I'm running an Ubuntu/WordPress server on Amazon EC2 which is experiencing problems every 24-48 hours: I get a CPU alarm from EC2, log into the server, and discover sshd is running at 99.9% CPU.
This is a public-facing WordPress server, so normally, I would assume the server has been compromised... except port 22 is enabled only to my IP, root login is disabled, passwords are disabled, I have the only key, and last and lastb show that I'm the only user who has ever logged into sshd.
When I kill the offending process or reboot the server, all is OK for 24-48 hours, then the problem recurs.
Any advice or pointers would be very appreciated because I can't find a problem.