{"title":"Protection against remote desktop attacks","authors":"O. Hornyák","doi":"10.32968/psaie.2022.3.3","DOIUrl":null,"url":null,"abstract":"This paper overviews the most common malicious software types. The motivationof writing this paper was a real wordcase studythat had to be investigated. Acomputer was suspected to have had an unwanted remote desktop connection attack. This paper presents how to investigatethe event log artifacts. For the unfortunate case when such an attack is proved to have happened, the second part of the article describes a method that allows the system administrator to detect brute force attacks through the remote desktop connection. When such an attack was revealed, the attacker’s IP address can be blacklisted.","PeriodicalId":117509,"journal":{"name":"Production Systems and Information Engineering","volume":"21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Production Systems and Information Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.32968/psaie.2022.3.3","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
This paper overviews the most common malicious software types. The motivationof writing this paper was a real wordcase studythat had to be investigated. Acomputer was suspected to have had an unwanted remote desktop connection attack. This paper presents how to investigatethe event log artifacts. For the unfortunate case when such an attack is proved to have happened, the second part of the article describes a method that allows the system administrator to detect brute force attacks through the remote desktop connection. When such an attack was revealed, the attacker’s IP address can be blacklisted.