SSHafe:实时SSH暴力攻击检测与新型凭证轮换标准
SSHafe: A Real-Time SSH Brute Force Attack Detection and Novel Credential Rotation Standard
浏览论文内容
中文总结 AI 辅助
本研究提出SSHafe系统,结合时间序列特征工程与LightGBM实现实时SSH暴力攻击检测,采用新型密码重置标准提升安全性,可在10秒内抑制攻击并防止账户入侵。
中文摘要 AI 辅助
SSH是远程系统管理的关键协议,却遭受大量攻击,基于密码的认证使服务器面临大规模暴力、字典及凭证喷洒攻击风险。现有基于规则的防御如Fail2Ban无法检测慢速、分布式或阈值感知的攻击者,而传统账户恢复机制(邮件链接、一次性密码OTP、带外验证)会引入钓鱼、会话劫持、弱认证绑定等额外漏洞。本研究提出SSHafe,一种实时SSH暴力攻击检测与缓解系统,结合时间序列特征工程与轻量级LightGBM分类器,直接从系统认证日志中识别攻击模式。多尺度滑动窗口方法提取尝试率、到达间隔时间、失败率、用户名多样性等行为特征,使模型在基准数据上达到99.96%的检测准确率,在未标记的真实流量中也表现出色。检测到攻击后,SSHafe自动拦截目标用户账户,并推送SSH横幅引导合法用户采用新型基于密钥的密码轮换工作流。所提出的新型密码重置标准在单个密码学绑定流程中完成认证与密码更新,无需会话、Cookie、OTP或基于邮件的验证,可缓解钓鱼、会话劫持、跨站请求伪造CSRF及重放攻击。在Azure虚拟机和实时对抗流量上的实验表明,SSHafe可在10秒内识别并抑制暴力攻击,即使凭证强度较弱也能防止账户被入侵。
英文摘要
SSH remains a critical yet heavily targeted protocol for remote system administration, with password-based authentication exposing servers to large-scale brute-force, dictionary, and credential-spray attacks. Existing rule-based defences such as Fail2Ban fail to detect slow, distributed, or threshold-aware adversaries, while conventional account-recovery mechanisms: email links, OTPs, and out-of-band verification introduce additional vulnerabilities including phishing, session hijacking, and weak authentication binding. This work presents SSHafe, a real-time SSH brute-force detection and mitigation system that combines time-series feature engineering with a lightweight LightGBM classifier to identify attack patterns directly from system authentication logs. A multi-scale sliding-window approach extracts behavioural features such as attempt rates, inter-arrival times, failure ratios, and username diversity, enabling the model to achieve a detection accuracy of 99.96% on benchmark data and strong performance on unlabeled real-world traffic. Upon detecting an attack, SSHafe automatically blocks the targeted user account and delivers an SSH banner guiding legitimate users to a novel passkey-based password-rotation workflow. The proposed novel password reset standard performs authentication and password update in a single cryptographically bound flow, eliminating the need for sessions, cookies, OTPs, or email-based verification, and mitigating phishing, session hijacking, CSRF, and replay attacks. Experiments on an Azure VM and live adversarial traffic demonstrate that SSHafe can identify and suppress brute-force activity within ten seconds, preventing account compromise even with weak credentials.