4 ms·
Yeah, but then you would have ssh traffic without a matching login. Wonder if any anomaly detection would work on that
by gitfan86 3y ago
Yeah, but then you would have ssh traffic without a matching login.
Wonder if any anomaly detection would work on that
- FergusArgyll 3y agoInteresting... Though you can edit whatever log file you want
- jmb99 3y agoAny log that root on that box has write access to. It’s theoretically possible to have an anomaly detection service running on a vulnerable machine dumping all of its’ data to an append-only service on some other non-compromised box. In that case, (in this ideal world) the attacker would not be able to disable the detection service before it had logged the anomalous traffic, and wouldn’t be able to purge those logs since they were on another machine. I’m not aware of any services that a) work like this, or b) would be able to detect this class of attack earlier than last week. If someone does though, please share.
- fubar9463 3y agoYou would be sending logs to a log collector (a SIEM) in security terms, and then you could join your firewall logs against your SSH auth logs. This kind of anomaly detection is possible. Not sure how common it is. I doubt it is common.
- fubar9463 3y agoIn any case the ROI for correlating SSH logs against network traffic is potentially error prone and may be more noisy than useful (can you differentiate in logs between SSH logins from a private IP and a public one?). An EDR tool would be much better to look for an attacker’s next steps. But if you’re trying to catch a nation state they probably already have a plan for hiding their tracks.
- juitpykyk 3y agoYou can do it on a single machine if you use the TPM to create log hashes which can't be rolled back.
- deleted 3y ago[deleted]
- skykooler 3y agoThat would look the same as a random failed ssh login, which happens all the time. The connection isn't maintained past that point (unless the payload chooses to do so).