Details

Beyond the leak : analyzing the real-world exploitation of stolen credentials using honeypots
ID Rabzelj, Matej (Author), ID Sedlar, Urban (Author)

.pdfPDF - Presentation file, Download (4,42 MB)
MD5: 21E318DB6D06EF6F93EBE29B8FF4296A
URLURL - Source URL, Visit https://www.mdpi.com/1424-8220/25/12/3676 This link opens in a new window

Abstract
This study presents one of the most extensive analyses of the lifecycle of leaked authentication credentials to date, bridging the gap between database breaches and real-world cyberattacks. We analyze over 27 billion leaked credentials—nearly 4 billion unique—using a sophisticated data filtering and normalization pipeline to handle breach inconsistencies. Following this analysis, we deploy a distributed sensor network of 39 honeypots running 14 unique services across 9 networks over a one-year-long experiment, capturing one of the most comprehensive authentication datasets in the literature. We analyze leaked credentials, SSH and Telnet session data, and HTTP authentication requests for their composition, characteristics, attack patterns, and occurrence. We comparatively assess whether credentials from leaks surface in real-world attacks. We observe a significant overlap of honeypot logins with common password wordlists (e.g., Nmap, John) and defaultlists (e.g., Piata, Mirai), and limited overlaps between leaked credentials, logins, and dictionaries. We examine generative algorithms (e.g., keywalk patterns, hashcat rules), finding they are widely used by users but not attackers—unless included in wordlists. Our analyses uncover unseen passwords and methods likely designed to detect honeypots, highlighting an adversarial arms race. Our findings offer critical insights into password reuse, mutation, and attacker strategies, with implications for authentication security, attack detection, and digital forensics.

Language:English
Keywords:cyberattack analysis, data breach, honeypots, leaked credentials, service modeling, username and password analysis
Work type:Article
Typology:1.01 - Original Scientific Article
Organization:FE - Faculty of Electrical Engineering
Publication status:Published
Publication version:Version of Record
Year:2025
Number of pages:44 str.
Numbering:Vol. 25, issue 12, art. 3676
PID:20.500.12556/RUL-169933 This link opens in a new window
UDC:007:004.056
ISSN on article:1424-8220
DOI:10.3390/s25123676 This link opens in a new window
COBISS.SI-ID:239917315 This link opens in a new window
Publication date in RUL:19.06.2025
Views:705
Downloads:137
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Record is a part of a journal

Title:Sensors
Shortened title:Sensors
Publisher:MDPI
ISSN:1424-8220
COBISS.SI-ID:10176278 This link opens in a new window

Licences

License:CC BY 4.0, Creative Commons Attribution 4.0 International
Link:http://creativecommons.org/licenses/by/4.0/
Description:This is the standard Creative Commons license that gives others maximum freedom to do what they want with the work as long as they credit the author.

Secondary language

Language:Slovenian
Keywords:analiza kibernetskih napadov, odtekanje podatkov, kibernetske vabe, modeliranje storitev, analiza uporabniških imen in gesel

Projects

Funder:ARIS - Slovenian Research and Innovation Agency
Project number:V2-2378
Name:Kibernetska varnost obrambnih sistemov in kritičnih infrastruktur

Funder:ARIS - Slovenian Research and Innovation Agency
Project number:V2-24009
Name:Modeliranje groženj in kibernetskih napadov na kibernetskem vadbišču MO

Funder:ARIS - Slovenian Research and Innovation Agency
Project number:P2-0425
Name:Decentralizirane rešitve za digitalizacijo industrije ter pametnih mest in skupnosti

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back