SSH Authentication Log Monitoring
Wazuh continuously monitors Ubuntu SSH authentication logs.
Provide centralized visibility into SSH authentication activity.
Organizations commonly use OpenSSH to provide secure remote administration of Linux servers. Because SSH is frequently exposed to administrators and operational teams, attackers may attempt repeated authentication attempts against SSH accounts to obtain unauthorized access.
A Brute-Force Attack attempts to gain access by repeatedly submitting authentication attempts until valid credentials are discovered. If repeated failed authentication activity is not monitored, an attacker may continue attempting access without being detected.
In this use case, an enterprise-like Linux SSH server is deployed on Ubuntu inside an isolated laboratory using VirtualBox. Kali Linux is used as the controlled security-testing system.
A controlled SSH brute-force simulation is performed against the authorized Ubuntu server using a dedicated laboratory test account. Only synthetic credentials are used, and no real account credentials are involved.
Wazuh is deployed as the primary SOC monitoring and detection platform. The Wazuh agent collects SSH authentication logs from the Ubuntu server and analyzes repeated authentication failures.
OpenSearch is used as the centralized SOC investigation and visualization platform. Detected authentication events are correlated to identify suspicious repeated login activity.
When the configured brute-force detection condition is satisfied, Wazuh generates a security alert and the configured response mechanism can temporarily restrict the identified laboratory source.
The suspicious activity is then investigated, correlated, contained, and validated. Legitimate SSH access is tested afterward to ensure that authorized administration remains available.
The complete SOC workflow is: SSH Server → Authentication Activity → Repeated Login Failures → Log Collection → Event Correlation → Brute-Force Detection → Security Alert → Investigation → Automated Response → Containment → Validation
OpenSSH provides secure remote access to Linux systems through the SSH protocol.
SSH authentication events generate security telemetry that can be monitored by a SOC to identify suspicious login behavior.
An attacker may repeatedly attempt authentication against an SSH service using different passwords or authentication combinations. A single failed login attempt is normally not sufficient to indicate an attack because users can make legitimate mistakes. However, a high number of failed authentication attempts from the same source or against multiple accounts within a short period can indicate brute-force behavior.
The security problem is therefore:
The controlled attack scenario simulates an SSH brute-force attack against the authorized Ubuntu Linux server. The purpose is to reproduce the authentication pattern associated with brute-force activity and determine whether the SOC monitoring system can detect the behavior.
The primary security concept is SOC-based authentication monitoring and behavioral detection.
The objective is to continuously monitor SSH authentication activity, identify abnormal failed-login patterns, generate security alerts, investigate the event, and initiate an appropriate response.
The secure processing flow is:
Wazuh continuously monitors Ubuntu SSH authentication logs.
Provide centralized visibility into SSH authentication activity.
Repeated failed SSH authentication events are identified.
Detect suspicious login activity.
Multiple authentication failures are correlated using source, username, destination, and time.
Identify behavioral patterns rather than isolated events.
Wazuh applies configured detection logic to repeated SSH authentication failures.
Identify potential brute-force attacks.
A security alert is generated when the configured brute-force condition is satisfied.
Provide immediate SOC visibility.
OpenSearch provides centralized access to authentication events and alerts.
Allow analysts to investigate the incident timeline.
The source system associated with repeated authentication failures is identified.
Support investigation and containment decisions.
The configured response mechanism can temporarily restrict the identified laboratory source.
Understand how the brute-force activity developed.
SSH activity is monitored after containment.
Verify that suspicious authentication activity has stopped while legitimate access remains functional.
Wazuh is the primary SOC platform because it provides endpoint monitoring, log collection, security-rule processing, alert generation, and automated response capabilities.
OpenSearch is used as the centralized investigation and visualization platform.
OpenSSH provides the remote-access service being monitored.
Hydra is used only within the isolated laboratory to generate controlled repeated SSH authentication attempts.
Ubuntu authentication telemetry is collected from the appropriate Linux authentication logging mechanism.
Ubuntu provides the controlled SSH server environment.
Kali Linux provides the controlled security-testing environment.
VirtualBox provides the isolated laboratory infrastructure.