Method, device, equipment and medium for detecting brute force cracking of ssh service in container

CN115827153BActive Publication Date: 2026-09-29JINAN INSPUR DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211390133.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-08
Publication Date
2026-09-29
Estimated Expiration
2042-11-08

AI Technical Summary

Technical Problem

但是直接安装fail2ban,没有使用容器的主机一样配置时,发现并不会生效

Benefits of technology

[0037]本发明具有以下有益技术效果:本发明实施例提供的容器内SSH服务的暴力破解检测的方法,通过获取容器ID列表信息和容器端口信息,并为每个容器设定暴力破解检测规则;为主机中的每个容器创建可插拔式认证pam模块;响应于主机容器的端口被访问,基于端口信息选择相应的pam模块进行认证登陆,并经由认证pam模块记录登陆事件;基于容器的暴力破解检测规则和登陆事件确定容器是否遭到暴力破解入侵的技术方案,能够在不创建特权容器的前提下,不依赖系统rsyslog服务,利用容器本身的端口映射机制和linux系统自身的pam可插拔式认证模块实现同时对宿主机内多个容器的SSH服务暴力破解的检测。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115827153B_ABST
    Figure CN115827153B_ABST
Patent Text Reader

Abstract

The application provides a method, device and equipment for detecting brute force cracking of SSH service in a container and a readable medium, the method comprising: obtaining container ID list information and container port information, and setting a brute force cracking detection rule for each container; creating a pluggable authentication pam module for each container in a host; in response to a port of a host container being accessed, selecting a corresponding pam module based on the port information to perform authentication login, and recording a login event via the authentication pam module; and determining whether the container is subjected to brute force cracking intrusion based on the brute force cracking detection rule of the container and the login event. By using the scheme of the application, the SSH service brute force cracking of multiple containers in a host can be detected simultaneously without creating a privileged container and without relying on a system rsyslog service, by using a port mapping mechanism of the container itself and a pam pluggable authentication module of a linux system itself.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computers, and more specifically to a method, apparatus, device, and readable medium for brute-force detection of SSH services within a container. Background Technology

[0002] fail2ban is a utility software for Linux systems that monitors system logs and then matches error messages in the logs (using regular expressions) to execute corresponding blocking actions. It supports a large number of services, such as sshd, apache, qmail, proftpd, sasl, etc. fail2ban's implementation mechanism is a log IP filter. Based on different rules, it identifies "misbehaving" IPs from the logs. Once these IPs send requests that violate the rules and reach a threshold, they are directly blocked in iptables. The duration of the block can be set to avoid excessive harm from false positives. The most important aspect of using fail2ban is how to formulate effective rules based on the logs. After formulating the rules, it is necessary to test whether the rules are effective and truly achieve their intended purpose.

[0003] Docker is an open-source application container engine that allows developers to package their applications and dependencies into a portable container in a unified way, and then deploy it to any server with the Docker engine installed (including popular Linux and Windows machines), thus achieving virtualization. After enabling SSH (Secure Shell, a security protocol built on the application layer) service in a Docker container, fail2ban can be used for brute-force attacks. However, directly installing fail2ban and configuring it the same as on the host machine without using the container shows that it doesn't work. This is because while the SSH service is enabled when using the Docker container, rsyslog is not enabled within the container, so the ` / var / log / auth.log` log file that fail2ban depends on cannot be generated. In other words, fail2ban's use strongly depends on the rsyslog service; however, without privileged permissions, the service cannot be started and features like iptables cannot be used. If privileges are granted to the container, the container user will have root user privileges on the host machine, posing a significant security risk. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a method, apparatus, device, and readable medium for brute-force detection of SSH services within containers. By using the technical solution of this invention, it is possible to detect brute-force attacks on SSH services of multiple containers within the host machine simultaneously without creating privileged containers or relying on the system rsyslog service, by utilizing the container's own port mapping mechanism and the Linux system's own PAM pluggable authentication module.

