Sign inSign up

dgisolfi/lcars_queue_manager

By dgisolfi

•Updated over 7 years ago

Manages all messages from the honeynet message queue

Image
0

1.2K

dgisolfi/lcars_queue_manager repository overview

⁠Queue Manager

⁠Authors

Daniel Gisolfi - All current work - dgisolfi⁠

Michael Gutierrez - All current work - maristmichael⁠

⁠About

The LCARS queue manager was created and is used to interact with the LCARS instance 0f RabbitMQ. When a honeypot sends an attack message to the queue, the queue manager is ready and waiting to pull the message from the queue. Once pulled, the message is inserted into the database where the honeynet API can retrieve it. To do this we use an open source python library called pika, documentation, and examples on this library can be found here⁠.

⁠Docker Implementation

The queue manager takes advantage of a docker container and is run using the image pulled from docker hub. The image for this service can be found here⁠. The Dockerfile found in this directory is used to create the dgisolfi/queue_manager image. The Docker file does the following:

  1. Pulls version 16.04 of Ubuntu from docker hub
  2. installs the following
    • python3-pip
    • python3-dev
    • libpq-dev
  3. Creates a new directory, and copies all of the src directory into it
  4. installs all python requirements
  5. Defines the entry-point and command to run on startup

⁠Usage

To run an instance of the queue_manager image first ensure docker is installed on the host machine, if not please refer to the Docker documentation found here⁠. With Docker properly setup you can either follow the instructions in the root directory to boot all services at once or to boot this service individually, run the following command:

docker run dgisolfi/queue_manager

⁠How it Works

When initialized the Docker container will run the file "getFromQueue.py". When running this file python will stay in an infinite while loop. Using this loop the program continually attempts to connect to RabbitMQ if it is unable to make a connection it will wait five seconds and then try again. Otherwise, if the connection to RabbitMQ is successful the program will start to consume the messages until the connection dies or is broken if this occurs the loop begins again.

Notice: when proccessing attacks if the queue manager comes accross a attack that fails to insert into the normal table the attack is inserted into the "exceptions" table.

Before entering the attack into the database the queue manager makes and API request to the Geo Locater API⁠. With the country of origin for the attack a python library called pyCountry⁠ is used to return the country code for the corosponding country. Both the country name and code are entered into the database.

Tag summary

Content type

Image

Digest

Size

220.5 MB

Last updated

over 7 years ago

docker pull dgisolfi/lcars_queue_manager