Monitoring HPC Systems against Compromised SSH

计算机科学 环境科学
作者
Lev Lafayette,Narendra Chinnam,Timothy Rice
出处
期刊:Chapman and Hall/CRC eBooks [Informa]
卷期号:: 333-354
标识
DOI:10.1201/9781003155799-12
摘要

Secure Shell is a very well established cryptographic network protocol for accessing operating network services and is the typical way to access high-performance computing (HPC) systems in preference to various unsecured remote shell protocols, such as rlogin, telnet, and ftp. SSH can be managed through configuration files and with passwordless SSH key-pairs easily automated in scripts. Despite the justified popularity and engineering excellence of SSH, in May 2020 multiple HPC centres across Europe found themselves subject to cyber-attacks via compromised SSH credentials. Based at experiences at the University of Melbourne HPC, it is possible at a system level using ssh-keygen to script a search to detect all keys with an empty password even when they are named differently with additional complexity required when parsing non-standard directories and configuration files. This is far more elegant than conducting a grep for MII and similar techniques which is commonly suggested. A further alternative is a test making direct use of libssh headers. This however, will require a version of libssh which incorporates the new SSH format, which is atypical for HPC systems which tend to have a degree of stability in the operating system level, even if they make use of diverse versions and compilers on the application level. Of course, invoking a different version of libssh (e.g., through an environment modules approach) provides an alternative solution which can be incorporated into a small C program (key_audit.c), which elegantly tests validation of an empty passphrase against a given keyfile.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
刚刚
马前人发布了新的文献求助10
1秒前
aaron9898完成签到,获得积分10
2秒前
3秒前
gjww应助高大的啤酒采纳,获得10
3秒前
iyaaaa完成签到,获得积分20
4秒前
原子完成签到,获得积分20
5秒前
华仔应助qwerty采纳,获得10
5秒前
三千完成签到 ,获得积分0
5秒前
小马甲应助虚幻双双采纳,获得30
5秒前
英勇MESSI完成签到,获得积分10
5秒前
wodetaiyangLLL完成签到,获得积分10
6秒前
xu发布了新的文献求助10
6秒前
CY完成签到,获得积分10
7秒前
黄伊若完成签到 ,获得积分10
7秒前
Lucas应助鲤鱼行云采纳,获得10
7秒前
小磊子完成签到,获得积分10
7秒前
小小旭呀发布了新的文献求助10
7秒前
zhangfan410发布了新的文献求助10
9秒前
SJW--666完成签到,获得积分10
9秒前
lisiwen818发布了新的文献求助10
9秒前
10秒前
日天的马铃薯完成签到,获得积分10
11秒前
qcarol发布了新的文献求助10
13秒前
CY发布了新的文献求助20
13秒前
孤独代亦完成签到,获得积分10
15秒前
xu完成签到,获得积分10
15秒前
15秒前
77完成签到,获得积分10
16秒前
传奇3应助蒙开心采纳,获得10
16秒前
Tao应助南瓜气气采纳,获得10
17秒前
小马甲应助殷权威采纳,获得10
17秒前
17秒前
18秒前
AbA完成签到,获得积分10
18秒前
丘比特应助阿义采纳,获得10
19秒前
20秒前
123566完成签到,获得积分10
20秒前
20秒前
高分求助中
请在求助之前详细阅读求助说明!!!! 20000
Specific features of molecular motion and properties of thin films and surface layers in amorphous polymers in a glassy state 2000
One Man Talking: Selected Essays of Shao Xunmei, 1929–1939 1000
The Three Stars Each: The Astrolabes and Related Texts 900
Yuwu Song, Biographical Dictionary of the People's Republic of China 800
Multifunctional Agriculture, A New Paradigm for European Agriculture and Rural Development 600
Bernd Ziesemer - Maos deutscher Topagent: Wie China die Bundesrepublik eroberte 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 有机化学 工程类 生物化学 纳米技术 物理 内科学 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 电极 光电子学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 2479330
求助须知:如何正确求助?哪些是违规求助? 2141878
关于积分的说明 5461027
捐赠科研通 1864989
什么是DOI,文献DOI怎么找? 927096
版权声明 562922
科研通“疑难数据库(出版商)”最低求助积分说明 496062