{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T17:34:53Z","timestamp":1785605693912,"version":"3.56.0"},"publisher-location":"Cham","reference-count":41,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031066672","type":"print"},{"value":"9783031066689","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-06668-9_8","type":"book-chapter","created":{"date-parts":[[2022,6,5]],"date-time":"2022-06-05T23:10:29Z","timestamp":1654470629000},"page":"75-95","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Realtime Risk Monitoring of\u00a0SSH Brute Force Attacks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2606-3988","authenticated-orcid":false,"given":"G\u00fcnter","family":"Fahrnberger","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,6,6]]},"reference":[{"key":"8_CR1","doi-asserted-by":"publisher","unstructured":"Blumenthal, U., Wijnen, B.: User-based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3). RFC 3414 (Internet Standard), December 2002. https:\/\/doi.org\/10.17487\/RFC3414","DOI":"10.17487\/RFC3414"},{"key":"8_CR2","unstructured":"Cao, P.M., et al.: CAUDIT: continuous auditing of SSH servers to mitigate brute-force attacks. In: Proceedings of the 16th USENIX Conference on Networked Systems Design and Implementation, pp. 667\u2013682. USENIX Association, February 2019. https:\/\/www.usenix.org\/system\/files\/nsdi19-cao.pdf"},{"key":"8_CR3","doi-asserted-by":"publisher","unstructured":"Case, J.D., Fedor, M., Schoffstall, M.L., Davin, J.R.: A Simple Network Management Protocol (SNMP). RFC 1157 (Historic), May 1990. https:\/\/doi.org\/10.17487\/RFC1157","DOI":"10.17487\/RFC1157"},{"key":"8_CR4","doi-asserted-by":"publisher","unstructured":"Eastlake, D., Hansen, T.: US Secure Hash Algorithms (SHA and SHA-based HMAC and HKDF). RFC 6234 (Informational), May 2011. https:\/\/doi.org\/10.17487\/RFC6234","DOI":"10.17487\/RFC6234"},{"key":"8_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/978-3-319-72344-0_14","volume-title":"Distributed Computing and Internet Technology","author":"G Fahrnberger","year":"2018","unstructured":"Fahrnberger, G.: Reliable condition monitoring of telecommunication services with time-varying load characteristic. In: Negi, A., Bhatnagar, R., Parida, L. (eds.) ICDCIT 2018. LNCS, vol. 10722, pp. 173\u2013188. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-72344-0_14"},{"key":"8_CR6","doi-asserted-by":"publisher","unstructured":"Fahrnberger, G.: Outlier removal for the reliable condition monitoring of telecommunication services. In: 2019 20th International Conference on Parallel and Distributed Computing, Applications and Technologies (PDCAT), pp. 240\u2013246, December 2019. https:\/\/doi.org\/10.1109\/PDCAT46702.2019.00052","DOI":"10.1109\/PDCAT46702.2019.00052"},{"key":"8_CR7","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1007\/978-3-030-75004-6_2","volume-title":"Innovations for Community Services","author":"G Fahrnberger","year":"2021","unstructured":"Fahrnberger, G.: Threshold pair selection for the reliable condition monitoring of telecommunication services. In: Krieger, U.R., Eichler, G., Erfurth, C., Fahrnberger, G. (eds.) I4CS 2021. CCIS, vol. 1404, pp. 9\u201321. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-75004-6_2"},{"key":"8_CR8","unstructured":"Faust, J.: Distributed Analysis of SSH Brute Force and Dictionary Based Attacks. Master\u2019s thesis, Saint Cloud State University, May 2018. https:\/\/repository.stcloudstate.edu\/cgi\/viewcontent.cgi?article=1083&context=msia_etds"},{"key":"8_CR9","doi-asserted-by":"publisher","unstructured":"Fern\u00e1ndez, G.C., Xu, S.: A case study on using deep learning for network intrusion detection. In: 2019 IEEE Military Communications Conference (MILCOM), MILCOM 2019, pp. 1\u20136. IEEE, November 2019. https:\/\/doi.org\/10.1109\/MILCOM47813.2019.9020824","DOI":"10.1109\/MILCOM47813.2019.9020824"},{"issue":"2","key":"8_CR10","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1002\/j.1538-7305.1950.tb00463.x","volume":"29","author":"RW Hamming","year":"1950","unstructured":"Hamming, R.W.: Error detecting and error correcting codes. Bell Syst. Tech. J. 29(2), 147\u2013160 (1950). https:\/\/doi.org\/10.1002\/j.1538-7305.1950.tb00463.x","journal-title":"Bell Syst. Tech. J."