b.sc. computer science m.sc. telematics (april 2014) now: ph.d. … · 2015-03-27 · (net)flow 101...

9
Luuk Hendriks B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. student at DACS (Graduation) project: SSHCure

Upload: others

Post on 07-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:

Luuk HendriksB.Sc. Computer ScienceM.Sc. Telematics (April 2014)

Now: Ph.D. student at DACS

(Graduation) project: SSHCure

Page 2: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:

SSH Intrusion Detection

Detection based on three phases:scan, brute-force, compromise

Network-level information for scalability

Behavioral analysis of attack tools in terms of flows

Page 3: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:

(Net)Flow 101

10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags: ASFP Start: 1414177099 End: 1414177261

Page 4: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:

(Net)Flow 101

10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags: ASFP Start: 1414177099 End: 1414177261

10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags: ASFP Start: 1414177099 End: 1414177261

Page 5: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:

(Net)Flow 101

10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags: ASFP Start: 1414177099 End: 1414177261

10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags: ASFP Start: 1414177099 End: 1414177261

Page 6: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:
Page 7: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:
Page 8: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags:
Page 9: B.Sc. Computer Science M.Sc. Telematics (April 2014) Now: Ph.D. … · 2015-03-27 · (Net)Flow 101 10.112.10.10:54876 -> 192.168.1.1:22 Bytes: 45378 Proto: TCP Packets: 211 Flags: