VYKOPAL, Jan, Martin DRAŠAR and Philipp WINTER. Flow-based Brute-force Attack Detection. Online. In Markus Zeilinger, Peter Schoo, Eckehard Hermann. Advances in IT Early Warning. Stuttgart: Fraunhofer Verlag, 2013. p. 41-51. ISBN 978-3-8396-0474-8. [citováno 2024-04-23]
Other formats:   BibTeX LaTeX RIS
Basic information
Original name Flow-based Brute-force Attack Detection
Name in Czech Detekce útoků hrubou silou pomocí síťových toků
Authors VYKOPAL, Jan (203 Czech Republic, guarantor, belonging to the institution), Martin DRAŠAR (203 Czech Republic, belonging to the institution) and Philipp WINTER (40 Austria)
Edition Stuttgart, Advances in IT Early Warning, p. 41-51, 11 pp. 2013.
Publisher Fraunhofer Verlag
Other information
Original language English
Type of outcome Chapter(s) of a specialized book
Field of Study 10201 Computer sciences, information science, bioinformatics
Country of publisher Germany
Confidentiality degree is not subject to a state or trade secret
Publication form printed version "print"
RIV identification code RIV/00216224:14610/13:00065695
Organization unit Institute of Computer Science
ISBN 978-3-8396-0474-8
Keywords in English network; flow; brute force attack; password; detection; similarity; entropy; evasion
Tags best1, rivok
Tags International impact
Changed by Changed by: Mgr. Marta Novotná Buršíková, učo 15689. Changed: 3/4/2014 15:24.
Abstract
Brute-force attacks are a prevalent phenomenon that is getting harder to successfully detect on a network level due to increasing volume and encryption of network traffic and growing ubiquity of high-speed networks. Although the research in this field advanced considerably, there still remain classes of attacks that are hard to detect. In this chapter, we present several methods for the detection of brute-force attacks based on the analysis of network flows. We discuss their strengths and shortcomings as well as shortcomings of flow-based methods in general. We also demonstrate the fragility of some methods by introducing detection evasion techniques.
Links
OVMASUN200801, research and development projectName: CYBER ? Bezpečnost informačních a komunikačních systémů AČR - on line monitorování, vizualizace a filtrace paketů. Rozvoj schopností Computer Incident Response Capability v prostředí Cyber Defence. (Acronym: CYBER)
Investor: Ministry of Defence of the CR, CYBER - Security of Czech Army Information and Communication Systems - On-line Monitoring, Visualization and Packet Filtration. Computer Incident Response Capability Development in the Cyber Defence Environment
PrintDisplayed: 23/4/2024 16:12