},{"key":"8_CR11","doi-asserted-by":"publisher","unstructured":"Hancock, J., Khoshgoftaar, T.M., Leevy, J.L.: Detecting SSH and FTP brute force attacks in big data. In: 2021 20th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 760\u2013765. IEEE, December 2021. https:\/\/doi.org\/10.1109\/ICMLA52953.2021.00126","DOI":"10.1109\/ICMLA52953.2021.00126"},{"key":"8_CR12","doi-asserted-by":"publisher","unstructured":"Hossain, M.D., Ochiai, H., Doudou, F., Kadobayashi, Y.: SSH and FTP brute-force attacks detection in computer networks: LSTM and machine learning approaches. In: 2020 5th International Conference on Computer and Communication Systems (ICCCS), pp. 491\u2013497. IEEE, May 2020. https:\/\/doi.org\/10.1109\/ICCCS49078.2020.9118459","DOI":"10.1109\/ICCCS49078.2020.9118459"},{"key":"8_CR13","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1007\/978-3-030-58201-2_4","volume-title":"ICT Systems Security and Privacy Protection","author":"K Hynek","year":"2020","unstructured":"Hynek, K., Bene\u0161, T., \u010cejka, T., Kub\u00e1tov\u00e1, H.: Refined detection of SSH brute-force attackers using machine learning. In: H\u00f6lbl, M., Rannenberg, K., Welzer, T. (eds.) SEC 2020. IAICT, vol. 580, pp. 49\u201363. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58201-2_4"},{"key":"8_CR14","doi-asserted-by":"publisher","unstructured":"Kantor, B.: BSD Rlogin. RFC 1282 (Informational), December 1991. https:\/\/doi.org\/10.17487\/RFC1282","DOI":"10.17487\/RFC1282"},{"key":"8_CR15","unstructured":"Kenna, C.: Analysis of and Response to SSH Brute Force Attacks, April 2010. https:\/\/citeseerx.ist.psu.edu\/viewdoc\/download?doi=10.1.1.587.8707&rep=rep1&type=pdf"},{"key":"8_CR16","unstructured":"Kennedy, D., O\u2019Gorman, J., Kearns, D., Aharoni, M.: Metasploit: The Penetration Tester\u2019s Guide. No Starch Press, July 2011"},{"issue":"4","key":"8_CR17","doi-asserted-by":"publisher","first-page":"165","DOI":"10.33851\/JMIS.2019.6.4.165","volume":"6","author":"J Kim","year":"2019","unstructured":"Kim, J., Shin, Y., Choi, E.: An intrusion detection model based on a convolutional neural network. J. Multimed. Inf. Syst. 6(4), 165\u2013172 (2019). https:\/\/doi.org\/10.33851\/JMIS.2019.6.4.165","journal-title":"J. Multimed. Inf. Syst."},{"key":"8_CR18","unstructured":"Lee, J.K., Kim, S.J., Hong, T.: A denied-events based detection method against SSH brute-force attack in supercomputing service environment. In: The 2016 International Conference on Security and Management (SAM 2016), pp. 351\u2013352. CSREA Press, July 2016. https:\/\/worldcomp-proceedings.com\/proc\/p2016\/SAM9761.pdf"},{"key":"8_CR19","doi-asserted-by":"crossref","unstructured":"Lee, J.K., Kim, S.J., Hong, T.: Brute-force attacks analysis against SSH in HPC multi-user service environment. Indian J. Sci. Technol. 9(24) (2016). http:\/\/ischolar.info\/index.php\/indjst\/article\/view\/134547","DOI":"10.17485\/ijst\/2016\/v9i24\/96070"},{"issue":"2","key":"8_CR20","doi-asserted-by":"publisher","first-page":"253","DOI":"10.3938\/jkps.69.253","volume":"69","author":"JK Lee","year":"2016","unstructured":"Lee, J.K., Kim, S.J., Park, C.Y., Hong, T., Chae, H.: Heavy-tailed distribution of the SSH brute-force attack duration in a multi-user environment. J. Korean Phys. Soc. 69(2), 253\u2013258 (2016). https:\/\/doi.org\/10.3938\/jkps.69.253","journal-title":"J. Korean Phys. Soc."},{"key":"8_CR21","doi-asserted-by":"publisher","unstructured":"Lehtinen, S., Lonvick, C.: The Secure Shell (SSH) Protocol Assigned Numbers. RFC 4250 (Proposed Standard), January 2006. https:\/\/doi.org\/10.17487\/RFC4250","DOI":"10.17487\/RFC4250"},{"key":"8_CR22","unstructured":"McDougall, R., Gillespie, N., Guster, D.: Using an enhanced dictionary to facilitate auditing techniques related to brute force SSH and FTP attacks. In: 44th Midwest Instruction and Computing Symposium (MICS). Midwest Instruction and Computing Symposium (MICS), April 2011. https:\/\/micsymposium.org\/mics_2011_proceedings\/mics2011_submission_10.pdf"},{"key":"8_CR23","doi-asserted-by":"publisher","unstructured":"Najafabadi, M.M., Khoshgoftaar, T.M., Calvert, C., Kemp, C.: Detection of SSH brute force attacks using aggregated netflow data. In: 2015 IEEE 14th International Conference on Machine Learning and Applications (ICMLA), pp. 283\u2013288. IEEE, December 2015. https:\/\/doi.org\/10.1109\/ICMLA.2015.20","DOI":"10.1109\/ICMLA.2015.20"},{"key":"8_CR24","unstructured":"Owens, J., Matthews, J.: A Study of Passwords and Methods Used in Brute-Force SSH Attacks, February 2008. https:\/\/people.clarkson.edu\/~jmatthew\/publications\/leet08.pdf"},{"issue":"1","key":"8_CR25","doi-asserted-by":"publisher","first-page":"887","DOI":"10.32604\/cmc.2021.015172","volume":"68","author":"J Park","year":"2021","unstructured":"Park, J., Kim, J., Gupta, B.B., Park, N.: Network log-based SSH brute-force attack detection model. Comput. Mater. Continua 68(1), 887\u2013901 (2021). https:\/\/doi.org\/10.32604\/cmc.2021.015172","journal-title":"Comput. Mater. Continua"},{"key":"8_CR26","doi-asserted-by":"publisher","unstructured":"Postel, J., Reynolds, J.K.: Telnet Protocol Specification. RFC 854 (Internet Standard), May 1983. https:\/\/doi.org\/10.17487\/RFC0854","DOI":"10.17487\/RFC0854"},{"key":"8_CR27","doi-asserted-by":"publisher","unstructured":"Postel, J., Reynolds, J.K.: File Transfer Protocol. RFC 959 (Internet Standard), October 1985. https:\/\/doi.org\/10.17487\/RFC0959","DOI":"10.17487\/RFC0959"},{"key":"8_CR28","doi-asserted-by":"publisher","unstructured":"Raikar, M.M., Maralappanavar, M.: SSH brute force attack mitigation in Internet of Things (IoT) network: an edge device security measure. In: 2021 2nd International Conference on Secure Cyber Computing and Communications (ICSCCC), pp. 72\u201377, May 2021. https:\/\/doi.org\/10.1109\/ICSCCC51823.2021.9478131","DOI":"10.1109\/ICSCCC51823.2021.9478131"},{"issue":"4","key":"8_CR29","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/TIT.1954.1057465","volume":"4","author":"IS Reed","year":"1954","unstructured":"Reed, I.S.: A class of multiple-error-correcting codes and the decoding scheme. Inf. Theory Trans. IRE Prof. Group 4(4), 38\u201349 (1954). https:\/\/doi.org\/10.1109\/TIT.1954.1057465","journal-title":"Inf. Theory Trans. IRE Prof. Group"},{"key":"8_CR30","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/978-981-13-2348-5_9","volume-title":"Towards Extensible and Adaptable Methods in Computing","author":"GK Sadasivam","year":"2018","unstructured":"Sadasivam, G.K., Hota, C., Anand, B.: Honeynet data analysis and distributed SSH brute-force attacks. In: Chakraverty, S., Goel, A., Misra, S. (eds.) Towards Extensible and Adaptable Methods in Computing, pp. 107\u2013118. Springer, Singapore (2018). https:\/\/doi.org\/10.1007\/978-981-13-2348-5_9"},{"key":"8_CR31","unstructured":"Seifert, C.: Analyzing Malicious SSH Login Attempts, September 2006. https:\/\/www.symantec.com\/connect\/articles\/analyzing-malicious-ssh-login-attempts"},{"key":"8_CR32","unstructured":"Shmagin, D.: Utilizing Machine Learning Classifiers to Identify SSH Brute Force Attacks, May 2019. https:\/\/scholarworks.wm.edu\/honorstheses\/1416"},{"key":"8_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1007\/978-3-642-04989-7_13","volume-title":"Integrated Management of Systems, Services, Processes and People in IT","author":"A Sperotto","year":"2009","unstructured":"Sperotto, A., Sadre, R., de Boer, P.