{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,4,3]],"date-time":"2022-04-03T19:49:35Z","timestamp":1649015375307},"reference-count":35,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2015]]},"DOI":"10.1587\/transinf.2014icp0005","type":"journal-article","created":{"date-parts":[[2015,4,1]],"date-time":"2015-04-01T15:11:47Z","timestamp":1427901107000},"page":"760-768","source":"Crossref","is-referenced-by-count":0,"title":["A New Approach to Identify User Authentication Methods toward SSH Dictionary Attack Detection"],"prefix":"10.1587","volume":"E98.D","author":[{"given":"Akihiro","family":"SATOH","sequence":"first","affiliation":[{"name":"Kyushu Institute of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yutaka","family":"NAKAMURA","sequence":"additional","affiliation":[{"name":"Kyushu Institute of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takeshi","family":"IKENAGA","sequence":"additional","affiliation":[{"name":"Kyushu Institute of Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","unstructured":"[1] T. Ylonen, \u201cSSH: Secure login connections over the Internet,\u201d Proc. 6th Conference on USENIX Security Symposium, Focusing on Applications of Cryptography, vol.6, 1996."},{"key":"2","unstructured":"[2] Net-SSH-Expect, http:\/\/www.cpan.org\/"},{"key":"3","unstructured":"[3] J. Ouellette, \u201cParanoid penguin: Managing SSH for scripts and cron jobs,\u201d Linux Journal, no.137, 2005."},{"key":"4","unstructured":"[4] R. Strubinger, \u201cShell scripting: A homegrown backup solution utilizing RSA keys, SSH, and tar,\u201d J. Sys. Admin., vol.11, no.4, pp.37-38, 2002."},{"key":"5","doi-asserted-by":"crossref","unstructured":"[5] C. Rapier and B. Bennett, \u201cHigh speed bulk data transfer using the SSH protocol,\u201d Proc. 15th ACM Mardi Gras Conference, no.11, pp.1-7, 2008.","DOI":"10.1145\/1341811.1341824"},{"key":"6","unstructured":"[6] F. Pellegrin and C. Pellegrin, \u201cSystem administration: Secure logging over a network,\u201d Linux Journal, no.74, 2000."},{"key":"7","doi-asserted-by":"crossref","unstructured":"[7] V. Marinov and J. Schonwalder, \u201cPerformance analysis of SNMP over SSH,\u201d Proc. 17th IFIP\/IEEE International Conference on Distributed Systems: Operations and Management, vol.12, no.3, pp.25-36, 2006.","DOI":"10.1007\/11907466_3"},{"key":"8","unstructured":"[8] SANS Internet Storm Center, http:\/\/isc.sans.edu\/"},{"key":"9","doi-asserted-by":"crossref","unstructured":"[9] J. Vykopal, T. Plesnik, and P. Minarik, \u201cNetwork-based dictionary attack detection,\u201d Proc. International Conference on Future Networks, pp.23-27, 2009.","DOI":"10.1109\/ICFN.2009.36"},{"key":"10","doi-asserted-by":"crossref","unstructured":"[10] L. Hellemons, L. Hendriks, R. Hofstede, A. Sperotto, R. Sadre, and A. Pras, \u201cSSHCure: A flow-based SSH intrusion detection system,\u201d Lect. Notes Comput. Sci., vol.7279, pp.86-97, 2012.","DOI":"10.1007\/978-3-642-30633-4_11"},{"key":"11","doi-asserted-by":"crossref","unstructured":"[11] K. Takemori, D.A.L. Romana, S. Kubota, K. Sugitani, and Y. Musashi, \u201cDetection of NS resource record DNS resolution traffic, host search, and SSH dictionary attack activities,\u201d Int. J. Intelligent Engineering and Systems, vol.2, no.4, pp.35-42, 2009.","DOI":"10.22266\/ijies2009.1231.05"},{"key":"12","doi-asserted-by":"crossref","unstructured":"[12] A. Satoh, Y. Nakamura, and T. Ikenaga, \u201cSSH dictionary attack detection based on flow analysis,\u201d Proc. 12th IEEE\/IPSJ International Symposium on Applications and the Internet, pp.51-59, 2012.","DOI":"10.1109\/SAINT.2012.16"},{"key":"13","doi-asserted-by":"crossref","unstructured":"[13] T. Ylonen and C. Lonvick, \u201cThe Secure Shell (SSH) transport layer protocol,\u201d RFC 4253, 2006.","DOI":"10.17487\/rfc4253"},{"key":"14","doi-asserted-by":"crossref","unstructured":"[14] T. Ylonen and C. Lonvick, \u201cThe Secure Shell (SSH) authentication protocol,\u201d RFC 4252, 2006.","DOI":"10.17487\/rfc4252"},{"key":"15","doi-asserted-by":"crossref","unstructured":"[15] T. Ylonen and C. Lonvick, \u201cThe Secure Shell (SSH) connection protocol,\u201d RFC 4254, 2006.","DOI":"10.17487\/rfc4254"},{"key":"16","unstructured":"[16] OpenSSH, http:\/\/www.openssh.com\/"},{"key":"17","unstructured":"[17] Tectia, http:\/\/www.ssh.com\/"},{"key":"18","doi-asserted-by":"crossref","unstructured":"[18] R.K. Guha, Z. Furqan, and S. Muhammad, \u201cDiscovering man-in-the-middle attacks in authentication protocols,\u201d Proc. 26th IEEE Conference on Military Communications, pp.1-7, 2007.","DOI":"10.1109\/MILCOM.2007.4455039"},{"key":"19","unstructured":"[19] J. Owens and J. Matthews, \u201cA study of passwords and methods used in brute-force SSH attacks,\u201d tech. rep., Department of Computer Science, Clarkson University of New York, 2008."