3 ms·
It indeed is. If a port scanner does any analysis on the welcome banner, it's pretty obvious when you're dealing with an SSH server. That is, unless someone d
by elmo2you 6y ago
It indeed is.
If a port scanner does any analysis on the welcome banner, it's pretty obvious when you're dealing with an SSH server.
That is, unless someone decided to run with a custom banner, which isn't something I have come across often in over two decades of experience (but I might not have recognized one if I saw one). The reality is that many (fast) scanners/script-kiddies often only scan for default ports. Changing the default port will lower your hit rate.
It could be argued that this will only eliminate the less sophisticated attackers, which might hold some merit. However, good security is almost always a combination of factors that each add their own little contribution to the overall security. Even small increases can be worth it in the overall effort.
Time is often an overlooked aspect within security. If you have SSH on an alternative port, you can use the detection of an inbound scan on the standard port to mitigate an subsequent scan/attack on your custom port. For instance by throwing the scanning IP address immediately in a deny ACL. Just a suggestion.
Port knocking is also be an interesting concept, but a whole different discussion.