Sign inSign up

dgisolfi/peitho

By dgisolfi

•Updated over 7 years ago

A honeypot that mimics a service providing a REST API.

Image
1

1.1K

dgisolfi/peitho repository overview

⁠NSF SecureCloud Research - REST Honeytrap

A honeypot that mimics a service providing a REST API. The production version of this honeypot can be found running on 10.11.17.23⁠ within the Marist network. The publicly natted IP address is located here: 148.100.116.135⁠

⁠Authors

Daniel Gisolfi - Spark Rewrite - dgisolfi⁠

Michael Gutierrez - Spark Rewrite - maristmichael⁠

⁠Docker Deployment

The Peitho honeypot is run using a docker container. The image for the container can be found here: Peitho Image⁠. Deploying an instance of the container can be done one of three ways:

  1. Makefile - Using the makefile found in the root of the repository run the honeypot_prod target

  2. Docker Run - Using a Docker command(the same as used in the makefile) the container can be run. To do so run the following:

    docker run -it --rm --name peitho_prod -p80:80 dgisolfi/peitho

  3. Docker Compose - Using Docker Compose you can run the following command in the same directory as the docker-compose.yml file

    docker-compose up

Note: all 3 methods result in the same container running with the same settings

⁠Logging setup

The Docker container is set up to log all requests to the honeypot. However with Docker containers unless volumes are used all data is lost once the container is killed. At any point, while a container is running you may enter the bash shell for that particular container, to do so run the following on the host machine

docker exec -it peitho_prod bash
⁠Using a CronTab

In order to save the logs recorded by the honeypot, a system must be set up to copy the file over to the host machine. This can be done in many ways the following is an example of how to accomplish this with a cronjob.

Use the template script found in the root of the repository named log_backup.sh. In the script edit the variable that sets the path to where logs will be saved. In this case, there is a directory called logs at the level of the bash script. When running, the bash script will create a copy of the "PEI02-DATE.log" found inside the docker container and place the file in the destination set within the script. This process is then automated and will run every hour on the 10th minute. This can be done by running the following on the host machine:

sudo crontab -e

then create the cronjob that will run the backup script every hour on the 10th minute

# m h  dom mon dow   command
 10 *  *   *   *     ~/home/<User_Name>/peitho/log_backup.sh

⁠RabbitMQ

The Pasietha honeypot is one of many honeypots in the honeynet to be integrated with RabbitMQ. This allows for real-time data to be sent as messages as well as logged to the hard drive. For further details on where RabbitMQ is running, how it is integrated and how to use it visit the LCARS⁠ repository in the SDN GitHub organization for documentation. For the scope of this project just be aware that unless the source code is altered the honeypot will attempt to send every attack received as a message to the message queue where LCARS and QRadar can read and visualize the data.

⁠Maven and Developing the source code

To compile, run and, test the Peitho honeypot Maven is used to create one jar file containing all dependencies and source code. This jar file is then executed at runtime. To test development code run make honeypot_dev in the same directory as the makefile.

The result of the make target is the newly build peitho dev image and maven being executed to attempt to run the newly edited code. This can be done without using the makefile by running the following docker commands in the root directory of the repository:

docker build -t peitho .

docker run -it --rm --name peitho_dev -p80:80 peitho

Tag summary

Content type

Image

Digest

Size

364.2 MB

Last updated

over 7 years ago

docker pull dgisolfi/peitho