Sign inSign up

dgisolfi/honeynet_api

By dgisolfi

•Updated almost 8 years ago

the API for LCARS to interact with all honeypots within the honeynet.

Image
0

994

dgisolfi/honeynet_api repository overview

⁠Honeynet API

⁠Authors

Daniel Gisolfi - All current work - dgisolfi⁠

Michael Gutierrez - All current work - maristmichael⁠

This Honeynet API is used as the main point of contact for all of the honeynet infastructure. The frontend uses this API to render data and information about the infastructure.

⁠Docker Implementation

The API takes advantage of a docker container and is run using the image pulled from docker hub. The image for this API can be found here⁠. The Dockerfile found in the HoneynetAPI⁠ directory is used to build the image for this service. The Dockerfile does the following:

  1. pull the latest version of Ubuntu from docker hub
  2. install the following:
    • python-pip
    • python-dev
    • build-essential
    • libpq-dev
    • tzdata
  3. change the local time to the New York timezone
  4. Create a directory in the image, and copy all of src into it
  5. install all python requirements
  6. define the entry-point and command to run on startup

⁠Running the API

Docker Compose will luanch this service when run, otherwise to run the API individually, on a machine where Docker is installed run the following commands:

docker pull dgisolfi/honeynet_api
docker run --rm --name honeynet_api_prod -p 5525:5525 dgisolfi/honeynet_api

⁠Usage

All responses will have the form

[
    {
        "key":"value"
    }
]
⁠Methods

Definition

GET /

Retrieve API Help Page

Response

200 OK on success

Definition

GET /attack_logs/<honeypot>

Retrieve the log entries for the specified active honeypot

Note: to get all honeypot logs, pass "all" as the honeypot parameter

Response

200 OK on success

[
  {
    "id": "THA01", 
    "timestamp": "2018-08-21 09:21:16.155", 
    "pot_name": "thanatos", 
    "host_ip": "0.0.0.0/32", 
    "host_name": "d1796dfb2f14", 
    "host_PID": 6, 
    "HPID": "jw84f4wnf", 
    "method": "GET", 
    "requested_text": "/", 
    "source_ip": "92.242.236.223/32", 
    "source_port": 4400, 
    "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTMLCOMMA like Gecko) Version/9.1.2 Safari/601.7.7", 
    "post_text": "nu", 
    "source_country": "Croatia", 
    "country_code": "hr"
  }
]

Definition

GET /attack_logs/<honeypot>/<start_date>/<end_date>

Retrieve the log entries for the specified active honeypot within a given date range

Note: The date format must be YYYY-MM-DD

A more specific range can be given using the format YYYY-MM-DD_HH:MM:SS, for example:

GET /attack_logs/<honeypot>/2018-09-20_00:00:00/2018-09-20_06:00:00

Response

200 OK on success

[
  {
    "id": "THA01", 
    "timestamp": "2018-08-14 07:30:44.901", 
    "pot_name": "thanatos", 
    "host_ip": "148.100.116.135/32", 
    "host_name": "923810b0412c", 
    "host_PID": 1, 
    "HPID": "4f355343276525f67ade27d8d5b5635c5", 
    "method": "GET", 
    "requested_text": "/", 
    "source_ip": "174.220.14.144/32", 
    "source_port": 4400, 
    "user_agent": "Mozilla/5.0 (iPhone; CPU iPhone OS 11_4 like Mac OS X) AppleWebKit/605.1.15 (KHTMLCOMMA like Gecko) Version/11.0 Mobile/15E148 Safari/604.1", 
    "post_text": "null", 
    "source_country": "United States", 
    "country_code": "us"
  }, 
  {
    "id": "THA01", 
    "timestamp": "2018-08-17 13:05:35.828", 
    "pot_name": "thanatos", 
    "host_ip": "148.100.116.135/32", 
    "host_name": "938eb4fa46ad", 
    "host_PID": 1, 
    "HPID": "4f355343276525f67ade27d8d5b5635c5", 
    "method": "GET", 
    "requested_text": "/", 
    "source_ip": "174.220.9.78/32", 
    "source_port": 4400, 
    "user_agent": "Mozilla/5.0 (iPhone; CPU iPhone OS 11_4 like Mac OS X) AppleWebKit/605.1.15 (KHTMLCOMMA like Gecko) Version/11.0 Mobile/15E148 Safari/604.1", 
    "post_text": "null", 
    "source_country": "United States", 
    "country_code": "us"
  }, 
]

Definition

GET /attack_count

Retrieve the total attack count received today

Response

200 OK on success

[
    {
      "attacks": 300
    }
]

Definition

GET /active_pots

Retrieve the count of currently active honeypots

Response

200 OK on success

[
    {
      "active_honeypots": 2
    }
]

Definition

GET /active_pots_info

Retrieve the attack count, name, and time when last attacked of each honeypot

Response

200 OK on success

[
  {
    "attack_count": 23, 
    "honeypot_name": "thanatos", 
    "last_attack": "2018-08-13 13:40:19.442349"
  },
  {
    "attack_count": 45, 
    "honeypot_name": "peitho", 
    "last_attack": "2018-08-013 14:55:35.856204"
  }
]

Definition

GET /country_data

Retrieve the count of all attacks, grouped by countries for today

Response

200 OK on success

[
  {
    "US": 1
  }, 
  {
    "BD": 1
  }
]

Definition

GET /exceptions

Retrieve all exception entries for todays

Response

200 OK on success

[
  {
    "id": "THA01", 
    "timestamp": "2018-08-14 07:30:44.901", 
    "pot_name": "thanatos", 
    "host_ip": "148.100.116.135/32", 
    "host_name": "923810b0412c", 
    "host_PID": 1, 
    "HPID": "4f355343276525f67ade27d8d5b5635c5", 
    "method": "GET", 
    "requested_text": "/", 
    "source_ip": "174.220.14.144/32", 
    "source_port": 4400, 
    "user_agent": "Mozilla/5.0 (iPhone; CPU iPhone OS 11_4 like Mac OS X) AppleWebKit/605.1.15 (KHTMLCOMMA like Gecko) Version/11.0 Mobile/15E148 Safari/604.1", 
    "post_text": "null", 
    "source_country": "United States", 
    "country_code": "us"
  } 
]

Tag summary

Content type

Image

Digest

Size

377.4 MB

Last updated

almost 8 years ago

docker pull dgisolfi/honeynet_api