• DocumentCode
    151806
  • Title

    Analysis and prevention of network password guessing attacks in an enterprise environment

  • Author

    Manolache, Florin B. ; Qingping Hou ; Rusu, Octavian

  • Author_Institution
    Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2014
  • fDate
    11-13 Sept. 2014
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Common tools are available to protect individual computers against malicious password guessing attacks affecting services like ssh or imap. This paper takes such tools to the next level by proposing network-wide defense strategies and by presenting an implementation of a system that creates a collective defense. Such a system is useful in enterprise environments where frequent ssh scans waste bandwidth and some aggressive imap scans can induce denial of service to mail servers. The defense system is based on a set of computers that maintain a common database about the individual attacks. By interpreting the events stored in the database, every computer on the network can preemptively block attackers. The main objectives of the design of this system are to avoid creating a single point of failure by using a distributed database, and to handle the entire configuration of the participants from one single file. A variety of attack scenarios are studied to improve the efficiency of the defense.
  • Keywords
    computer network security; distributed databases; file servers; denial of service; distributed database; enterprise environment; imap scans; mail servers; malicious network password guessing attacks; network-wide defense strategies; ssh scans; Computers; Databases; Dictionaries; IP networks; Niobium; Ports (Computers); Servers; ddos; fail2ban; password guessing; ssh scan;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    RoEduNet Conference 13th Edition: Networking in Education and Research Joint Event RENAM 8th Conference, 2014
  • Conference_Location
    Chisinau
  • ISSN
    2068-1038
  • Print_ISBN
    978-1-4799-6860-2
  • Type

    conf

  • DOI
    10.1109/RoEduNet-RENAM.2014.6955303
  • Filename
    6955303