[0005] To achieve the above objectives, one aspect of the present invention provides a method for brute-force detection of SSH services within a container, comprising the following steps:

[0006] Obtain a list of container IDs and container port information, and set brute-force detection rules for each container;

[0007] Create a pluggable authentication PAM module for each container in the host;

[0008] In response to the access to the host container's port, the appropriate PAM module is selected based on the port information for authentication login, and the login event is recorded by the authentication PAM module.

[0009] Container-based brute-force attack detection rules and login events determine whether a container has been subjected to brute-force intrusion.

[0010] According to one embodiment of the present invention, obtaining container ID list information and container port information, and setting brute-force detection rules for each container includes:

[0011] Get the list of container IDs and the port information for each container. The port information is the port on the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to get the container ID of docker port.

[0012] Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

[0013] According to one embodiment of the present invention, determining whether a container has been subjected to brute-force attack based on container brute-force detection rules and login events includes:

[0014] Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event;

[0015] Count whether the number of failed login attempts within a preset time period reaches a threshold;

[0016] If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

[0017] According to one embodiment of the present invention, it further includes:

[0018] In response to the determination that the container has been subjected to brute-force attack, the IP address that logs into the container port is blocked, and the corresponding alarm information is sent.

[0019] Another aspect of the present invention provides an apparatus for brute-force detection of SSH services within a container, the apparatus comprising:

[0020] The module is configured to retrieve a list of container IDs and container port information, and to set brute-force detection rules for each container.

[0021] Create a module, configure the module to create a pluggable authentication PAM module for each container in the host;

[0022] The logging module is configured to respond to access to the host container's port, select the appropriate PAM module for authentication login based on the port information, and record the login event via the authentication PAM module.

[0023] The module is configured to use container-based brute-force attack detection rules and login events to determine whether a container has been subjected to brute-force intrusion.

[0024] According to one embodiment of the present invention, the acquisition module is further configured to:

[0025] Get the list of container IDs and the port information for each container. The port information is the port on the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to get the container ID of docker port.

[0026] Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

[0027] According to one embodiment of the present invention, the determining module is further configured to:

[0028] Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event;

[0029] Count whether the number of failed login attempts within a preset time period reaches a threshold;

[0030] If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

[0031] According to one embodiment of the present invention, an alarm module is further included, the alarm module being configured as follows:

[0032] In response to the determination that the container has been subjected to brute-force attack, the IP address that logs into the container port is blocked, and the corresponding alarm information is sent.

[0033] Another aspect of the embodiments of the present invention also provides a computer device, the computer device comprising:

[0034] At least one processor; and

[0035] The memory stores computer instructions that can be executed by a processor, which, when executed by the processor, implement the steps of any of the methods described above.

[0036] In another aspect, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the above methods.

[0037] The present invention has the following beneficial technical effects: The method for brute-force attack detection of SSH services within containers provided in the embodiments of the present invention obtains container ID list information and container port information, and sets brute-force attack detection rules for each container; creates a pluggable authentication PAM module for each container in the host; responds to the access of the host container's port, selects the corresponding PAM module for authentication login based on the port information, and records the login event through the authentication PAM module; the technical solution for determining whether a container has been subjected to brute-force attack based on the container's brute-force attack detection rules and login events can simultaneously detect brute-force attacks on SSH services of multiple containers in the host machine without creating privileged containers or relying on the system's rsyslog service, by utilizing the container's own port mapping mechanism and the Linux system's own pluggable PAM authentication module. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other embodiments can be obtained based on these drawings without creative effort.

[0039] Figure 1 A schematic flowchart illustrating a method for brute-force detection of SSH services within a container according to an embodiment of the present invention;

[0040] Figure 2 This is a schematic diagram of a brute-force attack detection system for SSH services within a container according to an embodiment of the present invention.

