Describe the bug
The crowdsecurity/sshd-logs parser currently matches logs such as:
Connection closed by <IP> port <port> [preauth]
and classifies them as:
log_type = ssh_failed-auth
However, this log does not necessarily indicate that an authentication attempt occurred.
I encountered this with an SSH health check used by Termix. The check only opens the SSH connection, exchanges the SSH identification/banner, and disconnects before authentication. No username or password is submitted.
OpenSSH logs this as:
Connection closed by <IP> port <port> [preauth]
CrowdSec then classifies it as ssh_failed-auth, causing it to be fed into scenarios such as crowdsecurity/ssh-slow-bf.
To Reproduce
Have a service doing a health check of SSH by opening the SSH connection, exchanges the SSH identification/banner, and disconnects before authentication.
Expected behavior
Would it make sense for a bare [preauth] disconnect without an authenticating user or invalid user indication to use a different log_type, rather than being treated as a failed authentication?
The regex itself appears to be working as intended; the issue is the classification:
preauth disconnect → ssh_failed-auth
A pre-auth disconnect can also be caused by legitimate SSH-aware health checks or monitoring tools, without any authentication attempt taking place. It would make more sense to classify this, at most, as a probing scenario rather than a failed authentication attempt.
Describe the bug
The
crowdsecurity/sshd-logsparser currently matches logs such as:Connection closed by <IP> port <port> [preauth]and classifies them as:
log_type = ssh_failed-authHowever, this log does not necessarily indicate that an authentication attempt occurred.
I encountered this with an SSH health check used by Termix. The check only opens the SSH connection, exchanges the SSH identification/banner, and disconnects before authentication. No username or password is submitted.
OpenSSH logs this as:
Connection closed by <IP> port <port> [preauth]CrowdSec then classifies it as
ssh_failed-auth, causing it to be fed into scenarios such ascrowdsecurity/ssh-slow-bf.To Reproduce
Have a service doing a health check of SSH by opening the SSH connection, exchanges the SSH identification/banner, and disconnects before authentication.
Expected behavior
Would it make sense for a bare
[preauth]disconnect without anauthenticating userorinvalid userindication to use a differentlog_type, rather than being treated as a failed authentication?The regex itself appears to be working as intended; the issue is the classification:
preauth disconnect→ssh_failed-authA pre-auth disconnect can also be caused by legitimate SSH-aware health checks or monitoring tools, without any authentication attempt taking place. It would make more sense to classify this, at most, as a probing scenario rather than a failed authentication attempt.