Active and Passive Collection of SSH key material for cyber threat intelligence

04/11/2022
by   Alexandre Dulaunoy, et al.
0

This paper describes a system for storing historical forensic artefacts collected from SSH connections. This system exposes a REST API in a similar fashion as passive DNS databases, malware hash registries, and SSL notaries with the goal of supporting incident investigations and monitoring of infrastructure.

READ FULL TEXT

Please sign up or login with your details

Forgot password? Click here to reset