[0041] Figure 3This is a schematic diagram of the communication of a brute-force attack detection system for an SSH service within a container according to an embodiment of the present invention;

[0042] Figure 4 A schematic diagram of an apparatus for brute-force detection of SSH services within a container according to an embodiment of the present invention;

[0043] Figure 5 This is a schematic diagram of a computer device according to an embodiment of the present invention;

[0044] Figure 6 This is a schematic diagram of a computer-readable storage medium according to an embodiment of the present invention. Detailed Implementation

[0045] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be further described in detail below with reference to specific examples and the accompanying drawings.

[0046] Based on the above objectives, a first aspect of the embodiments of the present invention provides an embodiment of a method for brute-force detection of SSH services within a container. Figure 1 The diagram shown is a schematic flowchart of the method.

[0047] like Figure 1 As shown, the method may include the following steps:

[0048] S1 retrieves a list of container IDs and container port information, and sets brute-force attack detection rules for each container. The port information is obtained by filtering the SSH service's default port 22 from the results of the `docker port container ID` command, mapping it to the host port. Then, based on the container's attributes and requirements, brute-force attack detection rules are set for each container in the container ID list. These rules are based on a threshold number of failed login attempts within a preset time period. For example, a detection duration of 1 minute and a threshold of 10 attempts would be considered a brute-force attack if SSH login attempts fail 10 times within 1 minute. Multiple containers can be configured with the same rules or different rules.

[0049] S2 creates a pluggable authentication PAM module for each container in the host.

[0050] S3 responds to access to a host container's port by selecting the appropriate PAM module for authentication based on the port information and recording the login event via the authentication PAM module. A pluggable authentication PAM module is created for each container, and different PAM modules are used during host login authentication depending on the accessed port. For example, if container A maps port 4321 and its pluggable authentication module is PAM-A, when port 4321 on the host machine is accessed, the PAM-A module is invoked to record the login event on port 4321, including the login time, logged-in user, remote IP address, and whether the login was successful.

[0051] S4 uses container-based brute-force attack detection rules and login events to determine if a container has been subjected to a brute-force attack. It counts the number of failed login attempts and the times recorded in login events for the container IDs. It then checks if the number of failed login attempts within a preset time period reaches a threshold. If the threshold is reached, the container is confirmed to have been subjected to a brute-force attack. If a brute-force attack is confirmed, the IP address of the login port to the container is blocked, and corresponding alert information is sent.

[0052] Can be used as Figure 2 The system shown implements the method of this invention. The system includes a brute-force attack detection agent deployed within a container, a brute-force attack detection management terminal deployed on the host machine, a container cluster management system, and the host machine. One or more Docker containers are deployed on the host machine, each containing a Docker daemon and a containerized Docker application (web application, database application, etc.). The brute-force attack detection management terminal communicates with the container cluster management system. It can obtain container ID list information and container port information from the container cluster management system (the port information is the information of the default SSH service port 22 mapped to the host machine after filtering the results of the `docker port container ID` command). It supports configuring brute-force attack detection rules for different container ID lists, such as setting the detection duration and threshold. For example, if the detection duration is 1 minute and the threshold is 10 times, then 10 failed SSH login attempts within 1 minute are considered a brute-force attack. Multiple containers can be configured with the same rules or different rules. Figure 3 As shown, the brute-force attack detection management terminal communicates with the brute-force attack detection agent terminal, sending the configured rules and obtained ports to the agent terminal of the specific container. The sent message is in the form of:

[0053]

[0054]

[0055] The agent creates a pluggable authentication PAM module for each container and uses different PAM modules depending on the port accessed during host login authentication. For example, if container A maps port 4321 and the pluggable authentication module is PAM-A, when port 4321 on the host is accessed, the PAM-A module is called. The PAM-A module records the login event on port 4321, uploading information such as login time, login user, remote IP address, and whether the login was successful to the brute-force attack detection management end. After receiving the login event, the brute-force attack detection management end filters out login failure events and performs calculations. If the events meet the preset rules, it is considered that the SSH service in the container has been brute-force attacked.

