Location Research Breakthrough Possible @S-Logix pro@slogix.in

Monitoring Brute-Force SSH Attacks Against Linux Servers Through Authentication Log Analysis and Automated Security Response

Description

Organizations commonly use OpenSSH to provide secure remote administration of Linux servers. Because SSH is frequently exposed to administrators and operational teams, attackers may attempt repeated authentication attempts against SSH accounts to obtain unauthorized access.

A Brute-Force Attack attempts to gain access by repeatedly submitting authentication attempts until valid credentials are discovered. If repeated failed authentication activity is not monitored, an attacker may continue attempting access without being detected.

In this use case, an enterprise-like Linux SSH server is deployed on Ubuntu inside an isolated laboratory using VirtualBox. Kali Linux is used as the controlled security-testing system.

A controlled SSH brute-force simulation is performed against the authorized Ubuntu server using a dedicated laboratory test account. Only synthetic credentials are used, and no real account credentials are involved.

Wazuh is deployed as the primary SOC monitoring and detection platform. The Wazuh agent collects SSH authentication logs from the Ubuntu server and analyzes repeated authentication failures.

OpenSearch is used as the centralized SOC investigation and visualization platform. Detected authentication events are correlated to identify suspicious repeated login activity.

When the configured brute-force detection condition is satisfied, Wazuh generates a security alert and the configured response mechanism can temporarily restrict the identified laboratory source.

The suspicious activity is then investigated, correlated, contained, and validated. Legitimate SSH access is tested afterward to ensure that authorized administration remains available.

The complete SOC workflow is: SSH Server → Authentication Activity → Repeated Login Failures → Log Collection → Event Correlation → Brute-Force Detection → Security Alert → Investigation → Automated Response → Containment → Validation

Existing Security Problem

Application: OpenSSH

OpenSSH provides secure remote access to Linux systems through the SSH protocol.

SSH authentication events generate security telemetry that can be monitored by a SOC to identify suspicious login behavior.

Existing Problem:

An attacker may repeatedly attempt authentication against an SSH service using different passwords or authentication combinations. A single failed login attempt is normally not sufficient to indicate an attack because users can make legitimate mistakes. However, a high number of failed authentication attempts from the same source or against multiple accounts within a short period can indicate brute-force behavior.

The security problem is therefore:

External Source → SSH Service → Repeated Authentication Attempts → Multiple Failed Logins → Suspicious Authentication Pattern → Potential Brute-Force Attack → Unauthorized Access Risk

Attack

Specific Attack: SSH Brute-Force Attack

The controlled attack scenario simulates an SSH brute-force attack against the authorized Ubuntu Linux server. The purpose is to reproduce the authentication pattern associated with brute-force activity and determine whether the SOC monitoring system can detect the behavior.

Attack Behavior:
Kali Linux Test System
→
SSH Connection Attempts
→
Repeated Authentication Failures
→
Ubuntu Authentication Logs
→
Wazuh Log Collection
→
Failed-Login Correlation
→
Brute-Force Detection
→
Security Alert
→
SOC Investigation
→
Automated Response
→
Source Restriction

Security Concept

SOC Authentication Monitoring:

The primary security concept is SOC-based authentication monitoring and behavioral detection.

The objective is to continuously monitor SSH authentication activity, identify abnormal failed-login patterns, generate security alerts, investigate the event, and initiate an appropriate response.

The secure processing flow is:

Authentication Events
→
Log Collection
→
Event Normalization
→
Authentication Correlation
→
Behavior Analysis
→
Brute-Force Detection
→
Security Alert
→
SOC Investigation
→
Automated Response
→
Containment
→
Validation

Defensive Mechanism

SSH Authentication Log Monitoring

Wazuh continuously monitors Ubuntu SSH authentication logs.

Purpose

Provide centralized visibility into SSH authentication activity.

Failed Authentication Detection

Repeated failed SSH authentication events are identified.

Purpose

Detect suspicious login activity.

Authentication Event Correlation

Multiple authentication failures are correlated using source, username, destination, and time.

