Articles

ISSUES OF SSH CONNECTION PROTECTION BASED ON GOST ENCRYPTION IN ALT OS

Download PDF Article on eLIBRARY.RU

Abstract

The paper examines ways to improve the security of remote administration by using Russian cryptographic algorithms when establishing SSH connections in the ALT Linux operating system. The relevance of the study is determined by the need to comply with national information security requirements and to reduce dependence on foreign cryptographic solutions. The research problem consists in assessing the stability of SSH connections based on GOST algorithms and in analyzing how the selected cryptographic policy affects unauthorized access attempts and connection performance. The object of the study is the process of establishing and maintaining an SSH connection, while the subject is the server behavior when the cryptographic algorithm sets of the client and the server do not match. To solve the problem, an experimental SSH server and client configuration was performed in ALT Linux using gostcrypto packages that implement the Grasshopper and Magma algorithms and Stribog-based integrity control functions. The methodology included modeling legitimate and illegitimate connection attempts, analyzing network traffic with Wireshark, and measuring bandwidth and resource load. The experiments showed that a server configured to use only GOST algorithms effectively blocks connections with incompatible cryptographic parameters. When the client is configured correctly, the session is established stably and follows the specified security policy. The performance measurements demonstrate that GOST encryption provides throughput comparable to standard OpenSSH algorithms with a similar computational load. The results confirm the practical applicability of GOST-based SSH encryption for secure administration in domestic operating systems.

Online viewer

References

  1. Алицар, А. Wireshark для всех. Лайфхаки на каждый день [Электронный ресурс] / А. Алицар // Habr. – 2021. – 14 июня. – URL: https://habr.com/ru/companies/vdsina/articles/562110/ (дата обращения: 01.12.2025).
  2. ГОСТ Р 34.10–2012. Информационная технология. Криптографическая защита информации. Процессы формирования и проверки электронной цифровой подписи. – Москва : Стандартинформ, 2012.
  3. ГОСТ Р 34.12–2015. Информационная технология. Криптографическая защита информации. Блочные шифры. – Москва : Стандартинформ, 2015.
  4. Официальный репозиторий пакетов ALT Linux [Электронный ресурс] // ALT Linux Packages. – URL: https://packages.altlinux.org/ (дата обращения: 10.11.2025).
  5. OpenSSH GOSTCrypto [Электронный ресурс] // ALT Linux Packages. – URL: https://packages.altlinux.org/ru/p10/srpms/openssh-gostcrypto/ (дата обращения: 11.12.2025).
  6. OpenSSL GOST Engine [Электронный ресурс] // ALT Linux Packages. – URL: https://packages.altlinux.org/ru/p10/srpms/openssl-gost-engine/ (дата обращения: 11.12.2025).
  7. Создание SSH-туннелей, использующих контроль целостности заголовков IP-пакетов в соответствии с ГОСТ Р 34.12-2015 [Электронный ресурс] // Документация ALT Linux. ALT Workstation 10.2. – URL: https://docs.altlinux.org/ru-RU/alt-workstation/10.2/html/alt-workstation/ssh_t.html (дата обращения: 11.12.2025).
  8. Уймин, А. Г. Определение отечественной технологической платформы в рамках создания киберполигона: «Сетевое и системное администрирование» / А. Г. Уймин // Текущие вызовы в подготовке кадров. Обучение специалистов по современным направлениям информационных технологий, кибербезопасности и ИКТ-электроники, актуальным для экономики данных : сборник научных трудов. – Тверь, 2024. – С. 122–123.

License

Copyright (c) 2025 D. V. Demidova , E. D. Komnatskaya (Authors)

Keywords