首页> 外文会议>Annual Midwest Instruction and Computing Symposium >'Using An Enhanced Dictionary to Facilitate Auditing Techniques Related to Brute Force SSH and FTP Attacks'
【24h】

'Using An Enhanced Dictionary to Facilitate Auditing Techniques Related to Brute Force SSH and FTP Attacks'

机译:“使用增强词典来促进与蛮力SSH和FTP攻击相关的审计技术”

获取原文

摘要

This paper analyzes the efficiency of security auditing on network user accounts. More specifically, the paper focuses on the drawbacks of traditional network account username and password creation, namely "dictionaries." Most auditing methods will employ dictionaries, which in this case are lists of common user names and passwords, and use them to try and gain access by guessing the account credentials. When these dictionaries are created, they are based on a criterion that weakens passwords. As an alternative, the authors consider a new way to create a network dictionary, focusing on two important elements: default user names and common user name schemes. A user name dictionary emphasizing user name accuracy based on common schemes, used in conjunction with a large password dictionary, reduces the chances of a security breach. The security put in place creates account lockouts, banning the IP addresses of attackers. This auditing method lowers the effectiveness of attacks.
机译:本文分析了网络用户帐户的安全审计效率。更具体地说,该文件侧重于传统的网络帐户用户名和密码创建的缺点,即“词典”。大多数审计方法都将采用词典,在这种情况下,该字典是常见的用户名和密码列表,并使用它们来尝试通过猜测帐户凭据来获取访问。创建这些词典时,它们基于削弱密码的标准。作为替代方案,作者考虑了一种创建网络词典的新方法,专注于两个重要元素:默认用户名和常用用户名方案。用户名字典强调基于与大密码字典一起使用的常见方案的用户名准确性,从而减少了安全漏洞的机会。建立的安全性创建帐户锁定,禁止攻击者的IP地址。该审计方法降低了攻击的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号