IT Forensics · Linux

Forensic evidence of SSH brute-force attacks – Providing forensic evidence of systematic login attempts

SSH brute-force attacks are characterised by a large number of automated login attempts using different sets of credentials, with the aim of guessing the correct credentials for a system.

Enquire without obligation

Authentication logs typically record both failed and successful login attempts, enabling a forensic reconstruction of both the course of the attack and any potential success on the part of the attacker.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We systematically analyse authentication logs for patterns of automated login attempts, determine the scale and duration of a brute-force attack, and check whether it was ultimately successful.

Typical areas of application

Evidence of systematic brute-force attack attempts
Determining whether an attack was ultimately successful
Identification of the login credentials that were originally compromised
Assessment of the adequacy of existing safeguards
Incident Response on Linux Systems
Judicial and non-judicial expert reports

How an SSH brute-force attack is carried out

Once the system has been secured, the relevant authentication logs are fully analysed and examined for patterns of automated, systematic login attempts. Particular attention is paid to the time interval between a failed login attempt and a potentially successful one.

Why is the SSH brute-force investigation relevant from a forensic perspective?

Determining whether a brute-force attack was ultimately successful is crucial to establishing whether the system was actually compromised or whether the attempts were unsuccessful.

Identifying the compromised login details is also important in order to secure the affected accounts in a targeted manner and to check other systems that may be protected by the same login details.

Frequently Asked Questions

How is a brute-force attack typically detected?+
A strikingly high number of failed login attempts within a short period of time, often from the same or different IP addresses.
How is a successful attack identified?+
By carrying out a targeted check for a successful login following a series of failed attempts from the same account.
Can distributed attacks originating from many different addresses also be detected?+
Yes, such distributed attack patterns are identified through a comprehensive analysis of all relevant login attempts.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „proving SSH brute-force attacks forensically"? LanCologne can assist you in securing digital evidence in a manner that stands up in court, as well as in the traceable analysis of relevant Linux artefacts.

Get in touch now