{"id":"https://openalex.org/W3045526966","doi":"https://doi.org/10.1109/icc40277.2020.9148912","title":"Measuring the Prevalence of the Password Authentication Vulnerability in SSH","display_name":"Measuring the Prevalence of the Password Authentication Vulnerability in SSH","publication_year":2020,"publication_date":"2020-06-01","ids":{"openalex":"https://openalex.org/W3045526966","doi":"https://doi.org/10.1109/icc40277.2020.9148912","mag":"3045526966"},"language":"en","primary_location":{"id":"doi:10.1109/icc40277.2020.9148912","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icc40277.2020.9148912","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICC 2020 - 2020 IEEE International Conference on Communications (ICC)","raw_type":"proceedings-article"},"type":"conference-paper","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5089460688","display_name":"Ron Andrews","orcid":null},"institutions":[{"id":"https://openalex.org/I146416000","display_name":"University of Kansas","ror":"https://ror.org/001tmjg57","country_code":"US","type":"education","lineage":["https://openalex.org/I146416000"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ron Andrews","raw_affiliation_strings":["EECS Department, ITTC University of Kansas, Lawrence, KS"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"EECS Department, ITTC University of Kansas, Lawrence, KS","institution_ids":["https://openalex.org/I146416000"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011578928","display_name":"Dalton A. Hahn","orcid":"https://orcid.org/0000-0002-7117-2155"},"institutions":[{"id":"https://openalex.org/I146416000","display_name":"University of Kansas","ror":"https://ror.org/001tmjg57","country_code":"US","type":"education","lineage":["https://openalex.org/I146416000"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dalton A. Hahn","raw_affiliation_strings":["EECS Department, ITTC University of Kansas, Lawrence, KS"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"EECS Department, ITTC University of Kansas, Lawrence, KS","institution_ids":["https://openalex.org/I146416000"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5034290852","display_name":"Alexandru G. Bardas","orcid":"https://orcid.org/0000-0003-3043-5905"},"institutions":[{"id":"https://openalex.org/I146416000","display_name":"University of Kansas","ror":"https://ror.org/001tmjg57","country_code":"US","type":"education","lineage":["https://openalex.org/I146416000"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alexandru G. Bardas","raw_affiliation_strings":["EECS Department, ITTC University of Kansas, Lawrence, KS"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"EECS Department, ITTC University of Kansas, Lawrence, KS","institution_ids":["https://openalex.org/I146416000"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I146416000"],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":12,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/password","display_name":"Password","score":0.8258694410324097},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7503691911697388},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6542959213256836},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.5581080317497253},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5021841526031494},{"id":"https://openalex.org/keywords/s/key","display_name":"S/KEY","score":0.48778897523880005},{"id":"https://openalex.org/keywords/challenge-handshake-authentication-protocol","display_name":"Challenge-Handshake Authentication Protocol","score":0.4592537581920624},{"id":"https://openalex.org/keywords/authentication-protocol","display_name":"Authentication protocol","score":0.4389364421367645},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.4293113648891449},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.4155423641204834},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.25597503781318665}],"concepts":[{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.8258694410324097},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7503691911697388},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6542959213256836},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.5581080317497253},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5021841526031494},{"id":"https://openalex.org/C4957475","wikidata":"https://www.wikidata.org/wiki/Q242186","display_name":"S/KEY","level":3,"score":0.48778897523880005},{"id":"https://openalex.org/C207828512","wikidata":"https://www.wikidata.org/wiki/Q1060131","display_name":"Challenge-Handshake Authentication Protocol","level":4,"score":0.4592537581920624},{"id":"https://openalex.org/C21564112","wikidata":"https://www.wikidata.org/wiki/Q4825885","display_name":"Authentication protocol","level":3,"score":0.4389364421367645},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.4293113648891449},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.4155423641204834},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.25597503781318665}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icc40277.2020.9148912","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icc40277.2020.9148912","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICC 2020 - 2020 IEEE International Conference on Communications (ICC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W1513380209","https://openalex.org/W1555169622","https://openalex.org/W2004013580","https://openalex.org/W2114398364","https://openalex.org/W2118226475","https://openalex.org/W2124890572","https://openalex.org/W2138779530","https://openalex.org/W2161810161","https://openalex.org/W2161954933","https://openalex.org/W2241474894","https://openalex.org/W2273298738","https://openalex.org/W2294935184","https://openalex.org/W2295782180","https://openalex.org/W2495983688","https://openalex.org/W2733765803","https://openalex.org/W2919808920","https://openalex.org/W2967079395","https://openalex.org/W3089688333","https://openalex.org/W3199359596","https://openalex.org/W4210726200","https://openalex.org/W6633252068","https://openalex.org/W6677217071","https://openalex.org/W6683814343","https://openalex.org/W6760252381"],"related_works":["https://openalex.org/W2377502939","https://openalex.org/W1549341377","https://openalex.org/W2377525748","https://openalex.org/W2050433615","https://openalex.org/W2374274463","https://openalex.org/W2354399035","https://openalex.org/W2377075426","https://openalex.org/W2584792246","https://openalex.org/W2135836328","https://openalex.org/W2348068295"],"abstract_inverted_index":{"Securing":[0],"and":[1,5,10,75,105],"hardening":[2],"network":[3],"protocols":[4,26],"services":[6,76,106],"is":[7,15,33,64,97,137],"a":[8,34,49,78,124],"resource-consuming":[9],"continuous":[11],"effort.":[12],"Thus,":[13],"it":[14,96],"important":[16],"to":[17,38,55,86,99,107,132,145],"question":[18],"how":[19,57],"prolific":[20],"known,":[21],"mitigable":[22],"features":[23],"of":[24,61,102,111,119,162],"those":[25],"are.":[27],"The":[28],"Secure":[29],"Shell":[30],"(SSH)":[31],"protocol":[32],"good":[35],"example":[36],"due":[37],"its":[39],"known":[40],"vulnerability":[41],"in":[42,81,114,156],"using":[43],"password":[44,62,112,135,174],"based":[45],"authentication.":[46,175],"We":[47,69,92],"take":[48],"closer":[50],"look":[51],"at":[52,65],"these":[53,103],"configurations":[54],"identify":[56],"prevalent":[58],"the":[59,109,146,163,170],"use":[60],"authentication":[63,113,136],"an":[66,129],"internet":[67,172],"scale.":[68],"show":[70,150],"that":[71,95,151,158],"current":[72],"scanning":[73],"tools":[74,104],"provide":[77],"starting":[79],"point":[80],"evaluating":[82],"prevalence,":[83],"but":[84],"need":[85],"be":[87],"validated":[88],"for":[89,127],"specific":[90],"implementations.":[91],"also":[93],"demonstrate":[94],"possible":[98],"augment":[100],"some":[101],"determine":[108],"prevalence":[110],"SSH":[115,130,167],"specifically.":[116],"As":[117],"part":[118],"our":[120,152],"evaluation,":[121],"we":[122,149],"propose":[123],"novel":[125],"method":[126],"probing":[128],"service":[131],"establish":[133],"if":[134],"allowed,":[138],"without":[139],"being":[140],"intrusive":[141],"or":[142],"causing":[143],"harm":[144],"host.":[147],"Finally,":[148],"analysis":[153],"has":[154],"resulted":[155],"determining":[157],"more":[159],"than":[160],"65%":[161],"over":[164],"20":[165],"million":[166],"servers":[168],"on":[169],"public":[171],"allow":[173]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":3},{"year":2020,"cited_by_count":1}],"updated_date":"2026-07-14T23:27:15.235271","created_date":"2025-10-10T00:00:00"}
