首页> 外文会议>44th Annual Midwest Instruction and Computing Symposium 2011. >'Using An Enhanced Dictionary to Facilitate Auditing Techniques Related to Brute Force SSH and FTP Attacks'
【24h】

'Using An Enhanced Dictionary to Facilitate Auditing Techniques Related to Brute Force SSH and FTP Attacks'

机译:“使用增强型词典来简化与蛮力SSH和FTP攻击有关的审核技术”

获取原文
获取原文并翻译 | 示例

摘要

This paper analyzes the efficiency of security auditing on network user accounts. More specifically, the paper focuses on the drawbacks of traditional network account username and password creation, namely "dictionaries." Most auditing methods will employ dictionaries, which in this case are lists of common user names and passwords, and use them to try and gain access by guessing the account credentials. When these dictionaries are created, they are based on a criterion that weakens passwords. As an alternative, the authors consider a new way to create a network dictionary, focusing on two important elements: default user names and common user name schemes. A user name dictionary emphasizing user name accuracy based on common schemes, used in conjunction with a large password dictionary, reduces the chances of a security breach. The security put in place creates account lockouts, banning the IP addresses of attackers. This auditing method lowers the effectiveness of attacks.
机译:本文分析了对网络用户帐户进行安全审核的效率。更具体地说,本文着眼于传统网络帐户用户名和密码创建(即“字典”)的弊端。大多数审核方法将使用词典,在这种情况下,词典是常用用户名和密码的列表,并使用它们来猜测帐户凭据,从而尝试获得访问权限。创建这些字典时,它们基于削弱密码的条件。作为替代方案,作者考虑了一种创建网络词典的新方法,主要关注两个重要元素:默认用户名和通用用户名方案。结合大型密码字典使用的,基于通用方案强调用户名称准确性的用户名称字典可减少安全漏洞的机会。实施的安全措施会导致帐户锁定,从而禁止攻击者的IP地址。这种审核方法降低了攻击的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号