VYKOPAL, Jan. A Flow-Level Taxonomy and Prevalence of Brute Force Attacks. In Advances in Computing and Communications. Berlin: Springer Berlin Heidelberg, 2011, p. 666-675. ISBN 978-3-642-22714-1. Available from: https://dx.doi.org/10.1007/978-3-642-22714-1_69.
Other formats:   BibTeX LaTeX RIS
Basic information
Original name A Flow-Level Taxonomy and Prevalence of Brute Force Attacks
Authors VYKOPAL, Jan (203 Czech Republic, guarantor, belonging to the institution).
Edition Berlin, Advances in Computing and Communications, p. 666-675, 10 pp. 2011.
Publisher Springer Berlin Heidelberg
Other information
Original language English
Type of outcome Proceedings paper
Field of Study 10201 Computer sciences, information science, bioinformatics
Country of publisher Germany
Confidentiality degree is not subject to a state or trade secret
Publication form printed version "print"
WWW URL
RIV identification code RIV/00216224:14610/11:00050706
Organization unit Institute of Computer Science
ISBN 978-3-642-22714-1
Doi http://dx.doi.org/10.1007/978-3-642-22714-1_69
UT WoS 000308380600069
Keywords in English netflow; taxonomy; prevalence; brute force attack; SSH
Tags best2, rivok
Changed by Changed by: doc. RNDr. Jan Vykopal, Ph.D., učo 98724. Changed: 19/7/2013 10:17.
Abstract
Online brute force and dictionary attacks against network services and web applications are ubiquitous. We present their taxonomy from the perspective of network flows. This contributes to clear evaluation of detection methods and provides better understanding of the brute force attacks within the research community. Next, we utilize the formal definitions of attacks in a long-term analysis of SSH traffic from 10 gigabit university network. The results shows that flow-based intrusion detection may profit from traffic observation of the whole network, particularly it can allow more accurate detection of the majority of brute-force attacks in high-speed networks.
Links
OVMASUN200801, research and development projectName: CYBER ? Bezpečnost informačních a komunikačních systémů AČR - on line monitorování, vizualizace a filtrace paketů. Rozvoj schopností Computer Incident Response Capability v prostředí Cyber Defence. (Acronym: CYBER)
Investor: Ministry of Defence of the CR, CYBER - Security of Czech Army Information and Communication Systems - On-line Monitoring, Visualization and Packet Filtration. Computer Incident Response Capability Development in the Cyber Defence Environment
PrintDisplayed: 18/7/2024 18:17