[0056] By using the technical solution of this invention, it is possible to detect brute-force attacks on the SSH services of multiple containers within the host machine simultaneously, without creating privileged containers or relying on the system's rsyslog service, by utilizing the container's own port mapping mechanism and the Linux system's own PAM pluggable authentication module.

[0057] In a preferred embodiment of the present invention, obtaining container ID list information and container port information, and setting brute-force detection rules for each container includes:

[0058] Get the list of container IDs and the port information for each container. The port information is the port on the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to get the container ID of docker port.

[0059] Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

[0060] In a preferred embodiment of the present invention, determining whether a container has been subjected to brute-force attack based on container brute-force detection rules and login events includes:

[0061] Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event;

[0062] Count whether the number of failed login attempts within a preset time period reaches a threshold;

[0063] If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

[0064] In a preferred embodiment of the present invention, it further includes:

[0065] In response to the determination that the container has been subjected to brute-force attack, the IP address that logs into the container port is blocked, and the corresponding alarm information is sent.

[0066] By using the technical solution of this invention, it is possible to detect brute-force attacks on the SSH services of multiple containers within the host machine simultaneously, without creating privileged containers or relying on the system's rsyslog service, by utilizing the container's own port mapping mechanism and the Linux system's own PAM pluggable authentication module.

[0067] It should be noted that those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc. The embodiments of the computer program described above can achieve the same or similar effects as any of the corresponding foregoing method embodiments.

[0068] Furthermore, the method disclosed in the embodiments of the present invention can also be implemented as a computer program executed by a CPU, which may be stored in a computer-readable storage medium. When the computer program is executed by the CPU, it performs the functions defined in the method disclosed in the embodiments of the present invention.

[0069] Based on the above objectives, a second aspect of the embodiments of the present invention provides an apparatus for brute-force detection of SSH services within a container, such as... Figure 4 As shown, the device 200 includes:

[0070] The module is configured to retrieve a list of container IDs and container port information, and to set brute-force detection rules for each container.

[0071] Create a module, configure the module to create a pluggable authentication PAM module for each container in the host;

[0072] The logging module is configured to respond to access to the host container's port, select the appropriate PAM module for authentication login based on the port information, and record the login event via the authentication PAM module.

[0073] The module is configured to use container-based brute-force attack detection rules and login events to determine whether a container has been subjected to brute-force intrusion.

[0074] In a preferred embodiment of the present invention, the acquisition module is further configured as follows:

[0075] Get the list of container IDs and the port information for each container. The port information is the port on the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to get the container ID of docker port.

[0076] Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

[0077] In a preferred embodiment of the present invention, the determining module is further configured as follows:

[0078] Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event;

[0079] Count whether the number of failed login attempts within a preset time period reaches a threshold;

[0080] If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

[0081] In a preferred embodiment of the present invention, an alarm module is further included, and the alarm module is configured as follows:

[0082] In response to the determination that the container has been subjected to brute-force attack, the IP address that logs into the container port is blocked, and the corresponding alarm information is sent.

[0083] In view of the above objectives, a third aspect of the present invention provides a computer device. Figure 5 The diagram shown is a schematic representation of an embodiment of the computer device provided by the present invention. Figure 5 As shown, embodiments of the present invention include the following apparatus: at least one processor 21; and a memory 22 storing computer instructions 23 executable on the processor, which, when executed by the processor, implement the following method:

[0084] Obtain a list of container IDs and container port information, and set brute-force detection rules for each container;

[0085] Create a pluggable authentication PAM module for each container in the host;

[0086] In response to the access to the host container's port, the appropriate PAM module is selected based on the port information for authentication login, and the login event is recorded by the authentication PAM module.

[0087] Container-based brute-force attack detection rules and login events determine whether a container has been subjected to brute-force intrusion.

[0088] In a preferred embodiment of the present invention, obtaining container ID list information and container port information, and setting brute-force detection rules for each container includes:

[0089] Get the list of container IDs and the port information for each container. The port information is the port on the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to get the container ID of docker port.

