Manages all messages from the honeynet message queue
1.2K
Daniel Gisolfi - All current work - dgisolfi
Michael Gutierrez - All current work - maristmichael
The LCARS queue manager was created and is used to interact with the LCARS instance 0f RabbitMQ. When a honeypot sends an attack message to the queue, the queue manager is ready and waiting to pull the message from the queue. Once pulled, the message is inserted into the database where the honeynet API can retrieve it. To do this we use an open source python library called pika, documentation, and examples on this library can be found here.
The queue manager takes advantage of a docker container and is run using the image pulled from docker hub. The image for this service can be found here. The Dockerfile found in this directory is used to create the dgisolfi/queue_manager image. The Docker file does the following:
To run an instance of the queue_manager image first ensure docker is installed on the host machine, if not please refer to the Docker documentation found here. With Docker properly setup you can either follow the instructions in the root directory to boot all services at once or to boot this service individually, run the following command:
docker run dgisolfi/queue_manager
When initialized the Docker container will run the file "getFromQueue.py". When running this file python will stay in an infinite while loop. Using this loop the program continually attempts to connect to RabbitMQ if it is unable to make a connection it will wait five seconds and then try again. Otherwise, if the connection to RabbitMQ is successful the program will start to consume the messages until the connection dies or is broken if this occurs the loop begins again.
Notice: when proccessing attacks if the queue manager comes accross a attack that fails to insert into the normal table the attack is inserted into the "exceptions" table.
Before entering the attack into the database the queue manager makes and API request to the Geo Locater API. With the country of origin for the attack a python library called pyCountry is used to return the country code for the corosponding country. Both the country name and code are entered into the database.
Content type
Image
Digest
Size
220.5 MB
Last updated
over 7 years ago
docker pull dgisolfi/lcars_queue_manager