Details

Praktična implementacija kibernetskih vab za nadzor in analizo kibernetskih napadov
ID Dolenec, Benjamin (Author), ID Sedlar, Urban (Mentor) More about this mentor... This link opens in a new window

.pdfPDF - Presentation file, Download (3,02 MB)
MD5: C5CE971560430B69385F522E31CE77C6

Abstract
V diplomskem delu je predstavljena praktična implementacija kibernetske vabe za spremljanje in analizo kibernetskih napadov. Na osnovi pasivnega zajema omrežnega prometa so bila identificirana najpogosteje skenirana vrata ter analizirani viri prometa. Na podlagi teh podatkov je bila vzpostavljena srednje interaktivna kibernetska vaba Cowrie, ki je bila prilagojena tako, da je delovala čim bolj realistično. Integracija s sistemom Splunk je omogočila centralizirano zbiranje dnevniških zapisov in vizualizacijo podatkov o napadalcih. Analiza interakcij in naložene zlonamerne kode je pokazala, da napadalci še vedno pogosto uporabljajo metode, kot so avtomatizirani napadi na zastarele ali slabo konfigurirane storitve. Vaba je kljub temu nudila dragocen vpogled v njihovo delovanje ter potrdila svojo uporabnost kot raziskovalno in varnostno orodje.

Language:Slovenian
Keywords:kibernetska vaba, omrežna varnost, analiza, zlonamerna koda, Cowrie
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FE - Faculty of Electrical Engineering
Year:2025
PID:20.500.12556/RUL-173793 This link opens in a new window
COBISS.SI-ID:258638595 This link opens in a new window
Publication date in RUL:23.09.2025
Views:935
Downloads:239
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Secondary language

Language:English
Title:Practical Implementation of Honeypots for Monitoring and Analysis of Cyber Attacks
Abstract:
This thesis presents the practical implementation of a honeypot for monitoring and analyzing cyberattacks. Based on passive traffic capture, the most frequently scanned ports were identified and the main sources of traffic were analyzed. Using this information, a medium-interaction honeypot based on the Cowrie project was deployed and customized to provide a realistic environment. The honeypot was integrated with the Splunk system, enabling centralized log collection and data visualization of attacker interactions. The analysis of interactions and uploaded malware revealed that attackers still commonly rely on methods, such as automated exploitation of outdated or misconfigured services. Nevertheless, the honeypot provided valuable insights into their behavior and confirmed its usefulness as both a research and security tool.

Keywords:honeypot, cybersecurity, analysis, malware, Cowrie

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back