-T., Pras, A.: Hidden Markov model modeling of SSH brute-force attacks. In: Bartolini, C., Gaspary, L.P. (eds.) DSOM 2009. LNCS, vol. 5841, pp. 164\u2013176. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-04989-7_13"},{"key":"8_CR34","doi-asserted-by":"publisher","unstructured":"Studiawan, H., Pratomo, B.A., Anggoro, R.: Clustering of SSH brute-force attack logs using k-Clique percolation. In: 2016 International Conference on Information Communication Technology and Systems (ICTS), pp. 39\u201342. IEEE, October 2016. https:\/\/doi.org\/10.1109\/ICTS.2016.7910269","DOI":"10.1109\/ICTS.2016.7910269"},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"Wanjau, S.K., Wambugu, G.M., Kamau, G.N.: SSH-brute force attack detection model based on deep learning. Int. J. Comput. Appl. Technol. Res. (IJCATR) 10(1), 42\u201350 (2021). https:\/\/ijcat.com\/archieve\/volume10\/issue1\/ijcatr10011008.pdf","DOI":"10.7753\/IJCATR1001.1008"},{"key":"8_CR36","doi-asserted-by":"crossref","unstructured":"Wu, Y., Cao, P.M., Withers, A., Kalbarczyk, Z.T., Iyer, R.K.: Mining threat intelligence from billion-scale SSH brute-force attacks. In: Proceedings of Decentralized IoT Systems and Security (DISS) Workshop 2020, February 2020. https:\/\/www.ndss-symposium.org\/wp-content\/uploads\/2020\/04\/diss2020-23007-paper.pdf","DOI":"10.14722\/diss.2020.23007"},{"key":"8_CR37","doi-asserted-by":"publisher","unstructured":"Yao, C., Luo, X., Zincir-Heywood, A.N.: Data analytics for modeling and visualizing attack behaviors: a case study on SSH brute force attacks. In: 2017 IEEE Symposium Series on Computational Intelligence (SSCI), pp. 1\u20138. IEEE, December 2017. https:\/\/doi.org\/10.1109\/SSCI.2017.8280913","DOI":"10.1109\/SSCI.2017.8280913"},{"key":"8_CR38","doi-asserted-by":"publisher","unstructured":"Yl\u00f6nen, T., Lonvick, C.: The Secure Shell (SSH) Authentication Protocol. RFC 4252 (Proposed Standard), January 2006. https:\/\/doi.org\/10.17487\/RFC4252","DOI":"10.17487\/RFC4252"},{"key":"8_CR39","doi-asserted-by":"publisher","unstructured":"Yl\u00f6nen, T., Lonvick, C.: The Secure Shell (SSH) Connection Protocol. RFC 4254 (Proposed Standard), January 2006. https:\/\/doi.org\/10.17487\/RFC4254","DOI":"10.17487\/RFC4254"},{"key":"8_CR40","doi-asserted-by":"publisher","unstructured":"Yl\u00f6nen, T., Lonvick, C.: The Secure Shell (SSH) Protocol Architecture. RFC 4251 (Proposed Standard), January 2006. https:\/\/doi.org\/10.17487\/RFC4251","DOI":"10.17487\/RFC4251"},{"key":"8_CR41","doi-asserted-by":"publisher","unstructured":"Yl\u00f6nen, T., Lonvick, C.: The Secure Shell (SSH) Transport Layer Protocol. RFC 4253 (Proposed Standard), January 2006. https:\/\/doi.org\/10.17487\/RFC4253","DOI":"10.17487\/RFC4253"}],"container-title":["Communications in Computer and Information Science","Innovations for Community Services"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-06668-9_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,5]],"date-time":"2022-06-05T23:12:17Z","timestamp":1654470737000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-06668-9_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031066672","9783031066689"],"references-count":41,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-06668-9_8","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"6 June 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"I4CS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Innovations for Community Services","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Delft","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 June 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 June 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"i4cs2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.i4cs-conference.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"43","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.53","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5.43","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}