adworacz / threat-analyzer

Analyzes log files in real time looking for strange client behavior.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

threat-analyzer

Analyzes log files in real time looking for strange user behavior.

Approaches

  1. Regex matching of Apache error codes (403, 404, 500, etc), as well as error_log messages (warn, error, alert, etc).
  2. Request correlation (eg. large amount of 'good' requests in a small amount of time.)

Future Work

  1. SQL/HTML injection attempts
  2. Add support for other log file types
  • SSH files
  • Dovecot
  • IPTables
  1. Add support for clusters of server
  2. Abstract away log parsing from researcher into its own class
  3. GUI with Graphs

About

Analyzes log files in real time looking for strange client behavior.


Languages

Language:Java 100.0%