},{"key":"20","doi-asserted-by":"crossref","unstructured":"[20] D. Ramsbrock, R. Berthier, and M. Cukier, \u201cProfiling attacker behavior following SSH compromises,\u201d Proc. 37th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp.119-124, 2007.","DOI":"10.1109\/DSN.2007.76"},{"key":"21","unstructured":"[21] SSHGuard, http:\/\/www.sshguard.net\/"},{"key":"22","unstructured":"[22] DenyHOSTS, http:\/\/denyhosts.sourceforge.net\/"},{"key":"23","unstructured":"[23] SSHBLACK, http:\/\/sshblack.com"},{"key":"24","unstructured":"[24] BlockHosts, http:\/\/www.aczoom.com\/tools\/blockhosts\/"},{"key":"25","unstructured":"[25] BruteForceBlocker, http:\/\/danger.rulez.sk\/projects\/bruteforceblocker\/"},{"key":"26","doi-asserted-by":"crossref","unstructured":"[26] J.L. Thames, R. Abler, and D. Keeling, \u201cA distributed active response architecture for preventing SSH dictionary attacks,\u201d Proc. IEEE Southeast Conference, pp.84-89, 2008.","DOI":"10.1109\/SECON.2008.4494264"},{"key":"27","doi-asserted-by":"crossref","unstructured":"[27] A. Satoh, Y. Nakamura, and T. Ikenaga, \u201cA flow-based detection method for stealthy dictionary attacks against secure shell,\u201d J. Information Security and Applications, available online: http:\/\/www.sciencedirect.com\/science\/article\/pii\/S221421261400129X, 2014.","DOI":"10.1016\/j.jisa.2014.08.003"},{"key":"28","doi-asserted-by":"crossref","unstructured":"[28] M. Javed and V. Paxson, \u201cDetecting stealthy, distributed SSH brute-forcing,\u201d Proc. 20th ACM SIGSAC Conference on Computer &amp; Communications Security, pp.85-96, 2013.","DOI":"10.1145\/2508859.2516719"},{"key":"29","unstructured":"[29] A.W. Moore, D. Zuev, and M.L. Crogan, \u201cDiscriminators for use in flow-based classification,\u201d tech. rep., Department of Computer Science, Queen Mary University of London, 2005."},{"key":"30","doi-asserted-by":"crossref","unstructured":"[30] A. Satoh, Y. Nakamura, and T. Ikenaga, \u201cIdentifying user authentication methods on connections for SSH dictionary attack detection,\u201d Proc. IEEE 37th Annual Computer Software and Applications Conference, pp.593-598, 2013.","DOI":"10.1109\/COMPSACW.2013.80"},{"key":"31","doi-asserted-by":"crossref","unstructured":"[31] C.V. Wright, F. Monrose, and G.M. Masson, \u201cUsing visual motifs to classify encrypted traffic,\u201d Proc. 3rd International Workshop on Visualization for Computer Security, pp.41-50, 2006.","DOI":"10.1145\/1179576.1179584"},{"key":"32","unstructured":"[32] N. Provos and P. Honeyman, \u201cScanSSH \u2014 Scanning the Internet for SSH servers,\u201d Proc. 15th USENIX Systems Administration Conference, pp.25-30, 2001."},{"key":"33","unstructured":"[33] Net-Scan-SSH-Server-SupportedAuth, http:\/\/www.cpan.org\/"},{"key":"34","doi-asserted-by":"crossref","unstructured":"[34] L. Bernaille, R. Teixeira, and K. Salamation, \u201cEarly application identification,\u201d Proc. ACM CoNext Conference, no.6, pp.1-12, 2006.","DOI":"10.1145\/1368436.1368445"},{"key":"35","doi-asserted-by":"crossref","unstructured":"[35] M. Dusi, M. Crotti, F. Gringoli, and L. Salgarelli, \u201cTunnel hunter: Detecting application-layer tunnels with statistical fingerprinting,\u201d Int. J. Computer and Telecommunications Networking, vol.53, no.1, pp.81-97, 2009.","DOI":"10.1016\/j.comnet.2008.09.010"}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E98.D\/4\/E98.D_2014ICP0005\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,22]],"date-time":"2019-08-22T18:44:21Z","timestamp":1566499461000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E98.D\/4\/E98.D_2014ICP0005\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"references-count":35,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2015]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2014icp0005","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"value":"0916-8532","type":"print"},{"value":"1745-1361","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015]]}}}