavel Minarik

  • Affiliations:
  • -;-;-

  • Venue:
  • ICFN '09 Proceedings of the 2009 International Conference on Future Networks
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes the novel network-based approach to a dictionary attack detection with the ability to recognize successful attack. We analyzed SSH break-in attempts at a flow level and determined a dictionary attack pattern. This pattern was verified and compared to common SSH traffic to prevent false positives. The SSH dictionary attack pattern was implemented using decision tree technique. The evaluation was performed in a large high-speed university network with promising results.