Where The Wild Things Are: Brute-Force SSH Attacks In The Wild And How To Stop Them
Sachin Kumar Singh, Shreeman Gautam, Cameron Cartier, Sameer Patil, Robert Ricci
Abstract
SSH (Secure Shell) is widely used for remote access to systems and cloud services. This access comes with the persistent threat of SSH password-guessing brute-force attacks (BFAs) directed at sshd-enabled devices connected to the Internet. In this work, we present a comprehensive study of such attacks on a production facility (CloudLab), offering previously unreported insight. Our study provides a detailed analysis of SSH BFAs occurring on the Internet today through an in-depth analysis of sshd logs collected over a period of four years from over 500 servers. We report several patterns in attacker behavior, present insight on the targets of the attacks, and devise a method for tracking individual attacks over time across sources. Leveraging our insight, we develop a defense mechanism against SSH BFAs that blocks 99.5% of such attacks, significantly outperforming the 66.1% coverage of current state-of-the-art rate-based blocking while also cutting false positives by 83%. We have deployed our defense in production on CloudLab, where it catches four-fifths of SSH BFAs missed by other defense strategies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- NetCap: Data-Plane Capability-Based Defense Against Token Theft in Network AccessOsama Bajaber, Bo Ji, Peng GaoNDSS 2026 · 2 citations
- Catch-22: Uncovering Compromised Hosts using SSH Public KeysCristian Munteanu, Georgios Smaragdakis, Anja Feldmann, Tobias FiebigUSENIX Security 2025
Builds on4
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Under the Shadow of Sunshine: Understanding and Detecting Bulletproof Hosting on Legitimate Service Provider NetworksSumayah A. Alrwais, Xiaojing Liao, Xianghang Mi, Peng Wang et al.S&P 2017 · 51 citations
- Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof HostingArman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Hernandez Gañán et al.USENIX Security 2019 · 40 citations
- Gossamer: Securely Measuring Password-based LoginsMarina Sanusi Bohuk, Mazharul Islam, Suleman Ahmad, Michael M. Swift et al.USENIX Security 2022
Related papers
- Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number ManipulationFabian Bäumer, Marcus Brinkmann, Jörg SchwenkUSENIX Security 2024 · 15 citations
- Araña: Discovering and Characterizing Password Guessing Attacks in PracticeMazharul Islam, Marina Sanusi Bohuk, Paul Chung, Thomas Ristenpart et al.USENIX Security 2023
- Secure IP Address Allocation at Cloud ScaleEric Pauley, Kyle Domico, Blaine Hoak, Ryan Sheatsley et al.NDSS 2025
- On the Security of SSH Client SignaturesFabian Bäumer, Marcus Brinkmann, Maximilian Radoy, Jörg Schwenk et al.CCS 2025
- Network Detection of Interactive SSH Impostors Using Deep LearningJulien Piet, Aashish Sharma, Vern Paxson, David A. WagnerUSENIX Security 2023