[0090] Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

[0091] In a preferred embodiment of the present invention, determining whether a container has been subjected to brute-force attack based on container brute-force detection rules and login events includes:

[0092] Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event;

[0093] Count whether the number of failed login attempts within a preset time period reaches a threshold;

[0094] If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

[0095] In a preferred embodiment of the present invention, it further includes:

[0096] In response to the determination that the container has been subjected to brute-force attack, the IP address that logs into the container port is blocked, and the corresponding alarm information is sent.

[0097] In view of the above objectives, a fourth aspect of the present invention provides a computer-readable storage medium. Figure 6 The diagram shown is a schematic representation of an embodiment of the computer-readable storage medium provided by the present invention. Figure 6 As shown, computer-readable storage medium 31 stores a computer program 32 that, when executed by a processor, performs the following methods:

[0098] Obtain a list of container IDs and container port information, and set brute-force detection rules for each container;

[0099] Create a pluggable authentication PAM module for each container in the host;

[0100] In response to the access to the host container's port, the appropriate PAM module is selected based on the port information for authentication login, and the login event is recorded by the authentication PAM module.

[0101] Container-based brute-force attack detection rules and login events determine whether a container has been subjected to brute-force intrusion.

[0102] In a preferred embodiment of the present invention, obtaining container ID list information and container port information, and setting brute-force detection rules for each container includes:

[0103] Get the list of container IDs and the port information for each container. The port information is the port on the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to get the container ID of docker port.

[0104] Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

[0105] In a preferred embodiment of the present invention, determining whether a container has been subjected to brute-force attack based on container brute-force detection rules and login events includes:

[0106] Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event;

[0107] Count whether the number of failed login attempts within a preset time period reaches a threshold;

[0108] If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

[0109] In a preferred embodiment of the present invention, it further includes:

[0110] In response to the determination that the container has been subjected to brute-force attack, the IP address that logs into the container port is blocked, and the corresponding alarm information is sent.

[0111] Furthermore, the method disclosed in the embodiments of the present invention can also be implemented as a computer program executed by a processor, which may be stored in a computer-readable storage medium. When the computer program is executed by the processor, it performs the functions defined in the method disclosed in the embodiments of the present invention.

[0112] Furthermore, the above-described method steps and system units can also be implemented using a controller and a computer-readable storage medium for storing a computer program that enables the controller to perform the functions of the above-described steps or units.

[0113] Those skilled in the art will also understand that the various exemplary logic blocks, modules, circuits, and algorithm steps described in conjunction with the disclosure herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, the functionality of various illustrative components, blocks, modules, circuits, and steps has been generally described. Whether this functionality is implemented as software or as hardware depends on the specific application and the design constraints imposed on the system as a whole. Those skilled in the art can implement the functionality in various ways for each specific application, but such implementation decisions should not be construed as departing from the scope of the embodiments disclosed herein.

[0114] In one or more exemplary designs, functionality may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, functionality may be stored as one or more instructions or code on or transmitted via a computer-readable medium. Computer-readable media include computer storage media and communication media, including any medium that facilitates the transfer of a computer program from one location to another. Storage media may be any available medium accessible to a general-purpose or special-purpose computer. By way of example, and not limitation, computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disc storage devices, disk storage devices or other magnetic storage devices, or any other medium that may be used to carry or store the required program code in the form of instructions or data structures and is accessible to a general-purpose or special-purpose computer or a general-purpose or special-purpose processor. Furthermore, any connection may be appropriately referred to as computer-readable media. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the aforementioned coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are all included in the definition of media. As used herein, disks and optical discs include compact discs (CDs), laser discs, optical discs, digital multifunction discs (DVDs), floppy disks, and Blu-ray discs, wherein disks typically reproduce data magnetically, while optical discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0115] The above are exemplary embodiments disclosed in this invention. However, it should be noted that various changes and modifications can be made without departing from the scope of the embodiments of this invention as defined by the claims. The functions, steps, and / or actions of the methods according to the disclosed embodiments described herein do not need to be performed in any particular order. Furthermore, although the elements disclosed in the embodiments of this invention may be described or claimed individually, they may be understood as multiple unless explicitly limited to a singular number.

