Profiling attacker behavior following SSH compromises

D Ramsbrock, R Berthier… - 37th Annual IEEE/IFIP …, 2007 - ieeexplore.ieee.org
D Ramsbrock, R Berthier, M Cukier
37th Annual IEEE/IFIP international conference on dependable …, 2007ieeexplore.ieee.org
This practical experience report presents the results of an experiment aimed at building a
profile of attacker behavior following a remote compromise. For this experiment, we utilized
four Linux honeypot computers running SSH with easily guessable passwords. During the
course of our research, we also determined the most commonly attempted usernames and
passwords, the average number of attempted logins per day, and the ratio of failed to
successful attempts. To build a profile of attacker behavior, we looked for specific actions …
This practical experience report presents the results of an experiment aimed at building a profile of attacker behavior following a remote compromise. For this experiment, we utilized four Linux honeypot computers running SSH with easily guessable passwords. During the course of our research, we also determined the most commonly attempted usernames and passwords, the average number of attempted logins per day, and the ratio of failed to successful attempts. To build a profile of attacker behavior, we looked for specific actions taken by the attacker and the order in which they occurred. These actions were: checking the configuration, changing the password, downloading a file, installing/running rogue code, and changing the system configuration.
ieeexplore.ieee.org
以上显示的是最相近的搜索结果。 查看全部搜索结果