USENIX Security2023Top-tier venue
Network Detection of Interactive SSH Impostors Using Deep Learning
Julien Piet, Aashish Sharma, Vern Paxson, David A. Wagner
Abstract
Impostors who have stolen a user's SSH login credentials can inflict significant harm to the systems to which the user has remote access. We consider the problem of identifying such imposters when they conduct interactive SSH logins by detecting discrepancies in the timing and sizes of the clientside data packets, which generally reflect the typing dynamics of the person sending keystrokes over the connection. The problem of keystroke authentication using unknown freeform text has received limited-scale study to date. We develop a supervised approach based on using a transformer (a sequence model from the ML deep learning literature) and a custom "partition layer" that, once trained, takes as input the sequence of client packet timings and lengths, plus a purported user label, and outputs a decision regarding whether the sequence indeed corresponds to that user. We evaluate the model on 5 years of labeled SSH PCAPs (spanning 3,900 users) from a large research institute. While the performance specifics vary with training levels, we find that in all cases the model can catch over 95% of (injected) imposters within the first minutes of a connection, while incurring a manageable level of false positives per day.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a603776c-13de-4c9f-8523-c429aa6669efCited by top-tier papers4
- A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal AnalyticsJiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou et al.INFOCOM 2025 · 6 citations
- On Precisely Detecting Censorship Circumvention in Real-World NetworksRyan Wails, George Arnold Sullivan, Micah Sherr, Rob JansenNDSS 2024
- A First-Principles Evaluation of Graph-Based Network Intrusion Detection SystemsRui Zhao, Wajih UI HassanCCS 2026
- Censorship Evasion with Unidentified Protocol GenerationRyan Wails, Rob Jansen, Aaron Johnson, Micah SherrUSENIX Security 2025
Related papers
- Exploring the Effect of Music on User Typing and Identification through Keystroke DynamicsLukas Mecke, Assem Mahmoud, Simon Marat, Florian AltCHI 2025 · 1 citation
- Detecting Structurally Anomalous Logins Within Enterprise NetworksHossein Siadati, Nasir D. MemonCCS 2017 · 44 citations
- Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop ThemSachin Kumar Singh, Shreeman Gautam, Cameron Cartier, Sameer Patil et al.NSDI 2024 · 15 citations
- Automata-Based Automated Detection of State Machine Bugs in Protocol ImplementationsPaul Fiterau-Brostean, Bengt Jonsson, Konstantinos Sagonas, Fredrik TåquistNDSS 2023
- pASSWORD tYPOS and How to Correct Them SecurelyRahul Chatterjee, Anish Athayle, Devdatta Akhawe, Ari Juels et al.S&P 2016 · 68 citations
