English

Active and Passive Collection of SSH key material for cyber threat intelligence

Cryptography and Security 2022-04-12 v1 Networking and Internet Architecture

Abstract

This paper describes a system for storing historical forensic artefacts collected from SSH connections. This system exposes a REST API in a similar fashion as passive DNS databases, malware hash registries, and SSL notaries with the goal of supporting incident investigations and monitoring of infrastructure.

Keywords

Cite

@article{arxiv.2204.04922,
  title  = {Active and Passive Collection of SSH key material for cyber threat intelligence},
  author = {Alexandre Dulaunoy and Jean-Louis Huynen and Aurelien Thirion},
  journal= {arXiv preprint arXiv:2204.04922},
  year   = {2022}
}