Active and Passive Collection of SSH key material for cyber threat intelligence

Alexandre Dulaunoy, Jean-Louis Huynen, Aurelien Thirion

This paper describes a system for storing historical forensic artefacts collected from SSH connections. This system exposes a REST API in a similar fashion as passive DNS databases, malware hash registries, and SSL notaries with the goal of supporting incident investigations and monitoring of infrastructure.

Knowledge Graph

arrow_drop_up

Comments

Sign up or login to leave a comment