Re: SSH connections

From: Jani Mikkonen (jani_at_mikkonen.org)
Date: 08/25/05


Date: Thu, 25 Aug 2005 13:14:35 +0300

Fred wrote:
> I'm looking at thwarting some ssh probes by changing the port number
> and customizing the sshd_config file. I'm curious if these probes have
> an adverse affect on the performance of the server or are the
> connection attempts inexpensive resource-wise? Are there any ways to
> measure the impact of these connection attempts?

So you want to have statictics on how much resources these connection
attemps use ? Without more information is quite impossible to give you
any kind of "good answer". But i'll give you few questions..

Basicly when someone probes your ssh, its takes cpu cycles off your
server and network bandwidth, few seeks to "user database" what ever
that maybe is depending on your configuration and writes few lines of
text into logging facility..

Basicly, the probes are very inexpensive resources wise since they
usually happen in serial (atleast the scanners i've seen never launch
parallel probes but ofcourse this is just matter of time to change)

If you want to measure the resources, you need to indentify those first.
 Just plain network traffic ? Cpu time ? Disk io and space usage caused
by probes ? Im quite sure everything can be measured..



Relevant Pages

  • Re: When not to log
    ... >> never get any probes during the 5-20 minutes of collecting mail and news, ... Connection from unprivileged to my 80? ... Is it impossible for a compromised web server to pass client IPs ...
    (comp.os.linux.security)
  • Re: Class Inherits
    ... The data I wanna draw is a number of probes that are connected to the ... a set of routers that are connected to a set of servers. ... My plan is to read information from a database(ADODB Connection). ...
    (microsoft.public.visio.developer.vba)
  • Re: Telnet connections - the connection drops, the process doesnt die!
    ... that VMS doesn't terminate the process in the case of a telnet session ... so that your system will send out keepalive probes. ... keepalive probes repeatedly go unanswered the connection should be ...
    (comp.os.vms)
  • Re: "growler"
    ... The probes and light bulb are wired across the 120V line -- makes no sense ... have no connection to the line. ... I suspect there was little consideration for ...
    (sci.electronics.repair)
  • Re: Massive probes on port 4662 - could need som advice.
    ... not going to be due to the incoming connection attempt as a whole, ... Does ZoneAlarm drop packets completely, or does it send back a TCP+RST to ... My problem is that I get 5-10 probes each minute on port ...
    (comp.security.firewalls)