ITEj (Information Technology Engineering Journals)
Vol 10 No 2 (2025): December (In Progress)

Sharing SSH Threat Intelligence across Multiple Servers using WebSocket and Fail2Ban

Tely, Aristo (Unknown)
Aryanti, Aryanti (Unknown)
Soim, Sopian (Unknown)



Article Info

Publish Date
31 Jul 2025

Abstract

This study presents a lightweight prototype designed to improve SSH brute-force defense by enabling collaborative IP blocking across multiple servers. The system integrates Fail2Ban with WebSocket to distribute banned IP addresses in real-time among trusted nodes eliminating the need for centralized infrastructure. The experiment was conducted on 3 virtual private servers (VPS), where one acted as the WebSocket server and the others as clients equipped with Fail2Ban. When an SSH brute-force attack is detected, the source IP is automatically shared across the network and blocked on all connected nodes. A qualitative observational approach was used to evaluate the system’s feasibility. Log data from the clients and server was analyzed to confirm the accuracy and consistency of IP synchronization. The results showed that banned IPs were propagated and enforced on all nodes within seconds of detection. These findings demonstrate the potential for decentralized, lightweight collaboration among SSH servers to enhance security without introducing complex infrastructure or external dependencies.

Copyrights © 2025






Journal Info

Abbrev

itej

Publisher

Subject

Computer Science & IT Decision Sciences, Operations Research & Management Education Electrical & Electronics Engineering Mathematics

Description

ITEj (Information Technology Engineering Journals) is an international standard, open access, and peer-reviewed journal to discuss new findings in software engineering and information technology. The journal publishes original research articles and case studies focused on e-learning and information ...