{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/108105"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/108105","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Mining threat intelligence from billion-scale SSH brute-force attacks","abstract":"Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:55:59Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","abstract_html":"Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:55:59Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","abstract_has_math":false,"creators":["Wu, Yuming"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Iyer, Ravishankar K","Kalbarczyk, Zbigniew T"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2020,"date_issued":"2020-08-26T23:54:30Z","date_published":"2020-08-26T23:54:30Z","updated_at":"2026-07-22T22:24:47Z","subjects":["SSH honeypot","SSH brute-force attack","SSH key","SSH client version"],"languages":["en"],"rights":["Copyright 2020 Yuming Wu"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/108105","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Iyer, Ravishankar K","Kalbarczyk, Zbigniew T"]},{"key":"dc:creator","label":"Author","values":["Wu, Yuming"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2020-08-26T23:54:30Z","2022-08-26T23:58:55Z","2020-04-13","2020-05"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["SSH honeypot","SSH brute-force attack","SSH key","SSH client version"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2020 Yuming Wu"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/108105"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:55:59Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","This thesis first presents Continuous Auditing of Secure Shell (SSH) Servers to Mitigate Brute-Force Attacks (CAUDIT), an operational system deployed at the National Center for Supercomputing Applications (NCSA) at the University of Illinois. One of CAUDIT’s key features includes a honeypot, which attracted and recorded 11 billion SSH brute-force attack attempts targeting the operational system at NCSA from February 2017 to November 2019. Based on the attack data, this thesis then presents a comprehensive study to characterize the attack nature of the 11 billion attack attempts. We report the nature of these attacks in terms of i) persistence (i.e., consecutively attacking over an entire year), ii) targeted strategies (i.e., using stolen SSH keys), iii) large-scale evasion techniques (i.e., using randomized SSH client versions) to bypass signature detectors, and iv) behaviors of human- supervised botnet. The significance of our analyses for security operators include i) discerning cross-country attacks versus persistent attacks, ii) notifying cloud providers and IoT vendors regarding stolen SSH keys for them to verify the effectiveness of software patches, iii) deterring the above evasion techniques by using anomaly detectors/rate limiters, and iv) differentiating between fully automated attacks versus more sophisticated attacks driven by human. The work in this thesis is completed in two stages along with two papers. The first paper is published in 16th USENIX Symposium on Networked Systems Design and Implementation (NSDI’19), and the second paper is to be published in Workshop on Decentralized IoT Systems and Security (DISS) 2020. We collaborated with NCSA, which provided us with the network operational system and attack data. The research and analysis were performed jointly with the co-authors in the two papers. My specific contribution is highlighted in this thesis is threat intelligence analysis.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2022-05-01","The student, Yuming Wu, accepted the attached license on 2020-04-10 at 15:47.","The student, Yuming Wu, submitted this Thesis for approval on 2020-04-10 at 16:36.","This Thesis was approved for publication on 2020-04-13 at 16:56.","DSpace SAF Submission Ingestion Package generated from Vireo submission #14958 on 2020-08-25 at 17:27:17","Made available in DSpace on 2020-08-26T23:54:30Z (GMT). No. of bitstreams: 4 WU-THESIS-2020.pdf: 757290 bytes, checksum: 608bf9c818a4785014d144ca9b1a9bd0 (MD5) thesis_yuming_source.zip: 40128529 bytes, checksum: 389eb34e3ebd8597ab00e2591a255770 (MD5) LICENSE.txt: 4206 bytes, checksum: 4f85b23eb0bc3bca663f06a9d556b15b (MD5) NSDI '19 copyright.htm: 271356 bytes, checksum: 9b7bb34038e9e8bacc62396d30f14bbb (MD5) Previous issue date: 2020-04-13","Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:54:40Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:57:28Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:58:55Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Mining threat intelligence from billion-scale SSH brute-force attacks"]}]}],"canonical_facts":{"dc:contributor":["Iyer, Ravishankar K","Kalbarczyk, Zbigniew T"],"dc:creator":["Wu, Yuming"],"dc:date":["2020-08-26T23:54:30Z","2022-08-26T23:58:55Z","2020-04-13","2020-05"],"dc:description":["Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:55:59Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","This thesis first presents Continuous Auditing of Secure Shell (SSH) Servers to Mitigate Brute-Force Attacks (CAUDIT), an operational system deployed at the National Center for Supercomputing Applications (NCSA) at the University of Illinois. One of CAUDIT’s key features includes a honeypot, which attracted and recorded 11 billion SSH brute-force attack attempts targeting the operational system at NCSA from February 2017 to November 2019. Based on the attack data, this thesis then presents a comprehensive study to characterize the attack nature of the 11 billion attack attempts. We report the nature of these attacks in terms of i) persistence (i.e., consecutively attacking over an entire year), ii) targeted strategies (i.e., using stolen SSH keys), iii) large-scale evasion techniques (i.e., using randomized SSH client versions) to bypass signature detectors, and iv) behaviors of human- supervised botnet. The significance of our analyses for security operators include i) discerning cross-country attacks versus persistent attacks, ii) notifying cloud providers and IoT vendors regarding stolen SSH keys for them to verify the effectiveness of software patches, iii) deterring the above evasion techniques by using anomaly detectors/rate limiters, and iv) differentiating between fully automated attacks versus more sophisticated attacks driven by human. The work in this thesis is completed in two stages along with two papers. The first paper is published in 16th USENIX Symposium on Networked Systems Design and Implementation (NSDI’19), and the second paper is to be published in Workshop on Decentralized IoT Systems and Security (DISS) 2020. We collaborated with NCSA, which provided us with the network operational system and attack data. The research and analysis were performed jointly with the co-authors in the two papers. My specific contribution is highlighted in this thesis is threat intelligence analysis.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2022-05-01","The student, Yuming Wu, accepted the attached license on 2020-04-10 at 15:47.","The student, Yuming Wu, submitted this Thesis for approval on 2020-04-10 at 16:36.","This Thesis was approved for publication on 2020-04-13 at 16:56.","DSpace SAF Submission Ingestion Package generated from Vireo submission #14958 on 2020-08-25 at 17:27:17","Made available in DSpace on 2020-08-26T23:54:30Z (GMT). No. of bitstreams: 4 WU-THESIS-2020.pdf: 757290 bytes, checksum: 608bf9c818a4785014d144ca9b1a9bd0 (MD5) thesis_yuming_source.zip: 40128529 bytes, checksum: 389eb34e3ebd8597ab00e2591a255770 (MD5) LICENSE.txt: 4206 bytes, checksum: 4f85b23eb0bc3bca663f06a9d556b15b (MD5) NSDI '19 copyright.htm: 271356 bytes, checksum: 9b7bb34038e9e8bacc62396d30f14bbb (MD5) Previous issue date: 2020-04-13","Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:54:40Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:57:28Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Embargo set by: Seth Robbins for item 115715 Lift date: 2022-08-26T23:58:55Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/108105"],"dc:language":["en"],"dc:rights":["Copyright 2020 Yuming Wu"],"dc:subject":["SSH honeypot","SSH brute-force attack","SSH key","SSH client version"],"dc:title":["Mining threat intelligence from billion-scale SSH brute-force attacks"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:47Z"}