A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack

碩士 === 國立高雄大學 === 亞太工商管理學系碩士班 === 97 === With the rapid growth of technology, there are many applications system needs to authenticate in the Internet environment. User account and password is a simply and general way for authentication in network. The dictionary attack means that attackers attempt...

Full description

Bibliographic Details
Main Authors: Yu-Jen Hsueh, 薛昱仁
Other Authors: Han-Wei Hsiao
Format: Others
Language:zh-TW
Published: 2009
Online Access:http://ndltd.ncl.edu.tw/handle/06556425740792050670
id ndltd-TW-097NUK05026001
record_format oai_dc
spelling ndltd-TW-097NUK050260012016-06-19T04:12:06Z http://ndltd.ncl.edu.tw/handle/06556425740792050670 A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack 以網路流量偵測SSH字典攻擊與追蹤之研究 Yu-Jen Hsueh 薛昱仁 碩士 國立高雄大學 亞太工商管理學系碩士班 97 With the rapid growth of technology, there are many applications system needs to authenticate in the Internet environment. User account and password is a simply and general way for authentication in network. The dictionary attack means that attackers attempt to login some user accounts illegally by trying all possible password. There are a lot of login failed SSH service login records in the system authentication logs file, that become a usually situation on the Taiwan Academic Network environment. It implies that dictionary attack is a serious intrusive event. In this paper, we propose a classification-based detection module to detect SSH dictionary attack. We used three data mining classification algorithms, Naïve Bayes, decision tree and SVM to build our SSH dictionary attack detection module. We collected real world NetFlow traffic data in a month as our training samples to build our detection system. Our empirical evaluation results show that the proposed detection module reaches above 90% detection accuracy. Further, we used detection module and NetFlow history data to develop the SSH dictionary attack tracking algorithm. We try to find out the topology of IP address that launched SSH dictionary attack, and try to trace back the origin of SSH dictionary attacker. This research result that could be helps the network managers to detect implicit dictionary attack behaviors to improve the network security. Han-Wei Hsiao 蕭漢威 2009 學位論文 ; thesis 47 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立高雄大學 === 亞太工商管理學系碩士班 === 97 === With the rapid growth of technology, there are many applications system needs to authenticate in the Internet environment. User account and password is a simply and general way for authentication in network. The dictionary attack means that attackers attempt to login some user accounts illegally by trying all possible password. There are a lot of login failed SSH service login records in the system authentication logs file, that become a usually situation on the Taiwan Academic Network environment. It implies that dictionary attack is a serious intrusive event. In this paper, we propose a classification-based detection module to detect SSH dictionary attack. We used three data mining classification algorithms, Naïve Bayes, decision tree and SVM to build our SSH dictionary attack detection module. We collected real world NetFlow traffic data in a month as our training samples to build our detection system. Our empirical evaluation results show that the proposed detection module reaches above 90% detection accuracy. Further, we used detection module and NetFlow history data to develop the SSH dictionary attack tracking algorithm. We try to find out the topology of IP address that launched SSH dictionary attack, and try to trace back the origin of SSH dictionary attacker. This research result that could be helps the network managers to detect implicit dictionary attack behaviors to improve the network security.
author2 Han-Wei Hsiao
author_facet Han-Wei Hsiao
Yu-Jen Hsueh
薛昱仁
author Yu-Jen Hsueh
薛昱仁
spellingShingle Yu-Jen Hsueh
薛昱仁
A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack
author_sort Yu-Jen Hsueh
title A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack
title_short A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack
title_full A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack
title_fullStr A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack
title_full_unstemmed A Study of Using NetFlow Traffic Data to Detect and Track SSH Dictionary Attack
title_sort study of using netflow traffic data to detect and track ssh dictionary attack
publishDate 2009
url http://ndltd.ncl.edu.tw/handle/06556425740792050670
work_keys_str_mv AT yujenhsueh astudyofusingnetflowtrafficdatatodetectandtracksshdictionaryattack
AT xuēyùrén astudyofusingnetflowtrafficdatatodetectandtracksshdictionaryattack
AT yujenhsueh yǐwǎnglùliúliàngzhēncèsshzìdiǎngōngjīyǔzhuīzōngzhīyánjiū
AT xuēyùrén yǐwǎnglùliúliàngzhēncèsshzìdiǎngōngjīyǔzhuīzōngzhīyánjiū
AT yujenhsueh studyofusingnetflowtrafficdatatodetectandtracksshdictionaryattack
AT xuēyùrén studyofusingnetflowtrafficdatatodetectandtracksshdictionaryattack
_version_ 1718309632168951808