DocumentCode
151806
Title
Analysis and prevention of network password guessing attacks in an enterprise environment
Author
Manolache, Florin B. ; Qingping Hou ; Rusu, Octavian
Author_Institution
Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear
2014
fDate
11-13 Sept. 2014
Firstpage
1
Lastpage
7
Abstract
Common tools are available to protect individual computers against malicious password guessing attacks affecting services like ssh or imap. This paper takes such tools to the next level by proposing network-wide defense strategies and by presenting an implementation of a system that creates a collective defense. Such a system is useful in enterprise environments where frequent ssh scans waste bandwidth and some aggressive imap scans can induce denial of service to mail servers. The defense system is based on a set of computers that maintain a common database about the individual attacks. By interpreting the events stored in the database, every computer on the network can preemptively block attackers. The main objectives of the design of this system are to avoid creating a single point of failure by using a distributed database, and to handle the entire configuration of the participants from one single file. A variety of attack scenarios are studied to improve the efficiency of the defense.
Keywords
computer network security; distributed databases; file servers; denial of service; distributed database; enterprise environment; imap scans; mail servers; malicious network password guessing attacks; network-wide defense strategies; ssh scans; Computers; Databases; Dictionaries; IP networks; Niobium; Ports (Computers); Servers; ddos; fail2ban; password guessing; ssh scan;
fLanguage
English
Publisher
ieee
Conference_Titel
RoEduNet Conference 13th Edition: Networking in Education and Research Joint Event RENAM 8th Conference, 2014
Conference_Location
Chisinau
ISSN
2068-1038
Print_ISBN
978-1-4799-6860-2
Type
conf
DOI
10.1109/RoEduNet-RENAM.2014.6955303
Filename
6955303
Link To Document