A honeypot that mimics a service providing a REST API.
1.1K
A honeypot that mimics a service providing a REST API. The production version of this honeypot can be found running on 10.11.17.23 within the Marist network. The publicly natted IP address is located here: 148.100.116.135
Daniel Gisolfi - Spark Rewrite - dgisolfi
Michael Gutierrez - Spark Rewrite - maristmichael
The Peitho honeypot is run using a docker container. The image for the container can be found here: Peitho Image. Deploying an instance of the container can be done one of three ways:
Makefile - Using the makefile found in the root of the repository run the honeypot_prod target
Docker Run - Using a Docker command(the same as used in the makefile) the container can be run. To do so run the following:
docker run -it --rm --name peitho_prod -p80:80 dgisolfi/peitho
Docker Compose - Using Docker Compose you can run the following command in the same directory as the docker-compose.yml file
docker-compose up
Note: all 3 methods result in the same container running with the same settings
The Docker container is set up to log all requests to the honeypot. However with Docker containers unless volumes are used all data is lost once the container is killed. At any point, while a container is running you may enter the bash shell for that particular container, to do so run the following on the host machine
docker exec -it peitho_prod bash
In order to save the logs recorded by the honeypot, a system must be set up to copy the file over to the host machine. This can be done in many ways the following is an example of how to accomplish this with a cronjob.
Use the template script found in the root of the repository named log_backup.sh. In the script edit the variable that sets the path to where logs will be saved. In this case, there is a directory called logs at the level of the bash script. When running, the bash script will create a copy of the "PEI02-DATE.log" found inside the docker container and place the file in the destination set within the script. This process is then automated and will run every hour on the 10th minute. This can be done by running the following on the host machine:
sudo crontab -e
then create the cronjob that will run the backup script every hour on the 10th minute
# m h dom mon dow command
10 * * * * ~/home/<User_Name>/peitho/log_backup.sh
The Pasietha honeypot is one of many honeypots in the honeynet to be integrated with RabbitMQ. This allows for real-time data to be sent as messages as well as logged to the hard drive. For further details on where RabbitMQ is running, how it is integrated and how to use it visit the LCARS repository in the SDN GitHub organization for documentation. For the scope of this project just be aware that unless the source code is altered the honeypot will attempt to send every attack received as a message to the message queue where LCARS and QRadar can read and visualize the data.
To compile, run and, test the Peitho honeypot Maven is used to create one jar file containing all dependencies and source code. This jar file is then executed at runtime. To test development code run make honeypot_dev in the same directory as the makefile.
The result of the make target is the newly build peitho dev image and maven being executed to attempt to run the newly edited code. This can be done without using the makefile by running the following docker commands in the root directory of the repository:
docker build -t peitho .
docker run -it --rm --name peitho_dev -p80:80 peitho
Content type
Image
Digest
Size
364.2 MB
Last updated
over 7 years ago
docker pull dgisolfi/peitho