Purpose

Identify behavioral patterns rather than isolated events.

Brute-Force Detection Rule

Wazuh applies configured detection logic to repeated SSH authentication failures.

Purpose

Identify potential brute-force attacks.

Security Alert Generation

A security alert is generated when the configured brute-force condition is satisfied.

Purpose

Provide immediate SOC visibility.

Centralized Investigation

OpenSearch provides centralized access to authentication events and alerts.

Purpose

Allow analysts to investigate the incident timeline.

Source Attribution

The source system associated with repeated authentication failures is identified.

Purpose

Support investigation and containment decisions.

Automated Source Restriction

The configured response mechanism can temporarily restrict the identified laboratory source.

Purpose

Understand how the brute-force activity developed.

Post-Containment Validation

SSH activity is monitored after containment.

Purpose

Verify that suspicious authentication activity has stopped while legitimate access remains functional.

Security Tools

Primary SOC Detection and Response Tool: Wazuh

Wazuh is the primary SOC platform because it provides endpoint monitoring, log collection, security-rule processing, alert generation, and automated response capabilities.

Purpose
  • Collect SSH authentication logs.
  • Monitor Linux security events.
  • Detect repeated authentication failures.
  • Generate security alerts.
  • Correlate authentication events.
  • Trigger configured response actions.
  • Support incident investigation.

SOC Investigation Platform: OpenSearch

OpenSearch is used as the centralized investigation and visualization platform.

Purpose
  • Centralize security events.
  • Search SSH authentication activity.
  • Investigate brute-force alerts.
  • Visualize authentication patterns.
  • Review event timelines.
  • Support SOC investigation.

SSH Service: OpenSSH

OpenSSH provides the remote-access service being monitored.

Purpose
  • Provide SSH connectivity.
  • Generate authentication events.
  • Represent the protected Linux service.
  • Validate legitimate and suspicious authentication behavior.

Attack Simulation Tool: Hydra

Hydra is used only within the isolated laboratory to generate controlled repeated SSH authentication attempts.

Purpose
  • Generate repeated authentication attempts.
  • Reproduce brute-force authentication behavior.
  • Validate Wazuh detection.
  • Test the SOC response workflow.

Linux Authentication Monitoring: systemd journal / Authentication Logs

Ubuntu authentication telemetry is collected from the appropriate Linux authentication logging mechanism.

Purpose
  • Record SSH authentication events.
  • Provide failed-login information.
  • Support event investigation.
  • Provide evidence for brute-force detection.

Target Platform: Ubuntu Linux

Ubuntu provides the controlled SSH server environment.

Purpose
  • Host OpenSSH.
  • Generate authentication telemetry.
  • Provide controlled test accounts.
  • Apply response actions.
  • Validate legitimate SSH access.

Security Testing Platform: Kali Linux

Kali Linux provides the controlled security-testing environment.

Purpose
  • Generate authorized SSH brute-force test activity.
  • Run Hydra.
  • Validate detection.
  • Test post-containment behavior.

Virtualization Platform: VirtualBox

VirtualBox provides the isolated laboratory infrastructure.

Purpose
  • Host Ubuntu.
  • Host Kali Linux.
  • Isolate the authentication-security assessment.
  • Prevent interaction with production systems.

Process

STEP 01

Step 1: Prepare the Isolated SOC Laboratory

  • Create an isolated cybersecurity laboratory using VirtualBox.
  • Configure Ubuntu as the target SSH server.
  • Configure Kali Linux as the security-testing system.
  • Establish controlled network connectivity.
  • Verify communication between the laboratory systems.
  • Ensure the environment is separated from production systems.
  • Confirm that only test accounts and synthetic credentials are used.
Tools: VirtualBox + Ubuntu + Kali Linux
STEP 02

Step 2: Deploy OpenSSH

  • Install OpenSSH Server on Ubuntu.
  • Start the SSH service.
  • Verify that SSH is operational.
  • Configure SSH to accept connections from the laboratory network.
  • Record the initial SSH configuration.
  • Verify that legitimate SSH connectivity works.
Tools: OpenSSH + Ubuntu
STEP 03

