Skip to content

Bare SSH [preauth] disconnects are classified as ssh_failed-auth #1859

Description

@TheGeeKing

Describe the bug
The crowdsecurity/sshd-logs parser currently matches logs such as:

Connection closed by <IP> port <port> [preauth]

and classifies them as:

log_type = ssh_failed-auth

However, this log does not necessarily indicate that an authentication attempt occurred.

I encountered this with an SSH health check used by Termix. The check only opens the SSH connection, exchanges the SSH identification/banner, and disconnects before authentication. No username or password is submitted.

OpenSSH logs this as:

Connection closed by <IP> port <port> [preauth]

CrowdSec then classifies it as ssh_failed-auth, causing it to be fed into scenarios such as crowdsecurity/ssh-slow-bf.

To Reproduce
Have a service doing a health check of SSH by opening the SSH connection, exchanges the SSH identification/banner, and disconnects before authentication.

Expected behavior
Would it make sense for a bare [preauth] disconnect without an authenticating user or invalid user indication to use a different log_type, rather than being treated as a failed authentication?

The regex itself appears to be working as intended; the issue is the classification:

preauth disconnect → ssh_failed-auth

A pre-auth disconnect can also be caused by legitimate SSH-aware health checks or monitoring tools, without any authentication attempt taking place. It would make more sense to classify this, at most, as a probing scenario rather than a failed authentication attempt.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions