Your browser does not allow JavaScript!
JavaScript is necessary for the proper functioning of this website. Please enable JavaScript or use a modern browser.
Repository of the University of Ljubljana
Open Science Slovenia
Open Science
DiKUL
slv
|
eng
Search
Advanced
New in RUL
About RUL
In numbers
Help
Sign in
Details
Beyond the leak : analyzing the real-world exploitation of stolen credentials using honeypots
ID
Rabzelj, Matej
(
Author
),
ID
Sedlar, Urban
(
Author
)
PDF - Presentation file,
Download
(4,42 MB)
MD5: 21E318DB6D06EF6F93EBE29B8FF4296A
URL - Source URL, Visit
https://www.mdpi.com/1424-8220/25/12/3676
Image galllery
Abstract
This study presents one of the most extensive analyses of the lifecycle of leaked authentication credentials to date, bridging the gap between database breaches and real-world cyberattacks. We analyze over 27 billion leaked credentials—nearly 4 billion unique—using a sophisticated data filtering and normalization pipeline to handle breach inconsistencies. Following this analysis, we deploy a distributed sensor network of 39 honeypots running 14 unique services across 9 networks over a one-year-long experiment, capturing one of the most comprehensive authentication datasets in the literature. We analyze leaked credentials, SSH and Telnet session data, and HTTP authentication requests for their composition, characteristics, attack patterns, and occurrence. We comparatively assess whether credentials from leaks surface in real-world attacks. We observe a significant overlap of honeypot logins with common password wordlists (e.g., Nmap, John) and defaultlists (e.g., Piata, Mirai), and limited overlaps between leaked credentials, logins, and dictionaries. We examine generative algorithms (e.g., keywalk patterns, hashcat rules), finding they are widely used by users but not attackers—unless included in wordlists. Our analyses uncover unseen passwords and methods likely designed to detect honeypots, highlighting an adversarial arms race. Our findings offer critical insights into password reuse, mutation, and attacker strategies, with implications for authentication security, attack detection, and digital forensics.
Language:
English
Keywords:
cyberattack analysis
,
data breach
,
honeypots
,
leaked credentials
,
service modeling
,
username and password analysis
Work type:
Article
Typology:
1.01 - Original Scientific Article
Organization:
FE - Faculty of Electrical Engineering
Publication status:
Published
Publication version:
Version of Record
Year:
2025
Number of pages:
44 str.
Numbering:
Vol. 25, issue 12, art. 3676
PID:
20.500.12556/RUL-169933
UDC:
007:004.056
ISSN on article:
1424-8220
DOI:
10.3390/s25123676
COBISS.SI-ID:
239917315
Publication date in RUL:
19.06.2025
Views:
705
Downloads:
137
Metadata:
Cite this work
Plain text
BibTeX
EndNote XML
EndNote/Refer
RIS
ABNT
ACM Ref
AMA
APA
Chicago 17th Author-Date
Harvard
IEEE
ISO 690
MLA
Vancouver
:
Copy citation
Share:
Record is a part of a journal
Title:
Sensors
Shortened title:
Sensors
Publisher:
MDPI
ISSN:
1424-8220
COBISS.SI-ID:
10176278
Licences
License:
CC BY 4.0, Creative Commons Attribution 4.0 International
Link:
http://creativecommons.org/licenses/by/4.0/
Description:
This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.
Secondary language
Language:
Slovenian
Keywords:
analiza kibernetskih napadov
,
odtekanje podatkov
,
kibernetske vabe
,
modeliranje storitev
,
analiza uporabniških imen in gesel
Projects
Funder:
ARIS - Slovenian Research and Innovation Agency
Project number:
V2-2378
Name:
Kibernetska varnost obrambnih sistemov in kritičnih infrastruktur
Funder:
ARIS - Slovenian Research and Innovation Agency
Project number:
V2-24009
Name:
Modeliranje groženj in kibernetskih napadov na kibernetskem vadbišču MO
Funder:
ARIS - Slovenian Research and Innovation Agency
Project number:
P2-0425
Name:
Decentralizirane rešitve za digitalizacijo industrije ter pametnih mest in skupnosti
Similar documents
Similar works from RUL:
Similar works from other Slovenian collections:
Back