DenyHosts is a script intended to help Linux system administrators thwart SSH server attacks. It monitors authentication logs and automatically blocks hosts that exhibit malicious behavior by updating /etc/hosts.deny after a configurable number of failed login attempts. The script can also alert the administrator of suspicious login activity.
How It Works
- Scans SSH server logs for failed authentication attempts.
- Updates
/etc/hosts.denyonce a host exceeds the configured threshold of failed attempts. - Optionally sends email alerts to the administrator when suspicious logins are detected.
- Supports synchronization mode, allowing multiple servers to share deny data.
DenyHosts Statistical Summary
As of July 17, 2011, the DenyHosts network reported the following aggregate statistics from contributing clients:
| Clients contributing data | 191,924 |
|---|---|
| Hosts denied | 12,229,136 |
| Unique hosts denied | 1,063,586 |
| Average hosts denied per client | 63.72 |
| Most attacked client | 9,467 |
| Denied hosts (through 11:49 AM PDT, Jul 17) | 6,305 |
| Denied hosts (previous day) | 12,850 |
| Daily average (1 week) | 11,923.43 |
License & Availability
DenyHosts is released under the GNU Public License (GPL). More information, including documentation and source code, is available on the DenyHosts homepage.
DenyHosts provides Linux system administrators with a practical defense against SSH brute-force attacks, which are among the most common threats facing internet-connected servers. By continuously monitoring authentication logs, the script identifies hosts that repeatedly attempt failed logins and automatically adds them to the system's hosts.deny file. This proactive approach reduces the administrative burden of manually reviewing logs and blocking malicious IP addresses. The tool's configurability allows administrators to set their own thresholds for failed attempts before a host is blocked, making it adaptable to different security postures. For servers exposed to the public internet, this kind of automated threat response is an essential layer of defense that works alongside firewalls and intrusion detection systems.
Attack patterns observed in DenyHosts statistical summaries reveal a global distribution of malicious activity, with significant volumes of failed SSH login attempts originating from various countries. China, the United States, Brazil, and European nations frequently appear among the top sources of hostile connections. This geographic diversity underscores the borderless nature of cyber threats and the importance of automated blocking tools that do not rely on manual intervention. The statistical summaries provide administrators with valuable insight into attack trends over time, including hourly, daily, and monthly patterns. Understanding these patterns helps system administrators allocate resources effectively and recognize when attack volumes deviate from normal baselines, potentially indicating a coordinated campaign targeting their infrastructure.
The resilience of the DenyHosts approach lies in its ability to learn from ongoing attack data and adapt blocking rules accordingly. As new malicious hosts are identified, the system expands its deny list, creating a growing barrier against repeat offenders. The statistical summaries track metrics such as the number of unique attacking hosts, total denied attempts, and the earliest and most recent activity from each source. This historical data gives administrators confidence that their systems are becoming more resilient over time, as persistent attackers are permanently blocked. The tool's lightweight design means it can run continuously on production servers without consuming excessive resources, making it suitable for both small-scale deployments and large server environments.
Beyond the immediate blocking of malicious hosts, DenyHosts contributes to broader security awareness by generating detailed reports on attack patterns. Administrators can review which usernames attackers are targeting most frequently, whether specific ports are under sustained assault, and how attack volumes correlate with global events or time zones. This intelligence is valuable for hardening server configurations beyond simple IP blocking. For instance, if attackers are repeatedly attempting to log in as root, administrators can disable root SSH logins entirely. The tool's optional email alerts ensure that administrators stay informed of suspicious activity even when they are not actively monitoring logs, bridging the gap between automated defense and human oversight.
Deploying DenyHosts is part of a comprehensive strategy for securing SSH access on Linux servers, complementing other best practices such as key-based authentication, changing default ports, and keeping software updated. The tool works particularly well in environments where multiple users require SSH access, as it provides a centralized mechanism for detecting and responding to abuse. Its statistical summaries offer a clear window into the security posture of the server over time, helping administrators justify security investments and demonstrate compliance with organizational policies. For those managing servers exposed to the relentless background noise of internet scanning and brute-force attempts, DenyHosts transforms an otherwise tedious monitoring task into an automated, data-driven security function.