[0116] It should be understood that, as used herein, the singular form “a” is intended to include the plural form as well, unless the context clearly supports an exception. It should also be understood that, as used herein, “and / or” refers to any and all possible combinations of one or more of the associated listed items.

[0117] The embodiment numbers disclosed in the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0118] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0119] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention (including the claims) is limited to these examples. Within the framework of the invention, technical features of the above embodiments or different embodiments can be combined, and many other variations of different aspects of the invention exist, which are not provided in the details for the sake of brevity. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the invention should be included within the protection scope of the invention.

Claims

1. A method for brute force detection of SSH services within a container, the method comprising: Includes the following steps: Obtain a list of container IDs and container port information, and set brute-force detection rules for each container; Create a pluggable authentication PAM module for each container in the host; In response to the access to the host container's port, the appropriate PAM module is selected based on the port information for authentication login, and the login event is recorded by the authentication PAM module. Determine whether a container has been subjected to brute-force attack based on container-based brute-force attack detection rules and login events; Obtain a list of container IDs and container port information, and set brute-force detection rules for each container, including: Obtain a list of container IDs and port information for each container. The port information is the port information of the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to obtain the container ID of the docker port. Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

2. The method of claim 1, wherein, Determining whether a container has been subjected to a brute-force attack based on container-based brute-force detection rules and login events includes: Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event; Count whether the number of failed login attempts within a preset time period reaches a threshold; If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

3. The method of claim 1, wherein, Also includes: In response to the determination that the container has been subjected to brute-force attack, the IP address that logs into the container port is blocked, and the corresponding alarm information is sent.

4. An apparatus for brute force detection of SSH services within a container, the apparatus comprising: The device includes: The acquisition module is configured to acquire a list of container IDs and container port information, and to set brute-force detection rules for each container. Create a module, which is configured to create a pluggable authentication PAM module for each container in the host. A recording module is configured to respond to access to a port of the host container, select the appropriate PAM module for authentication login based on the port information, and record the login event via the authentication PAM module. The determination module is configured to determine whether a container has been subjected to brute-force intrusion based on container brute-force detection rules and login events; The acquisition module is further configured to: Obtain a list of container IDs and port information for each container. The port information is the port information of the host that the default port 22 of the SSH service is mapped to after filtering the results of the command to obtain the container ID of the docker port. Based on the container's attributes and requirements, brute-force detection rules are set for the containers in the container ID list. The brute-force detection rule is that the number of failed login attempts reaches a threshold within a preset time period.

5. The apparatus of claim 4, wherein, The determining module is further configured to: Count the number of failed login attempts and the time corresponding to the container ID recorded in the login event; Count whether the number of failed login attempts within a preset time period reaches a threshold; If the number of failed login attempts reaches a threshold within a preset time period, it is determined that the container has been subjected to brute-force attack.

6. The apparatus of claim 4, wherein, It also includes an alarm module, which is configured as follows: In response to determining that the container is subjected to a violent cracking intrusion, an IP address landing on a container port is shielded, and corresponding alarm information is sent.

7. A computer device, characterized by The method comprises: at least one processor; and a memory storing computer instructions executable on the processor, the instructions being executed by the processor to implement the steps of the method of any one of claims 1-3.

8. A computer-readable storage medium storing a computer program, the computer-readable storage medium comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 7. The computer program, when executed by a processor, implements the steps of the method of any one of claims 1-3.

Citation Information

Patent Citations

  • Brute force attack prevention method, device and system

    CN106161395A

  • Secure authentication and network management system for wireless LAN applications

    WO2005089120A2