Step 3: Create Controlled SSH Test Accounts

  • Create a dedicated laboratory SSH test account.
  • Configure a synthetic test password.
  • Create an authorized administrative test account.
  • Assign appropriate permissions.
  • Verify legitimate authentication.
  • Ensure that no production credentials are used.
Tools: Ubuntu + OpenSSH
STEP 04

Step 4: Establish the Normal Authentication Baseline

  • Perform legitimate SSH authentication using the authorized test account.
  • Generate successful SSH authentication events.
  • Generate a small number of controlled failed authentication events.
  • Review the Ubuntu authentication logs.
  • Identify the normal authentication pattern.
  • Preserve the baseline for comparison.
Tools: OpenSSH + Ubuntu
STEP 05

Step 5: Deploy Wazuh Monitoring

  • Install the Wazuh agent on Ubuntu.
  • Register the agent with the Wazuh manager.
  • Verify agent communication.
  • Configure monitoring for SSH authentication logs.
  • Confirm that authentication events are being collected.
  • Verify that Wazuh receives the generated SSH events.
Tools: Wazuh + Ubuntu
STEP 06

Step 6: Configure SSH Brute-Force Detection

  • Review the SSH authentication events received by Wazuh.
  • Identify failed SSH authentication events.
  • Configure or validate the applicable Wazuh detection rules.
  • Define the required failure threshold.
  • Define the relevant time interval.
  • Configure an appropriate alert severity.
  • Test the detection logic with controlled authentication failures.
Tools: Wazuh
STEP 07

Step 7: Configure OpenSearch Investigation

  • Connect the security-event pipeline to OpenSearch.
  • Confirm that Wazuh security events are available.
  • Create searches for SSH authentication failures.
  • Create a view for repeated authentication activity.
  • Identify fields such as source address, username, timestamp, and authentication result.
  • Verify that the events can be investigated centrally.
Tools: OpenSearch + Wazuh
STEP 08

Step 8: Configure the Automated Response

  • Configure the response mechanism for the brute-force detection alert.
  • Define the appropriate laboratory containment action.
  • Configure temporary source restriction where required.
  • Ensure that the response applies only to the controlled laboratory source.
  • Test the response mechanism safely.
  • Verify that the response event is recorded.
Tools: Wazuh + Ubuntu
STEP 09

Step 9: Generate Controlled SSH Brute-Force Activity

  • Use Kali Linux as the authorized test system.
  • Target only the laboratory Ubuntu SSH server.
  • Use the dedicated laboratory test account.
  • Generate repeated controlled authentication attempts using Hydra.
  • Use only synthetic test credentials.
  • Stop the activity after sufficient authentication telemetry is generated.
Tools: Hydra + Kali Linux + OpenSSH
STEP 10

Step 10: Collect and Correlate Authentication Events

  • Allow Wazuh to collect the generated SSH events.
  • Identify repeated failed authentication attempts.
  • Correlate events using source address and timestamp.
  • Identify the targeted username.
  • Determine the number of failed attempts.
  • Compare the behavior against the normal authentication baseline.
Tools: Wazuh + Ubuntu
STEP 11

Step 11: Detect the Brute-Force Attack

  • Verify that the configured Wazuh rule identifies the repeated authentication failures.
  • Confirm that the failure threshold is reached.
  • Verify the associated source system.
  • Verify the targeted SSH account.
  • Confirm that Wazuh classifies the activity as suspicious.
  • Record the generated security alert.
Tools: Wazuh
STEP 12

Step 12: Investigate the Security Alert

  • Open the brute-force security alert.
  • Identify the Ubuntu SSH server.
  • Identify the source address.
  • Identify the targeted account.
  • Review the authentication timestamps.
  • Review the number and sequence of failures.
  • Compare the event against normal authentication behavior.
  • Determine whether the event represents the controlled brute-force scenario.
Tools: Wazuh + OpenSearch
STEP 13

Step 13: Reconstruct the Incident Timeline

  • Search OpenSearch for the affected source.
  • Review all related authentication events.
  • Identify the first failed attempt.
  • Identify subsequent repeated failures.
  • Identify the time interval between attempts.
  • Identify the alert-generation event.
  • Identify the response event.
  • Build the complete authentication timeline.
Tools: OpenSearch + Wazuh
STEP 14

Step 14: Trigger and Validate Automated Containment

  • Allow the configured Wazuh response to execute.
  • Apply the temporary source restriction.
  • Verify that subsequent authentication attempts from the restricted laboratory source are blocked.
  • Confirm that the containment action is recorded.
  • Review the resulting authentication logs.
  • Verify that the brute-force activity has stopped.
Tools: Wazuh + Ubuntu + OpenSSH
STEP 15

Step 15: Validate Legitimate SSH Access

  • Use the authorized laboratory administrator account.
  • Connect to the Ubuntu SSH server.
  • Perform legitimate SSH authentication.
  • Verify that authorized access succeeds.
  • Confirm that the response mechanism does not unnecessarily block legitimate administration.
  • Review the corresponding Wazuh events.
Tools: OpenSSH + Ubuntu + Wazuh
STEP 16

Step 16: Review the SOC Investigation Results

  • Review the complete brute-force alert in OpenSearch.
  • Review Wazuh detection details.
  • Review source attribution.
  • Review authentication-event sequence.
  • Review containment activity.
  • Confirm that the incident was detected and contained.
  • Record the final investigation result.
Tools: OpenSearch + Wazuh
STEP 17

Step 17: Restore the Laboratory Configuration

  • Remove the temporary source restriction after validation.
  • Restore the normal SSH testing configuration.
  • Verify that the laboratory test account remains available.
  • Confirm that legitimate SSH connectivity is restored.
  • Remove temporary testing artifacts.
  • Verify that the environment has returned to its normal laboratory state.
Tools: Ubuntu + OpenSSH + Wazuh
STEP 18

Step 18: Perform Final SOC Detection and Response Validation

  • Repeat the controlled SSH brute-force assessment.
  • Verify that authentication failures are collected.
  • Verify that Wazuh detects the repeated failed-login pattern.
  • Verify that the security alert is generated.
  • Verify that OpenSearch displays the related events.
  • Verify that the configured automated response is triggered.
  • Confirm that continued brute-force activity is restricted.
  • Confirm that legitimate SSH access remains functional.
  • Review the complete incident timeline.
  • Document the final SOC detection and response results.
Tools: Hydra + Wazuh + OpenSearch + OpenSSH + Ubuntu + Kali Linux

Outcome

  1. A controlled Ubuntu SSH environment is successfully deployed within an isolated SOC laboratory.
  2. Normal SSH authentication behavior is established and monitored, providing a baseline for distinguishing legitimate activity from suspicious authentication patterns.
  3. A controlled SSH brute-force attack is safely simulated using Hydra, generating repeated authentication failures against the dedicated laboratory account.
  4. Wazuh successfully collects and correlates SSH authentication events, providing centralized visibility into repeated failed-login activity.
  5. The configured Wazuh detection rule identifies the brute-force authentication pattern when the defined threshold is reached.
  6. A security alert is generated containing relevant authentication information, including the affected SSH server, source, account, timestamps, and repeated failures.
  7. OpenSearch provides centralized SOC investigation and incident-timeline reconstruction, allowing analysts to understand the sequence and characteristics of the brute-force activity.
  8. The configured automated response temporarily restricts the identified laboratory source, preventing continued brute-force authentication attempts.
  9. Legitimate SSH administration remains functional after containment, demonstrating that the SOC response can restrict suspicious activity without unnecessarily disrupting authorized access.
  10. The complete SSH brute-force detection, authentication-log monitoring, event correlation, security alerting, SOC investigation, incident-timeline reconstruction, automated containment, legitimate-access validation, recovery, and final detection-and-response validation workflow is successfully demonstrated.
Project 1 of 7
Next Project →