Intelligent SSH Intrusion Detection for SMEs
Every 39 seconds, a server somewhere is being attacked. β Cukier, M. (2007). University of Maryland Study on Computer Hacking
Verizon DBIR, 2023
Ponemon Institute, 2022
IBM Cost of Data Breach Report, 2023
Rapid7 Research, 2022
Kaspersky APT Report, 2023
Akamai State of Internet, 2023
OECD SME Policy Index, 2021
APEC Cybersecurity Report, 2022
Research Questions & Objectives
Existing Solutions & Research Gap
| Feature | Fail2ban | OSSEC | CrowdSec | Splunk | SSH Guardian |
|---|---|---|---|---|---|
| ML Detection | β | β | β | β | β |
| Threat Intel | β | β | β | β | β |
| Dashboard | β | β | β | β | β |
| SME-Friendly | β | β | β | β | β |
| Free | β | β | β | β | β |
| Setup Time | 5 min | Hours | 30 min | Days | 10 min |
Design Science Research Approach
Training & Evaluation
Dashboard & Features
Performance Evaluation
| Metric | Fail2ban | SSH Guardian | Improvement |
|---|---|---|---|
| Accuracy | 78.0% | 96.91% | +18.91% |
| False Positives | 12.3% | 3.1% | -9.2% |
| Detection Latency | Threshold only | Real-time ML | Faster |
| Threat Intel | β | 4 APIs | New |
| Dashboard | β | Full UI | New |
| Behavioral Analysis | β | 50 features | New |
Roadmap & Open Source
Summary & Contributions
Questions & Discussion