Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dictionary Based Blocking - tracking and blocking #3221

Open
Athanasius opened this issue Sep 10, 2024 · 3 comments
Open

Dictionary Based Blocking - tracking and blocking #3221

Athanasius opened this issue Sep 10, 2024 · 3 comments

Comments

@Athanasius
Copy link

What would you like to be added?

/kind feature

I've just skim-read through https://www.flux.utah.edu/paper/singh-nsdi24 (no pay wall, click for the PDF) and it seems like something that would be useful to implement as part of crowdsec.

Why is this needed?

Given the claimed better blocking and lower false positive rates claimed, versus fail2ban, this would probably also improve crowdsec.

Obviously the paper is specifically about SSH, but the general technique should be applicable to any other scenarios where there's source IPs and target usernames (or other unique data being as part of an attempt).

Copy link

@Athanasius: Thanks for opening an issue, it is currently awaiting triage.

In the meantime, you can:

  1. Check Crowdsec Documentation to see if your issue can be self resolved.
  2. You can also join our Discord.
  3. Check Releases to make sure your agent is on the latest version.
Details

I am a bot created to help the crowdsecurity developers manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the BirthdayResearch/oss-governance-bot repository.

Copy link

@Athanasius: There are no 'kind' label on this issue. You need a 'kind' label to start the triage process.

  • /kind feature
  • /kind enhancement
  • /kind refactoring
  • /kind bug
  • /kind packaging
Details

I am a bot created to help the crowdsecurity developers manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the BirthdayResearch/oss-governance-bot repository.

@Athanasius
Copy link
Author

Athanasius commented Sep 10, 2024

/kind feature

Why did having that in the initial issue fail ?

@Athanasius Athanasius changed the title Dictionary Based Attacks tracking and blocking Dictionary Based Blocking - tracking and blocking Sep 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant